PWS:Win32/QQRob is a family of programs that steals user input for QQ mesenger. It also terminates or disables security-related processes and downloads and executes files from certain websites.
Installation
Depending on the variant, PWS:Win32/QQRob drops a copy of itself or its DLL component in the Windows or Windows system folder.
It then modifies the system registry to enable its dropped copy to run at every Windows start by adding a registry entry to the following subkey:
HKLM\SoftWare\Microsoft\Windows\CurrentVersion\Run
It may then use a batch file to delete its currently-running copy.
Payload
Disables Security-Related Processes
PWS:Win32/QQRob disables various security-related processes by modifying the following registry entries by setting their "Start" values to "4":
HKLM\SYSTEM\CurrentControlSet\Services\navapsvc
HKLM\SYSTEM\CurrentControlSet\Services\RsRavMon
HKLM\SYSTEM\CurrentControlSet\Services\RsCCenter
HKLM\SYSTEM\CurrentControlSet\Services\kavsvc
HKLM\SYSTEM\CurrentControlSet\Services\KVSrvXP
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc
HKLM\SYSTEM\CurrentControlSet\Services\KPfwSvc
HKLM\SYSTEM\CurrentControlSet\Services\KWatchSvc
HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc
HKLM\SYSTEM\CurrentControlSet\Services\ccProxy
HKLM\SYSTEM\CurrentControlSet\Services\ccEvtMgr
HKLM\SYSTEM\CurrentControlSet\Services\ccSetMgr
HKLM\SYSTEM\CurrentControlSet\Services\SPBBCSvc
HKLM\SYSTEM\CurrentControlSet\Services\Symantec Core LC
HKLM\SYSTEM\CurrentControlSet\Services\NPFMntor
HKLM\SYSTEM\CurrentControlSet\Services\MskService
HKLM\SYSTEM\CurrentControlSet\Services\FireSvc
HKLM\SYSTEM\CurrentControlSet\Services\McShield
HKLM\SYSTEM\CurrentControlSet\Services\McTaskManager
HKLM\SYSTEM\CurrentControlSet\Services\McAfeeFramework
It also looks for and closes windows that contain the following titles, if found:
Symantec AntiVirus
KV2004
RavMon.exe
RavMonClass
TfLockDownMain
ZoneAlarm
ZAFrameWnd
Tapplication
Steals User Input
PWS:Win32/QQRob retrieves user input if it finds an open window related to QQ Messenger.
Downloads Arbitrary Files
Some variants of PWS:Win32/QQRob have also been known to try to connect to certain websites to download arbitrary files. These files may include additional malware.
Analysis by Francis Allan Tan Seng