Home Malware Programs Worms Worm.Dorpiex.A

Worm.Dorpiex.A

Posted: May 15, 2013

Threat Metric

Threat Level: 5/10
Infected PCs: 9
First Seen: May 15, 2013
OS(es) Affected: Windows

Worm.Dorpiex.A (Worm:Win32/Dorpiex.A) is a worm that sends Facebook messages that carry a web link that downloads additional malware threats onto the affected computer. When installed on the infected computer, Worm:Win32/Dorpiex.A makes system changes. Worm:Win32/Dorpiex.A displays messages from an affected PC user's Facebook account that he/she does not recall writing. Once run, Worm.Dorpiex.A to a remote server, from which it gains the list of web links that it uses in the messages it delivers on Facebook. Worm.Dorpiex.A then attempts to get Facebook authentication cookies from the web browsers such as Google Chrome, Mozilla Firefox, Internet Explorer and other by searching the victim's saved cookies (a cookie is a file on a computer that Internet browsers use to store information about the websites a computer user visits). Worm.Dorpiex.A also strives to get Facebook authentication cookies from the processes such as 'facebookmessenger.exe', 'chrome.exe', 'firefox.exe', 'iexplore.exe' and others, if they are running.

Aliases

BackDoor.Generic17.FTC [AVG]Trojan/Win32.Injector [AhnLab-V3]BackDoor.IRC.NgrBot.42 [DrWeb]Trj/CI.A [Panda]Agent4.ANQX [AVG]W32/Agent.BTV!worm [Fortinet]Trojan/Win32.Banker [AhnLab-V3]Worm:Win32/Dorpiex.A [Microsoft]TR/ATRAPS.Gen2 [AntiVir]Win32.HLLW.Phorpiex.90 [DrWeb]UnclassifiedMalware [Comodo]Worm.Win32.Agent.btv [Kaspersky]Win32:Malware-gen [Avast]WS.Reputation.1 [Symantec]Artemis!3429E9AEF772 [McAfee]
More aliases (27)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\B29F.exe File name: B29F.exe
Size: 32.25 KB (32256 bytes)
MD5: 3429e9aef772f2805d023b05c7fc7115
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 15, 2013
%APPDATA%\12F4.exe File name: 12F4.exe
Size: 99.66 KB (99664 bytes)
MD5: 11e6e06f3d5a825b29cbcc92eec07bed
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 15, 2013
Loading...