Home Malware Programs Worms Worm.Phorpiex

Worm.Phorpiex

Posted: October 5, 2012

Threat Metric

Ranking: 5,557
Threat Level: 5/10
Infected PCs: 64,867
First Seen: October 5, 2012
Last Seen: March 8, 2025
OS(es) Affected: Windows

Aliases

Generic30.AFOS [AVG]TR/Jorik.IRCbot.vgn.1 [AntiVir]Win32.HLLW.Autoruner1.29986 [DrWeb]Trojan.Win32.Jorik.IRCbot.vgn [Kaspersky]Win32:Malware-gen [Avast]W32/Sdbot.worm!pr [McAfee]Trojan.Jorik.IRCbot.vgn [CAT-QuickHeal]Generic30.BHZ [AVG]W32/Bublik.MNO!tr [Fortinet]Trojan.Win32.Bublik [Ikarus]Trojan/Win32.Bublik [AhnLab-V3]TR/Dropper.Gen [AntiVir]BackDoor.IRC.NgrBot.42 [DrWeb]Trojan.Win32.Bublik.mno [Kaspersky]Win32:Agent-AQGP [Trj] [Avast]
More aliases (179)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\T-610356568130365630\winsvc.exe File name: winsvc.exe
Size: 304.12 KB (304128 bytes)
MD5: 4c51ef187457a6b60dd65da1785cd77d
Detection count: 1,112
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\T-610356568130365630\winsvc.exe
Group: Malware file
Last Updated: April 27, 2022
%WINDIR%\4993930030304004\winupd32cfg.exe File name: winupd32cfg.exe
Size: 43.14 KB (43141 bytes)
MD5: 525898d3171b336c6a633114a4eb67e8
Detection count: 731
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\4993930030304004\winupd32cfg.exe
Group: Malware file
Last Updated: April 27, 2022
C:\Users\<username>\7695275014274101\winfnsx.exe File name: winfnsx.exe
Size: 145.4 KB (145408 bytes)
MD5: d9e59a4295926df49c8d6484aa6b8305
Detection count: 344
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\7695275014274101\winfnsx.exe
Group: Malware file
Last Updated: January 10, 2023
%WINDIR%\4956060830304950\winsvcs.exe File name: winsvcs.exe
Size: 142.84 KB (142848 bytes)
MD5: 3cbf3552471627f240244765dda0c622
Detection count: 260
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\4956060830304950\winsvcs.exe
Group: Malware file
Last Updated: June 23, 2022
%USERPROFILE%\M-87-78985-6027-77788\winsvcr.exe File name: winsvcr.exe
Size: 39.42 KB (39424 bytes)
MD5: aa4e600d8c199bcf90247c2d01cc405d
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-87-78985-6027-77788
Group: Malware file
Last Updated: February 22, 2013
C:\Users\<username>\AppData\Local\Temp\Windows Archive Manager.exe File name: Windows Archive Manager.exe
Size: 301.05 KB (301056 bytes)
MD5: 04cdb6a52dad2af1eaaa5e76bc46796d
Detection count: 220
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Windows Archive Manager.exe
Group: Malware file
Last Updated: January 27, 2023
C:\Users\<username>\AppData\Local\Temp\104931452541650.exe File name: 104931452541650.exe
Size: 153.6 KB (153600 bytes)
MD5: 6974f40df848d49cad0a304794d1fce1
Detection count: 185
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\104931452541650.exe
Group: Malware file
Last Updated: April 3, 2023
%USERPROFILE%\M-100-4085-5427-34678\winmgr9g8.exe File name: winmgr9g8.exe
Size: 40.96 KB (40960 bytes)
MD5: c3b9e320cf30e1795a89e733422cf9d5
Detection count: 152
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-100-4085-5427-34678
Group: Malware file
Last Updated: October 5, 2012
C:\Users\<username>\AppData\Local\Temp\158381994823929.exe File name: 158381994823929.exe
Size: 204.28 KB (204288 bytes)
MD5: ec8bc22b6a8b2344355c20a38ba16a96
Detection count: 89
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\158381994823929.exe
Group: Malware file
Last Updated: April 27, 2022
%USERPROFILE%\86df68d668d68d\winsro.exe File name: winsro.exe
Size: 73.72 KB (73728 bytes)
MD5: 23afa7ca23c9dcc07346d8e7429c0f10
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\86df68d668d68d
Group: Malware file
Last Updated: March 1, 2013
C:\Users\<username>\AppData\Local\Temp\138331645016418.exe File name: 138331645016418.exe
Size: 164.35 KB (164352 bytes)
MD5: acc9ea10d6f63e502f43db909754d3f5
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\138331645016418.exe
Group: Malware file
Last Updated: January 30, 2022
%USERPROFILE%\M-500-7469-9976-4678\winmgr.exe File name: winmgr.exe
Size: 32.76 KB (32768 bytes)
MD5: 282d88e9611a85defc73ed852be3427e
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-500-7469-9976-4678
Group: Malware file
Last Updated: October 5, 2012
%USERPROFILE%\857648585795695\winvsn.exe File name: winvsn.exe
Size: 235.6 KB (235600 bytes)
MD5: 8e9228c6d0e85e77267cf42cafb84c69
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\857648585795695
Group: Malware file
Last Updated: December 24, 2012
%USERPROFILE%\T-1-52-5782-8754-5245\winsrv.exe File name: winsrv.exe
Size: 26.62 KB (26624 bytes)
MD5: 68f53bf83b49019dcf5dce066b74630a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\T-1-52-5782-8754-5245
Group: Malware file
Last Updated: October 8, 2012
%USERPROFILE%\P-7-78-8964-9648-3874\wincrs.exe File name: wincrs.exe
Size: 54.27 KB (54272 bytes)
MD5: 2212face6179f75b577426c4013dd91a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\P-7-78-8964-9648-3874
Group: Malware file
Last Updated: October 8, 2012

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\ScreenShot\screen.jpeg%APPDATA%\Skype\cssrss.exe%HOMEDRIVE%\_\DeviceConfigManager.exe%TEMP%\Windows Archive Manager.exe

Additional Information

The following directories were created:
%USERPROFILE%\M-1-25-8784-4125-7572%USERPROFILE%\M-1-52-5782-8754-5245%USERPROFILE%\M-10-6897-8685-3464%USERPROFILE%\M-5050324589790225392040235%USERPROFILE%\M-505045058025025030484340240%USERPROFILE%\M-78577389809558786%USERPROFILE%\M-87-78985-6027-77788%USERPROFILE%\M-9433461589685794657786%WINDIR%\91295601560973149617056167513670%WINDIR%\M-50500258608265602480562480650842068024682480%WINDIR%\M-505045058025025030484340240%WINDIR%\M-505059270375072397532052973057023740495830%WINDIR%\M-505076805704006805085868706806085%WINDIR%\M-50508068750580687808058005%WINDIR%\M-5050970685462056485602658064280562840%WINDIR%\M-505958576840600505580505058

Related Posts

Loading...