Worm:Win32/Phorpiex.O

Posted: December 14, 2012
Threat Metric
Threat Level: 8/10
Infected PCs 9

Worm:Win32/Phorpiex.O Description

Worm:Win32/Phorpiex.O is a worm that downloads other malicious files, which may be detected as malware threats. Worm:Win32/Phorpiex.O circulates via instant messaging applications, such as Google Talk, Skype, ICQ, Paltalk, Xfire, and Windows Live Messenger. Computer users may unknowingly download Worm:Win32/Phorpiex.O, thinking it is a legitimate application. Worm:Win32/Phorpiex.O sends a message to all of the victim's contacts, seducing or tricking him/her into downloading and opening a picture, which may be a copy of Worm:Win32/Phorpiex.O. The message is localized, and Worm:Win32/Phorpiex.O selects which message to send depending on the set language of the targeted computer. Once installed on the corrupted PC, Worm:Win32/Phorpiex.O makes system changes by displaying a message or link in your Google Talk, Skype, ICQ, Paltalk, Xfire, or Windows Live Messenger conversation history that the PC user does not recall writing. Worm:Win32/Phorpiex.O will also add potentially malicious files. Worm:Win32/Phorpiex.O is launched when the computer user runs or opens the malicious file. These files may be used by Worm:Win32/Phorpiex.O to help in its payload delivery. After Worm:Win32/Phorpiex.O has performed its malicious payload, it downloads and executes the certain file to remove itself from the PC.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Worm:Win32/Phorpiex.O may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



eb48d1c58b8d9fc1688f76dfecb5e27d File name: eb48d1c58b8d9fc1688f76dfecb5e27d
Size: 135.68 KB (135680 bytes)
MD5: eb48d1c58b8d9fc1688f76dfecb5e27d
Detection count: 43
Group: Malware file
Last Updated: March 5, 2013
Chiho.exe File name: Chiho.exe
Size: 188.41 KB (188416 bytes)
MD5: 93c86be05409ccca59fe637e91b07303
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
5e8927f5ebde777e07d2828edc61df1a File name: 5e8927f5ebde777e07d2828edc61df1a
Size: 66.04 KB (66048 bytes)
MD5: 5e8927f5ebde777e07d2828edc61df1a
Detection count: 27
Group: Malware file
Last Updated: March 5, 2013
MaryJane.exe File name: MaryJane.exe
Size: 151.55 KB (151552 bytes)
MD5: daaaffff39828546658bc14e160c1a95
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
%TEMP%\NRRQSCAkYD.zuG File name: %TEMP%\NRRQSCAkYD.zuG
Mime Type: unknown/zuG
Group: Malware file
%TEMP%\.exe File name: %TEMP%\.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%TEMP%\ZSa.tmp File name: %TEMP%\ZSa.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%TEMP%\rmrf.bat File name: %TEMP%\rmrf.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file

More files

Additional Information

The following messages's were detected:
# Message
1a tengo esta foto tuya del invierno pasado, te acordas?
creo que no voy a poder dormir más despues de ver esta foto. mirá
esta foto es gracios
mis padres me van a matar si ven esta foto mia, que decis?
no puedo creer que todav
quedarí a bien si pongo esta foto en mi perfil? o me veo medio mal?
2asta e ce-a mai funny poza! tu ce zici?
nu cred ca voi mai putea dormi dupa ce am vazut poza asta. tu ce zici?
nu imi mai voi face niciodat poze!! toate ies urate ca asta.
spune-mi ce crezi despre poza asta.
zimi ce crezi despre poza asta?
3ben jij dat op dit foto?
dit foto zal je echt eens bekijken!
ik hoop dat jij het net bent op dit foto
ken je dat foto nog?
ken je dit foto al?
kijk wat voor een foto ik heb gevonden
zo iets leilijk heb ik nog nooit in mijn leven gezien
4bist du das auf dem foto?
das foto solltest du wirklich sehen
hab ich dir das foto schon gezeigt?
kennst du das foto schon?
schau mal das foto an
schau mal welches foto ich gefunden hab
so will ich nicht aussehen wenn ich alt bin
unglaublich welche fotos leute von sich machen schau mal
wie findest du das foto?
5c'est la photo la plus marrante!
devrais-je mettre cette photo de profile?
dis moi ce que tu pense de cette photo de moi?
je n'arrive pas a croire que j'ai encore cette photo de toi depuis l'hiver dernier.
je ne pense pas que je vais pouvoir dormir après avoir vu ces photos.
mes parents vont me tués si ils trouvent cette photo
6chi e in questa foto?
conosci la persona in questa foto?
dopo che hai visto la foto, tu non dormirai piu
hai visto questa foto?
la foto e grandiosa!
ti piace la foto?
ti ricordi la Foto?
7i cant believe i still have this picture
i don't think i will ever sleep again after seeing this photo
should i make this my default picture?
tell me what you think of this photo
tell me what you think of this picture i edited
this is the funniest photo ever!

Home Malware Programs Worms Worm:Win32/Phorpiex.O

Leave a Reply

Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter. If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.