Home Malware Programs Worms Worm:Win32/Phorpiex.O

Worm:Win32/Phorpiex.O

Posted: December 14, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 9
First Seen: December 14, 2012
Last Seen: June 12, 2019
OS(es) Affected: Windows

Worm:Win32/Phorpiex.O is a worm that downloads other malicious files, which may be detected as malware threats. Worm:Win32/Phorpiex.O circulates via instant messaging applications, such as Google Talk, Skype, ICQ, Paltalk, Xfire, and Windows Live Messenger. Computer users may unknowingly download Worm:Win32/Phorpiex.O, thinking it is a legitimate application. Worm:Win32/Phorpiex.O sends a message to all of the victim's contacts, seducing or tricking him/her into downloading and opening a picture, which may be a copy of Worm:Win32/Phorpiex.O. The message is localized, and Worm:Win32/Phorpiex.O selects which message to send depending on the set language of the targeted computer. Once installed on the corrupted PC, Worm:Win32/Phorpiex.O makes system changes by displaying a message or link in your Google Talk, Skype, ICQ, Paltalk, Xfire, or Windows Live Messenger conversation history that the PC user does not recall writing. Worm:Win32/Phorpiex.O will also add potentially malicious files. Worm:Win32/Phorpiex.O is launched when the computer user runs or opens the malicious file. These files may be used by Worm:Win32/Phorpiex.O to help in its payload delivery. After Worm:Win32/Phorpiex.O has performed its malicious payload, it downloads and executes the certain file to remove itself from the PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Chiho.exe File name: Chiho.exe
Size: 189.84 KB (189843 bytes)
MD5: 8c8d86a6dcc1fcb22a314ad681cbb12e
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
eb48d1c58b8d9fc1688f76dfecb5e27d File name: eb48d1c58b8d9fc1688f76dfecb5e27d
Size: 135.68 KB (135680 bytes)
MD5: eb48d1c58b8d9fc1688f76dfecb5e27d
Detection count: 43
Group: Malware file
Last Updated: March 5, 2013
Chiho.exe File name: Chiho.exe
Size: 188.41 KB (188416 bytes)
MD5: 93c86be05409ccca59fe637e91b07303
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
5e8927f5ebde777e07d2828edc61df1a File name: 5e8927f5ebde777e07d2828edc61df1a
Size: 66.04 KB (66048 bytes)
MD5: 5e8927f5ebde777e07d2828edc61df1a
Detection count: 27
Group: Malware file
Last Updated: March 5, 2013
MaryJane.exe File name: MaryJane.exe
Size: 151.55 KB (151552 bytes)
MD5: daaaffff39828546658bc14e160c1a95
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
%TEMP%\NRRQSCAkYD.zuG File name: %TEMP%\NRRQSCAkYD.zuG
Mime Type: unknown/zuG
Group: Malware file
%TEMP%\<SIX-DIGIT RANDOM NUMBER>.exe File name: %TEMP%\<SIX-DIGIT RANDOM NUMBER>.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%TEMP%\ZSa<TWO-DIGIT RANDOM NUMBER>.tmp File name: %TEMP%\ZSa<TWO-DIGIT RANDOM NUMBER>.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%TEMP%\rmrf<FOUR-DIGIT RANDOM NUMBER>.bat File name: %TEMP%\rmrf<FOUR-DIGIT RANDOM NUMBER>.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file

Additional Information

The following messages's were detected:
# Message
1a tengo esta foto tuya del invierno pasado, te acordas?
creo que no voy a poder dormir más despues de ver esta foto. mirá
esta foto es gracios
mis padres me van a matar si ven esta foto mia, que decis?
no puedo creer que todav
quedarí a bien si pongo esta foto en mi perfil? o me veo medio mal?
2asta e ce-a mai funny poza! tu ce zici?
nu cred ca voi mai putea dormi dupa ce am vazut poza asta. tu ce zici?
nu imi mai voi face niciodat poze!! toate ies urate ca asta.
spune-mi ce crezi despre poza asta.
zimi ce crezi despre poza asta?
3ben jij dat op dit foto?
dit foto zal je echt eens bekijken!
ik hoop dat jij het net bent op dit foto
ken je dat foto nog?
ken je dit foto al?
kijk wat voor een foto ik heb gevonden
zo iets leilijk heb ik nog nooit in mijn leven gezien
4bist du das auf dem foto?
das foto solltest du wirklich sehen
hab ich dir das foto schon gezeigt?
kennst du das foto schon?
schau mal das foto an
schau mal welches foto ich gefunden hab
so will ich nicht aussehen wenn ich alt bin
unglaublich welche fotos leute von sich machen schau mal
wie findest du das foto?
5c'est la photo la plus marrante!
devrais-je mettre cette photo de profile?
dis moi ce que tu pense de cette photo de moi?
je n'arrive pas a croire que j'ai encore cette photo de toi depuis l'hiver dernier.
je ne pense pas que je vais pouvoir dormir après avoir vu ces photos.
mes parents vont me tués si ils trouvent cette photo
6chi e in questa foto?
conosci la persona in questa foto?
dopo che hai visto la foto, tu non dormirai piu
hai visto questa foto?
la foto e grandiosa!
ti piace la foto?
ti ricordi la Foto?
7i cant believe i still have this picture
i don't think i will ever sleep again after seeing this photo
should i make this my default picture?
tell me what you think of this photo
tell me what you think of this picture i edited
this is the funniest photo ever!

Loading...