Worm

What is “Worm.Phorpiex.Generic”?

Malware Removal

The Worm.Phorpiex.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Phorpiex.Generic virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to remove evidence of file being downloaded from the Internet
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.wipmania.com

How to determine Worm.Phorpiex.Generic?


File Info:

crc32: 510E4B74
md5: 0a6569e45a3a38f7168f4c4aa0594627
name: 0A6569E45A3A38F7168F4C4AA0594627.mlw
sha1: af8d33d98a8248f1e393337428a742929b02418f
sha256: ad74f606e358fb7f6db9a5652d0a60310d069ac108934a72d0352e5fa9248b38
sha512: f0e74357cff0bc9a9c91cc911a6e214ab0fb29d68ab3e51f766d6e77c0e16836402b3c7093d61b988e0eaa1415de8f0766c10164b8730897ffad5c530ce48f07
ssdeep: 96:L1YtYF8d/XFvRxR2xs9it95PtboynunSzCt4:L12jWbr5P1oynWSq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm.Phorpiex.Generic also known as:

K7AntiVirusTrojan ( 0056d4f21 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.11
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056d4f21 )
Cybereasonmalicious.45a3a3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Phorpiex.AG
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.11
MicroWorld-eScanGen:Heur.Mint.Zard.11
Ad-AwareGen:Heur.Mint.Zard.11
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Agent.EQE@80vxxy
BitDefenderThetaGen:NN.ZexaF.34686.auW@a0A3T4li
McAfee-GW-EditionBehavesLike.Win32.Generic.xt
FireEyeGeneric.mg.0a6569e45a3a38f7
EmsisoftGen:Heur.Mint.Zard.11 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Caynamer.A!ml
GDataGen:Heur.Mint.Zard.11
AhnLab-V3Malware/Win32.Dlder.C3467007
Acronissuspicious
McAfeeRDN/Generic.hbg
MAXmalware (ai score=89)
VBA32BScope.Trojan.Caynamer
MalwarebytesWorm.Phorpiex.Generic
RisingWorm.Phorpiex!8.48D (TFE:dGZlOgUN9lLDNPuMzg)
IkarusWin32.Outbreak
FortinetW32/Phorpiex.AH!worm
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml

How to remove Worm.Phorpiex.Generic?

Worm.Phorpiex.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment