Home Malware Programs Backdoors Win32/Sirefef.CH

Win32/Sirefef.CH

Posted: November 2, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 33
First Seen: November 2, 2011
OS(es) Affected: Windows

Win32/Sirefef.CH is a malicious backdoor Trojan that opens backdoor on the affected computer system and allows attackers to invade the compromised PC. Win32/Sirefef.CH redirects Internet users to malicious websites that advertise rogue software. Win32/Sirefef.CH blocks computer users from visiting legitimate web pages. Win32/Sirefef.CH may slow down your computer and steal personal information. Remove Win32/Sirefef.CH as early as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Desktop.ini File name: Desktop.ini
Size: 15.5 KB (15500 bytes)
MD5: 556f4c8c309d08de6cd3de68748694cd
Detection count: 11
Mime Type: unknown/ini
Group: Malware file
Last Updated: November 3, 2011
Desktop.ini File name: Desktop.ini
Size: 15.09 KB (15091 bytes)
MD5: 109dc99cdd53f8af5265a961840301aa
Detection count: 10
Mime Type: unknown/ini
Group: Malware file
Last Updated: November 3, 2011
Desktop.ini File name: Desktop.ini
Size: 13.86 KB (13868 bytes)
MD5: 441d97f39588b836cb1c8f6fd7803d7b
Detection count: 8
Mime Type: unknown/ini
Group: Malware file
Last Updated: November 3, 2011
Desktop.ini File name: Desktop.ini
Size: 25.6 KB (25600 bytes)
MD5: 922c6adf600a6cec1e6b2ceefe8b3696
Detection count: 7
Mime Type: unknown/ini
Group: Malware file
Last Updated: November 3, 2011
Desktop.ini File name: Desktop.ini
Size: 28.16 KB (28160 bytes)
MD5: 8674d6f9f88c8ae1ee0525f64aae4eb1
Detection count: 5
Mime Type: unknown/ini
Group: Malware file
Last Updated: November 3, 2011
%AllUsersProfile%\Application Data\.dll File name: %AllUsersProfile%\Application Data\.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AllUsersProfile%\Application Data\.exe File name: %AllUsersProfile%\Application Data\.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Windows\assembly\GAC_32\Desktop.ini File name: C:\Windows\assembly\GAC_32\Desktop.ini
Mime Type: unknown/ini
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Loading...