Home Malware Programs Trojans Trojan.Sirefef.J

Trojan.Sirefef.J

Posted: December 7, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 2,323
First Seen: December 7, 2011
Last Seen: December 14, 2022
OS(es) Affected: Windows

Trojan.Sirefef.J (Trojan:WinNT/Sirefef.J) is a rootkit Trojan that prevents affected web users from normal Internet surfing by changing search results in any legal search engine and creating pay-per-click advertising revenue for scammers. Trojan.Sirefef.J downloads updates and additional components and hides existing components on the compromised PC. Trojan.Sirefef.J uses advanced surreptitious techniques in an attempt to avoid detection and removal from the infected computer system. Trojan.Sirefef.J uses certain ports for its peer-to-peer communications.

Aliases

Generic.dx!b2c4 [McAfee]Gen:Variant.Graftor.25614 [BitDefender]Win32:Sirefef-WM [Rtk] [Avast]Trojan-FAHW!C8E3E7545E64 [McAfee]Trojan-FAHM!CBFDB9BAF82F [McAfee]Trojan-FAHM!718799C91EF9 [McAfee]Trojan.Sirefef.C [CAT-QuickHeal]Trojan-FAHM!3D3C16F3D89A [McAfee]Hider.OMW [AVG]Troj/ZAccess-AA [Sophos]TR/Sirefef.22 [AntiVir]TrojWare.Win32.Rootkit.ZAccess.A [Comodo]Win32:Malware-gen [Avast]Win32/Sirefef.DM [NOD32]RootKit [K7AntiVirus]
More aliases (773)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



H:\$RECYCLE.BIN\S-1-5-21-4293716402-2719066458-434042674-1001\$RVVGURN\WirelessKeyView.exe File name: WirelessKeyView.exe
Size: 48.64 KB (48640 bytes)
MD5: 8a943cedfce028c2916a57530b7f7e68
Detection count: 382
File type: Executable File
Mime Type: unknown/exe
Path: H:\$RECYCLE.BIN\S-1-5-21-4293716402-2719066458-434042674-1001\$RVVGURN\WirelessKeyView.exe
Group: Malware file
Last Updated: December 2, 2024
%USERPROFILE%\Application Data\Mkrjse27O.exe File name: Mkrjse27O.exe
Size: 387.07 KB (387072 bytes)
MD5: 2829e032070df80dbc1ea32408d91bd4
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: January 11, 2012
%WINDIR%\System32\drivers\afd.sys File name: afd.sys
Size: 138.36 KB (138368 bytes)
MD5: 36c7cb7f40cecdff7c5c7491bf126046
Detection count: 80
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: August 6, 2012
%USERPROFILE%\Application Data\8207RMW.exe File name: 8207RMW.exe
Size: 394.24 KB (394240 bytes)
MD5: f3f501a271be73f667ef275b588a3fef
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: March 22, 2012
%USERPROFILE%\Application Data\C2ru27.exe File name: C2ru27.exe
Size: 365.05 KB (365056 bytes)
MD5: 38af0f5e86bc1533119612eb37ac1c75
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: January 1, 2012
%USERPROFILE%\Local Settings\Application Data\lta.exe File name: lta.exe
Size: 283.13 KB (283136 bytes)
MD5: 3e59261ff1b8d29dac2d0fd6c6e2248d
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 12, 2011
%WINDIR%\TEMP\5689.sys File name: 5689.sys
Size: 141.31 KB (141312 bytes)
MD5: b1f5a542a8347b270284e4a06d91a40b
Detection count: 35
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: December 12, 2011
%WINDIR%\System32\drivers\netbt.sys File name: netbt.sys
Size: 185.85 KB (185856 bytes)
MD5: 7d65e94df92d2a7b06f25b31337e7bb2
Detection count: 30
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: March 1, 2013
%WINDIR%\System32\drivers\avgtdix.sys File name: avgtdix.sys
Size: 108.55 KB (108552 bytes)
MD5: aa743f421819644472aafc3fc557f41a
Detection count: 26
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: November 6, 2012
%APPDATA%\msnet\treecsc.exe File name: treecsc.exe
Size: 75.77 KB (75776 bytes)
MD5: 2cd9a12167e647c1ca66d9b1788a7206
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\msnet
Group: Malware file
Last Updated: December 12, 2011
%USERPROFILE%\Documents\bBqj2.exe File name: bBqj2.exe
Size: 392.19 KB (392192 bytes)
MD5: 4731fd0e40e2216fc0fa2ee365021a16
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents
Group: Malware file
Last Updated: March 13, 2012
%WINDIR%\System32\drivers\mrxsmb.sys File name: mrxsmb.sys
Size: 451.45 KB (451456 bytes)
MD5: d3e5303de61482ccf10a27bce6ec7a53
Detection count: 14
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: February 6, 2013
%USERPROFILE%\Application Data\88sICQ1J.exe File name: 88sICQ1J.exe
Size: 375.8 KB (375808 bytes)
MD5: f9471d2f63aee899001c51e84925ae11
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: May 9, 2012
%USERPROFILE%\Start Menu\Programs\Startup\Demokratska4.exe File name: Demokratska4.exe
Size: 493.3 KB (493305 bytes)
MD5: 9262bf8d8d46bd919855e620c86db659
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 12, 2011
%ALLUSERSPROFILE%\Application Data\yIrumcUIGGU.exe File name: yIrumcUIGGU.exe
Size: 457.35 KB (457352 bytes)
MD5: d1ca58cb53973e6ae7c67b2fc2cbf929
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: December 12, 2011
%ALLUSERSPROFILE%\Application Data\FNFPDoJienHIJQ.exe File name: FNFPDoJienHIJQ.exe
Size: 441.99 KB (441992 bytes)
MD5: 30e4df2f48504219004de7670dbd8208
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: December 12, 2011
%WINDIR%\System32\DRIVERS\serial.sys File name: serial.sys
Size: 64.51 KB (64512 bytes)
MD5: 91db9c3d5cabf92f2442cb58b730ed55
Detection count: 7
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: March 4, 2013
%ALLUSERSPROFILE%\Application Data\AnRKntfWhA.exe File name: AnRKntfWhA.exe
Size: 466.94 KB (466944 bytes)
MD5: 93ce3afecbba40a99e2d6e285a1a72fc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: December 12, 2011
%WINDIR%\System32\drivers\i8042prt.sys File name: i8042prt.sys
Size: 54.78 KB (54784 bytes)
MD5: b9e9772599b892492c5ff0e57836a708
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: March 4, 2013
%WINDIR%\System32\drivers\csc.sys File name: csc.sys
Size: 387.58 KB (387584 bytes)
MD5: 718799c91ef914ed0282a936542f7c06
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: April 2, 2013
%WINDIR%\System32\DRIVERS\ipsec.sys File name: ipsec.sys
Size: 74.75 KB (74752 bytes)
MD5: cbfdb9baf82f84b1a555bfa559dea745
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: April 2, 2013
%WINDIR%\System32\drivers\dfsc.sys File name: dfsc.sys
Size: 78.33 KB (78336 bytes)
MD5: 4163e068f8ce38d7a43d145611da6d13
Detection count: 1
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: November 26, 2012
%USERPROFILE%\Local Settings\Application Data\gsx.exe File name: gsx.exe
Size: 358.4 KB (358400 bytes)
MD5: 9affbbc310bc761345effbe55bee165f
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 12, 2011

More files
Loading...