Home Malware Programs Trojans Win32/Sirefef.er

Win32/Sirefef.er

Posted: March 21, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 21
First Seen: March 21, 2012
Last Seen: October 3, 2021
OS(es) Affected: Windows

Win32/Sirefef.er is a relatively small component of an overall Sirefef or ZeroAccess infection that may install fake security programs, hijack your search results or use your PC to generate fraudulent Pay-Per-Click revenue. Because Win32/Sirefef.er is designed for the singular purpose of launching and deactivating other Sirefef-based PC threats, Win32/Sirefef.er is only harmful in the context of assisting its Sirefef Trojans and scamware relatives. Due to the near-certainty of any Win32/Sirefef.er infection including other Sirefef-based dangers to your computer, SpywareRemove.com malware research team recommends that you use anti-malware software to detect and remove Win32/Sirefef.er and its relatives whenever you suspect the presence of a Sirefef infection. By itself, Win32/Sirefef.er doesn't show significant symptoms, although related PC threats may create visible attacks, such as browser redirects or fake pop-up alerts.

Win32/Sirefef.er: the Trigger on the Virtual Gun That's Held to Your Computer

Win32/Sirefef.er is a Trojan that functions as an on-off switch for other components of a Sirefef-based attack. In addition to enabling or disabling other PC threats as necessary, Win32/Sirefef.er will also monitor Sirefef's status and report this back to the Service Control Manager. Although Win32/Sirefef.er is a Windows-only PC threat, from Windows Win32/Sirefef.er can launch PC threats without any visible symptoms whatsoever, and due to this, SpywareRemove.com malware experts rate Win32/Sirefef.er as a potentially high-level danger to your computer. Win32/Sirefef.er was first identified early in 2012, and if your anti-malware software is outdated, you should consider updating its database to enable complete detection and removal of Win32/Sirefef.er.

Your anti-malware programs may also identify Win32/Sirefef.er by other names, such as Trojan:Win32/Sirefef.AA, Trojan.Sirefef.BP, Troj/ZAccess-AB, TR/Sirefef.BP.1, TROJ_SIREFEF.KN and ZeroAccess.dr.gen.d. Under normal circumstances, Win32/Sirefef.er will always have other PC threats working alongside Win32/Sirefef.er, and SpywareRemove.com malware researchers note the importance of scanning your entire computer to detect other components in a Sirefef or ZeroAccess-based infection. Deleting Win32/Sirefef.er can result in other PC threats reinstalling Win32/Sirefef.er if they aren't also removed at the same time.

Detecting Win32/Sirefef.er and Its Friends by Their Payload

Win32/Sirefef.er, while showing no real symptoms of its own for easy detection, can be indirectly detected by watching for the symptoms that are often associated with its fellow Sirefef Trojans. Some of the most easily seen symptoms that SpywareRemove.com malware analysts have found include:

  • The presence of fake security software. Rogue security scanners may create inaccurate infection alerts, fake announcements of application damage or scanner results that include nonexistent infections.
  • Browser redirects, especially redirects that target your online searches. You may find yourself redirected to unusual search sites or find that your search results have been replaced with hostile websites.

As long as you avoid any recommendations that Win32/Sirefef.er's friends may make, such as advising you to purchase rogue security software, your PC shouldn't suffer immediate damage from a Win32/Sirefef.er-related attack. However, the longer you allow Win32/Sirefef.er to remain on your computer, the greater the chance that this heightened state of vulnerability will lead to other attacks that could cause long-lasting damage.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{89721a77-988b-43cb-81e4-89c101e44f15}InprocServer32
Loading...