Malware

Sirefef.3 removal guide

Malware Removal

The Sirefef.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Sirefef.3 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Sirefef.3?


File Info:

name: D0B74A895A9DF3ECE25A.mlw
path: /opt/CAPEv2/storage/binaries/50566bcc96cff9ec855c20d08b0899e8237aba1d8a2624bf11b7bb54f014a067
crc32: A906DD5C
md5: d0b74a895a9df3ece25ae71b41bceaf4
sha1: 54bb36f628bb6c15f0cd710b333baa36eca36739
sha256: 50566bcc96cff9ec855c20d08b0899e8237aba1d8a2624bf11b7bb54f014a067
sha512: 76e8fbf571648e54074de3cb86c276b310362ab7d61f41c157d4595cd74a0da18b7b04ed9b0617969a17d9910b8581d97d967f97613792457f771bbfa9acc24a
ssdeep: 3072:RHYw3TXNun4qL1LXDAZheVd8qsgsmGropGSpXxFl/l4962iHu7GReqNQtUGZg9B/:KwDXNU4m1LmoeyGw/l4DiO7iLQuG88
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0141292CA683567E1D3E8370CFF412A9A045474B7779A978B0E6F48ED650B12A70F3C
sha3_384: cddaa4e3bec41b24e3da9f6268f0c9d2ad981f011cf1f56766af1764bff07f5bba20f69ac86a0d9e070e3430194fe089
ep_bytes: 60be00c041008dbe0050feff5783cdff
timestamp: 2011-05-17 16:32:46

Version Info:

CompanyName: Fears Snug Void Thai
FileDescription: Vexes Car Buddy
FileVersion: 2.4
InternalName: Stern Billy Amuse Vents
LegalCopyright: Copyleft © Beach Fount 2001-2006
OriginalFilename: Emily.exe
ProductName: Theta
ProductVersion: 2.4
Translation: 0x0409 0x04b0

Sirefef.3 also known as:

LionicTrojan.Win32.Zbot.lijp
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Sirefef.3
ClamAVWin.Trojan.Zbot-27150
FireEyeGeneric.mg.d0b74a895a9df3ec
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeeGeneric BackDoor.sw
ZillyaTrojan.Kryptik.Win32.119769
K7AntiVirusTrojan ( 004d06f31 )
AlibabaTrojan:Win32/Kryptik.b299f9b3
K7GWTrojan ( 004d06f31 )
ArcabitTrojan.Sirefef.3
BitDefenderThetaGen:NN.ZexaF.36132.mmKfaGn!wPmi
CyrenW32/Zbot.CQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.TFQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Sirefef.3
NANO-AntivirusTrojan.Win32.ZAccess.dcmwlh
SUPERAntiSpywareTrojan.Agent/Gen-Falint[Cont]
AvastWin32:Rootkit-gen [Rtk]
TencentWin32.Trojan.Generic.Qwhl
EmsisoftGen:Variant.Sirefef.3 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebBackDoor.Qbot.75
VIPREGen:Variant.Sirefef.3
McAfee-GW-EditionGeneric BackDoor.sw
Trapminemalicious.high.ml.score
SophosTroj/Zbot-AZB
IkarusTrojan.Spy.ZBot
JiangminTrojan/Generic.mhsm
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan[Backdoor]/Win32.ZAccess
XcitiumMalware@#l5mt8jc7ce84
MicrosoftVirTool:Win32/Obfuscator.QG
ViRobotBackdoor.Win32.A.ZAccess.206848
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Sirefef.3
GoogleDetected
AhnLab-V3Backdoor/Win32.ZAccess.R11524
VBA32Malware-Cryptor.ImgChk
ALYacGen:Variant.Sirefef.3
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic!8.C3 (CLOUD)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ZAccess.WIB!tr
AVGWin32:Rootkit-gen [Rtk]
DeepInstinctMALICIOUS

How to remove Sirefef.3?

Sirefef.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment