Malware

About “Sirefef.6865” infection

Malware Removal

The Sirefef.6865 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Sirefef.6865 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Sirefef.6865?


File Info:

name: 6435A16A834FACD9B7ED.mlw
path: /opt/CAPEv2/storage/binaries/22ee554ffa3270da4e19fa1352986a503155d1ade22becbae85fd4552cb352a3
crc32: D91CFFDB
md5: 6435a16a834facd9b7ed76e40a2264f6
sha1: 09597de590ba4984cdd06318eb23ed174e51a641
sha256: 22ee554ffa3270da4e19fa1352986a503155d1ade22becbae85fd4552cb352a3
sha512: 2097f92422b2f4a2704171c50dfb09cc719257cda4b1550be33456e59083b1ca70ecae99206b31183525e8bb70d32e402513b06ccab259dd6cc2cab025e653a0
ssdeep: 6144:Wiui2KQeZo9TcPVoOon/YrmBxBUXV/MJEGCo14nshUT:ePtMe/+K4Qz71apT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106849D2329961D67E5AC04BF2A6C7B18CCEFF82216A4B82F955114E908138B5DCFC75F
sha3_384: d162c31a1dae5acb1c5e2e330ef571c3def9de23bfa2659bd0c01f377a273b8c274401e208f5ddc51e3d12f2f20971f6
ep_bytes: 83ec0856e8c7feffff8b35704040006a
timestamp: 2012-07-12 20:57:35

Version Info:

LegalCopyright: Copyright Kensington Computer Products Group 2000-2002
CompanyName: Kensington Computer Products Group
FileDescription: Strip Converter
FileVersion: 1.0.0
ProductVersion: 1.0.0
InternalName: Strip Converter
OriginalFilename: stripconverter.exe
ProductName: Strip Converter
Translation: 0x0809 0x04b0

Sirefef.6865 also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.PWS.Panda.2000
MicroWorld-eScanGen:Variant.Sirefef.6865
FireEyeGeneric.mg.6435a16a834facd9
ALYacGen:Variant.Sirefef.6865
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.71505
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.a834fa
BitDefenderThetaGen:NN.ZexaF.34582.yy1@aCRZ@kdi
VirITTrojan.Win32.Generic.ATG
CyrenW32/Falab.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AIJX
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Sirefef.6865
NANO-AntivirusTrojan.Win32.Panda.dxxmin
AvastWin32:Spyware-gen [Spy]
TencentMalware.Win32.Gencirc.10b65680
Ad-AwareGen:Variant.Sirefef.6865
VIPREGen:Variant.Sirefef.6865
McAfee-GW-EditionGeneric BackDoor.abd
Trapminesuspicious.low.ml.score
SophosML/PE-A + Mal/NecursDrp-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Sirefef.6865
JiangminTrojanSpy.Zbot.busr
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R29893
McAfeeGeneric BackDoor.abd
TACHYONTrojan-Spy/W32.ZBot.406528.W
VBA32BScope.TrojanPSW.Panda
MalwarebytesTrojan.Agent.PHEX.Generic
APEXMalicious
RisingTrojan.Generic@AI.99 (RDML:2uy3Xee5OIDLsiUu23qqug)
YandexTrojan.GenAsa!1v+LGVJHX98
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.FJFE!tr
AVGWin32:Spyware-gen [Spy]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Sirefef.6865?

Sirefef.6865 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment