Trojan

Trojan:Win64/Sirefef.B (file analysis)

Malware Removal

The Trojan:Win64/Sirefef.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Sirefef.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Trojan:Win64/Sirefef.B?


File Info:

name: 7DC58227898A0C622C1C.mlw
path: /opt/CAPEv2/storage/binaries/26c96580b42842da89bc91f49f2400a13754427464c4a83bdfae93783208b0c9
crc32: 58D5B066
md5: 7dc58227898a0c622c1c4f4a2c634e7d
sha1: a29a4b6b13271136cf8f07a2a29724ba49881bd7
sha256: 26c96580b42842da89bc91f49f2400a13754427464c4a83bdfae93783208b0c9
sha512: b71ca39032be8ca2cac271b26f92b95ac649d37fde334ff96c786f915f3d632b750ee16933a1d988af37d786d46684ca548d06ffb71dce44de3b94ef91acc720
ssdeep: 6144:Cf+B0T0OumokS2eedqjOA3knrj0nV9ONhvsoAfeaf:CZTIkSFeGj3kvSV9ONJ02a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12634F11DF9489896E0F425B77425AB096631FD0E9C064A372472BFAFB87A782ED130D4
sha3_384: c5b0561387633f60dfb06f21dd6b62899f65589cf5de6b185cdb787d9498f035b95eec3aa6b76aacf6fbca64d3e53ac6
ep_bytes: 558bec81ec4403000056575350ff1500
timestamp: 2005-09-29 21:21:21

Version Info:

0: [No Data]

Trojan:Win64/Sirefef.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lrq3
Elasticmalicious (high confidence)
DrWebBackDoor.Maxplus.190
MicroWorld-eScanGen:Heur.Conjar.9
FireEyeGeneric.mg.7dc58227898a0c62
CAT-QuickHealTrojan.Sirefef.B
SkyhighBehavesLike.Win32.ZeroAccess.dc
McAfeeZeroAccess.gr
ZillyaTrojan.Jorik.Win32.24250
K7AntiVirusTrojan ( 0030ac401 )
AlibabaVirTool:Win32/Obfuscator.bd65fd22
K7GWTrojan ( 0030ac401 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.omW@am28TD
VirITTrojan.Win32.Generic.ANFQ
SymantecTrojan.Zeroaccess
ESET-NOD32Win32/Sirefef.DD
APEXMalicious
TrendMicro-HouseCallBKDR_CYCBOT.SMEE
ClamAVWin.Trojan.Agent-1034358
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.9
NANO-AntivirusTrojan.Win32.SirefefJ.cxhqit
AvastWin32:Crypt-KSW [Trj]
TencentWin32.Trojan.Generic.Itgl
EmsisoftGen:Heur.Conjar.9 (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Heur.Conjar.9
TrendMicroBKDR_CYCBOT.SMEE
Trapminemalicious.high.ml.score
SophosMal/FakeAV-IS
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.srx
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.ZAccess
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win64/Sirefef.B
XcitiumTrojWare.Win32.ZAccess.KX@4llwdi
ArcabitTrojan.Conjar.9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Conjar.9
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.ZAccess.R14440
VBA32SScope.Malware-Cryptor.Maxplus.0997
Cylanceunsafe
PandaTrj/Genetic.gen
RisingHackTool.Obfuscator!8.236 (TFE:3:y6IkwMoPvpQ)
YandexTrojan.Sirefef!N73+BDI/Jcc
IkarusTrojan.Win32.Ransom
MaxSecureTrojan.Malware.3185309.susgen
FortinetW32/Kryptik.XDE!tr
AVGWin32:Crypt-KSW [Trj]
Cybereasonmalicious.7898a0
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Conjar

How to remove Trojan:Win64/Sirefef.B?

Trojan:Win64/Sirefef.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment