SHARE
THIS ON

Facebook Twitter Google Plus

Free Virus Removal Tools

PC infected with a specific virus? Get rid of it now, for free! Simply browse through our database of known viruses below and hit the download button to start the virus removal process!

shield

Remove all Viruses and Spyware

Let one of Bitdefender's Microsoft Certified Tech-Pros eliminate all your PC annoyances!

Find Out More
Virus activity

threat level

Alert level : medium
Latest news
UK Internet Providers Block Pirate Movie Websites
Large Internet Service Providers in the UK have started blocking access to Movie2K and Dow [...]
Read More
Chinese Hackers Resume Attacks against US Targets
The Chinese People’s Liberation Army’s Unit 61396 is again hitting US high-profile tar [...]
Read More
Hackers may have Seized 22 Million User IDs in Yahoo! Japan Hack
The Japanese division of Yahoo may have leaked roughly 22 million user IDs in a hack targe [...]
Read More
OSX Backdoor Found on Angolan Activist’s Mac, Apparently Downloaded from Romania
The Bitdefender labs are currently working on an analysis of a Mac OS X backdoor that has [...]
Read More
Internet criminals outstrip hacktivists to take back dominance of the internet underworld
Organized crime, data theft, and other “old school” methods for stealing information h [...]
Read More
New TDL Clones in the Wild
New TDL clones are making the rounds these days, according to Bitdefender Labs antimalware [...]
Read More
BTC Acceptance Rising – Among Cyber-thieves
While the actual Bitcoin currency might have its ups and downs, the notion that it is real [...]
Read More
Police Ransomware Trojan Morphs, Spreads
The Trojan.Icepol e-threat (that we’ve covered here before) is still alive and very [...]
Read More
MiniDuke – The Final Cut
Bitdefender Labs analysts have taken the time to put together an in-depth look at MiniDuke [...]
Read More
How to Target a Collection Tool – MiniDuke
The 2012 sample of MiniDuke is now fully analyzed and the results are in, revealing a surp [...]
Read More
Featured removal tool

Rootkit.Sirefef.Gen

HIGH
MEDIUM
2.7 MB
11.20.2012

ZeroAccess/Sirefef is a sophisticated kernel-mode rootkit that gets installed when a ZeroAccess dropper gets executed. Initially, the dropper checks to see whether it is running on a 32- or a 64-bit machine by querrying the ZWQueryInformationProcess api. If it runs on a system that has UAC enabled, the malware manipulates the system to make a legit application look as if it requires escalation. This is achieved by loading a clean copy of the FlashPlayer installer that is dropped to a temporary directory. The Windows Firewall is turned off and the malware will try to disable a series of security sub-systems such as WinDefend (Windows Defender service), wscsvc (Windows Security Center service), WinHttpAutoProxySvc (Proxy Auto Discovery service). If the dropper runs on a 32-bit operating system, ZeroAccess installs a kernel-mode rootkit. If it runs on a 64-bit machine, it executes its code directly from the memory. [...]

load more results