Skip to main content
Skip to main content
Microsoft Security Intelligence
1 entries found.
Updated on Nov 03, 2011

Trojan:WinNT/Sirefef.J is a component of Win32/Sirefef - a multi-component family of malware that moderates your Internet experience by changing search results and generating pay-per-click advertising revenue for its controllers. The family consists of multiple parts that perform different functions, such as downloading updates and additional components, hiding existing components, or performing a payload.

Note: This Sirefef variant has been observed using specific ports for its peer-to-peer communications. We strongly encourage you to block access to the following ports to limit Sirefef’s communication channels and prevent additional Sirefef components being downloaded:

  • 16464
  • 16465
  • 16470
  • 16471

You can read more about how to block access to a port in this article: http://support.microsoft.com/kb/813878

Alert level: severe