Sirefef: what it is and how to remove it

Sirefef, or otherwise known as ZeroAccess or max++, is a malware-dropper that is known for its ability to hide itself on the infected computer. Numerous versions of the threat have been released over the years, although its main function is to gather relevant information about the machine and then use it as a tool to insert additional malware payloads.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If GoogleUpdate.exe returns after removal, a full scan can find the entry that brings it back.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Sirefef yourself 6 steps, about 18 minutes, no software needed.

Start the steps
Sirefef: trojan rootkit malware zero access
Sirefef as our 2019 report showed it.

Sirefef: summary

DistributionSecurity researchers noticed various versions of Sirefef being distributed via software cracks/keygens, exploits or by exploiting software vulnerabilities
NameSirefef
TypeTrojan, rootkit, backdoor
Also known asRootkit.sirefef.spy, ZeroAccess, Zero Access, max++, Win32/Sirefef, Patched.B.Gen
Operating systemAll versions of Windows (64 and 32-bit)
FunctionalityThe malware is multi-functional, and can be set to perform a variety of different tasks, including, but not limited to: Disabling anti-malware software Downloading and installing new malware Intercepting and redirecting browser traffic Using the host as a backdoor Including the host into a botnet Heavily modify Windows features and settings, including various services
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
SymptomsThe only infection indicator is the warnings from security software (if not disabled). In some rare cases, victims might notice increased amount of ads, high CPU/memory usage, crashing programs, etc.
Detection namesNo Microsoft detection name is known
DamageNot recorded in the old report
Evidence5 write-ups by security sites; no sample analysed yet
File namesGoogleUpdate.exe
First seen16 December 2019
Microsoft Defender nameVirus:Win32/Sirefef
Facts checked6 October 2026

What Sirefef does on an infected PC

From our report of Dec 2019 · not reviewed since

Sirefef - prolific malware that seeks to open a backdoor on the host machine

Sirefef, or otherwise known as ZeroAccess or max++, is a malware-dropper that is known for its ability to hide itself on the infected computer.

Numerous versions of the threat have been released over the years, although its main function is to gather relevant information about the machine and then use it as a tool to insert additional malware payloads. Rootkit.sirefef.spy distribution methods can vary, although it is usually proliferated with the help of other malware, such as Necurs Trojan.

Sirefef virus is a multi-functional malware, meaning that it employs several modules that perform different tasks on the system. For example, one component is set to open a backdoor, another one - block the firewall and security software, the next one can be used for downloading malicious files and updates from the internet, and so on.

Besides, Rootkit.sirefef.spy trojan can also intercept and redirect HTTP traffic to pre-determined sites, consequently generating ad revenue for the attackers.

Because Rootkit.sirefef.spy is a Trojan and its functionality mainly consists of background activities, it can remain on the system undetected for days or even months. However, because some variants of the virus are known to redirect traffic to unknown domains, aggressive ads and redirects on Google Chrome, Mozilla Firefox, Internet Explorer or another browser can serve as a good sign of system compromise.

However, be aware that the Sirefef rootkit is not the only threat that can cause browser redirects, as it is also a functionality of adware, as well as browser hijackers, which are both much lesser threats than Rootkit.sirefef.spy Trojan. The best way to check for malicious activity is to scan the computer with anti-malware software, such as , , or another reputable security program.

Other symptoms that might be related to Rootkit.sirefef.spy infection includes (although users will rarely experience anything at all, making the detection and Sirefef removal a much more complicated task):

It is important to note that Sirefef Trojan can disable some security applications post-infection, which only increases its prevalence n the infected device. Due to this, as well as the low occurrence of signs of the infection, users might not be aware that they are infected for weeks or even months.

This is why regular computer scans with anti-malware are so important. As evident, if you have an anti-malware installed and it is not performing pre-determined scans, there is a good chance that malware like Rootkit.sirefef.spy has disabled it.

To remove Sirefef rootkit and to prevent from stopping the anti-virus, experts advise accessing Safe Mode with Networking and performing a full system scan with anti-malware software. The Safe Mode launches with only necessary drivers and system components, disabling malware' functions.

However, be aware that rootkits and other malicious software might permanently damage system components on Windows.

  • High CPU or memory usage
  • Crashing applications or Windows
  • Overall slow computer operation
Sirefef: trojan rootkit malware zero access
Sirefef in our 2019 report.
Sirefef: virus malware zeroaccess
Sirefef in our 2019 report.

From our report of Dec 2019 · not reviewed since

Infection routine

As previously mentioned, there have been multiple Sirefef variants released over the years, and each possesses some differences from another version, and distribution, prevalence, and obfuscation techniques may vary.

Some of the variants were noticed to come as an executable GoogleUpdate.exe - it is very common for malicious actors to disguise the primary executable under legitimate names to prevent users from being suspicious. The executable is placed into a newly created folder inside the %ProgramFiles% and %APPDATA% directories, begging the infection routine.

Rootkit.sirefef.spy also initiates changes inside Windows registry, modifying the following keys:

Sirefef also creates a separate folder here multiple files are dropped, and the malicious code inside is used to communicate with other infected devices as well as attackers' servers via peer-to-peer. This ensures that hackers can enable new functions or update malware when desired remotely.

Rootkit.sirefef.spy tampers with system drivers by replacing legitimate ones with malicious ones. These drivers might be picked up by AV vendors as Virus:Win32/Sirefef or TrojanDropper:Win32/Sirefef.B. Additionally, the malware turns off various system components that are vital to secure OS, including Windows Firewall, Windows Update, RemoteAccess, etc.

Sirefef: detected by various av vendors
Sirefef in our 2019 report.

From our report of Dec 2019 · not reviewed since

Pirated software installers and software vulnerabilities are the most common attack vectors

Most of the users will come close to malicious attacks when using Windows computers, but whether they infect them with malware depends on multiple factors, and the most important one is awareness. As evident, acting responsibly online and secure the OS with powerful anti-malware software will bring the best results.

First thing's first: do not download pirated software, as well as keygens/cracks that can enable full version of the program that is otherwise not free. Torrent and similar P2P networks are known to be insecure as not much effort are put into protecting users on those sites. In fact, some website owners allow malicious actors to insert JavaScript-based ads that would download and install malware automatically (by exploiting software vulnerabilities).

To avoid the latter, you need to ensure that all your browsers and the operating system are running the latest versions. For that, you should never delay the updates and rather enable the auto-update feature.

From our report of Dec 2019 · not reviewed since

More from our earlier report on Sirefef

  • Use most up-to-date security software and perform a full system scan in Safe Mode with Networking
  • To restore Windows registry and recover from system crashes post-infection, use

How to check the PC for Sirefef

Which name will your scanner show?

Microsoft's name for Sirefef is Virus:Win32/Sirefef.

Defender sorts threats by category first, so the word before the colon tells you what kind of program was found, even if the family name means nothing to you.

Do not search for a removal tool by the detection name alone; fake "removal tools" use the same keywords. How the naming works is explained in our guide to antivirus detection names.

  • File: GoogleUpdate.exe

How to remove Sirefef

How to remove Sirefef and lock the attacker out

Someone may have had remote control of the PC.

Cut the connection first, then remove the trojan and secure your accounts.

  1. Step 1: Remove remote access tools and lock the attacker out

    Attackers keep access through remote control tools and extra user accounts. Disconnect the PC from the internet, then remove every remote access program you did not install yourself from the installed apps list in Windows 11 or Windows 10.

    Look for a user account you do not know and delete it, and switch off Remote Desktop in Settings > System. Reconnect only for the scan.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  2. Step 2: Check where GoogleUpdate.exe runs from and stop it

    In Task Manager (Ctrl + Shift + Esc) find GoogleUpdate.exe on Processes, right-click it and choose Open file location before ending anything.

    Windows' own files live in C:\Windows\System32; the same name in %AppData%, %Temp% or C:\Users\Public is an impostor. If the folder is wrong, right-click the process again, choose End task and delete the file.

    If it starts again within seconds, a task or another process restarts it, so run the scan step in Safe Mode. Task Manager works the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Close a frozen app (Task Manager, Force Quit) On uGetFix

  3. Step 3: Delete scheduled tasks that bring it back

    Programs like Sirefef add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  5. Step 5: Scan the PC, then run the offline scan

    A scan finds the parts of Sirefef that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  6. Step 6: Change passwords from another device and sign out other sessions

    Sirefef can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Manual removal using Safe Mode

Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.

Step 1. Access Safe Mode with Networking

Manual malware removal should be best performed in the Safe Mode environment.

Windows 7 / Vista / XP

  1. Click Start > Shutdown > Restart > OK.
  2. When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  3. Select Safe Mode with Networking from the list.Windows 7/XP

Windows 10 / Windows 8

  1. Right-click on Start button and select Settings.
    Settings
  2. Scroll down to pick Update & Security.
    Update and security
  3. On the left side of the window, pick Recovery.
  4. Now scroll down to find Advanced Startup section.
  5. Click Restart now.
    Reboot
  6. Select Troubleshoot.Choose an option
  7. Go to Advanced options.Advanced options
  8. Select Startup Settings.Startup settings
  9. Press Restart.
  10. Now press 5 or click 5) Enable Safe Mode with Networking.Enable safe mode

Step 2. Shut down suspicious processes

Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Click on More details.
    Open task manager
  3. Scroll down to Background processes section, and look for anything suspicious.
  4. Right-click and select Open file location.
    Open file location
  5. Go back to the process, right-click and pick End Task.
    End task
  6. Delete the contents of the malicious folder.

Step 3. Check program Startup

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Go to Startup tab.
  3. Right-click on the suspicious program and pick Disable.
    Startup

Step 4. Delete virus files

Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:

  1. Type in Disk Cleanup in Windows search and press Enter.
    Disk cleanup
  2. Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
  3. Scroll through the Files to delete list and select the following: Temporary Internet Files
    Downloads
    Recycle Bin
    Temporary files
  4. Pick Clean up system files.
    Delete temp files
  5. You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter): %AppData%
    %LocalAppData%
    %ProgramData%
    %WinDir%

After you are finished, reboot the PC in normal mode.

From our report of Dec 2019 · not reviewed since

Access Safe Mode to remove Sirefef virus

Trojans are very malicious cyber threats, so it is important to remove Sirefef from your computer because it may not only use it and your Internet resources for illegal purposes, it can also try to delete your valuable files, steal your sensitive information and so on. Additionally, it may open a remote control connection to your PC and let additional threats inside your computer.

When trying to perform Sirefef removal on your system, it may kill your anti-spyware and its processes. Once inside, you should employ the most up-to-date anti-malware tool and run a full system scan.

[GI=method-1]Rootkit.sirefef.spy can disable various anti-malware tools, along with other security components, in order to prevent its removal. Access Safe Mode with Networking and perform a full system scan:

After removal: passwords, accounts and prevention

Accounts come next

Because the PC showed an unfamiliar process called GoogleUpdate.exe in Task Manager, a sign of a program that could read browser data, the clean-up is only half of the work.

The other half happens in your online accounts.

Change passwords from a clean device, beginning with e-mail; sign out of all sessions; check forwarding rules and recovery phone numbers; and turn on two-step verification with an authenticator app or a passkey. Ask your bank to replace cards saved in the browser.

Why the order matters and what to check in each account: secure your accounts after malware.

Choose a proper web browser and improve your safety with a VPN tool

Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.

One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.

However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.

Lost your files? Use data recovery software

While some files located on any computer are replaceable or useless, others can be extremely valuable.

Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:

  • power cuts
  • Blue Screen of Death errors
  • hardware failures
  • crypto-malware attack
  • even accidental deletion

To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.

Questions about Sirefef

Is GoogleUpdate.exe safe?

It depends on where the file is and who signed it, not on the name. Open Task Manager, go to the Details tab, right-click GoogleUpdate.exe and choose Open file location. A file inside Program Files or System32 with a valid digital signature from a known company is usually part of a legitimate program.

A file in AppData, Temp or ProgramData with no signature, especially one that restarts itself after you end it, is suspicious. If you cannot tie the process to anything you installed, uninstall recent unfamiliar programs and run a Microsoft Defender Offline scan.

What does the name Virus:Win32/Sirefef tell me?

Microsoft builds names in a fixed order:

  • category
  • then platform
  • then family
  • sometimes followed by a variant letter
  • a suffix

The category is the most useful part for you. Trojan, Backdoor and PWS mean real malware that can download more, give remote access or steal passwords. PUA means unwanted software.

Ransom means ransomware. Suffixes such as !ml or !MTB mean the detection came from machine learning or behaviour analysis. Search for the family part of Virus:Win32/Sirefef together with the word Microsoft to find its entry in Microsoft's security encyclopedia.

Can I delete the GoogleUpdate.exe file?

Only after you know what it belongs to. If GoogleUpdate.exe is part of a program, uninstall that program through Settings instead, so its services and tasks go too. If it belongs to nothing and is unsigned, end the process, disable whatever starts it and then delete its folder.

Do not delete files from the Windows folder or files signed by Microsoft: those are part of the system, and removing them can stop Windows from starting. When in doubt, run a Microsoft Defender scan first and let it decide.

Should I change my passwords after Virus:Win32/Sirefef?

It depends on the category and on whether the file ran. If the name begins with PWS, Spy, Backdoor or Trojan and the file sat in AppData, ProgramData or Temp, assume it ran and change your important passwords from a different device, starting with e-mail, then banking.

Sign out of all sessions too. If Virus:Win32/Sirefef is a PUA or was caught in Downloads before you opened anything, a password change is a precaution rather than a must. When in doubt, change the e-mail password and turn on two-step verification; it is quick and protects everything else.

Is GoogleUpdate.exe a virus?

If it sits outside the Windows and Program Files folders and your antivirus links it to Sirefef, yes. GoogleUpdate.exe is the file name used by this trojan. Some trojans borrow the names of real Windows components, so the name alone does not decide it:

  • right-click the process in Task Manager
  • choose Open file location
  • look at the folder and the publisher under Properties > Details

A file in a user folder with no publisher is the trojan. Do not delete it by hand while it runs; use the offline scan in the plan above.

Is Microsoft Defender enough to remove Sirefef?

For most home PCs it is a solid first step. Defender detects this threat as Virus:Win32/Sirefef, and a full scan followed by an offline scan covers the places where Sirefef usually hides. The offline scan runs before Windows starts, so malware that hides while Windows is running cannot interfere: Run a Microsoft Defender Offline scan.

Defender does not undo everything, though. It does not restore browser settings, decrypt files or change passwords that may have been copied, which is why this guide has separate steps for those. If Defender finds the same item again after removal, something else keeps reinstalling it.

Should I check my other computers too?

Yes, it takes little time and removes doubt. Sirefef itself usually stays on one PC, but the download that carried it may have been copied to other computers, shared drives may hold the same installer, and an attacker who had access could have tried saved passwords on other devices.

Run a full scan on every Windows PC in the home or office, check shared folders for the original download, and change Wi-Fi and router passwords if they were stored on the infected machine.

Should I report Sirefef?

Report it if you lost money, if accounts were taken over, if you are a business, or if the trojan came through a scam call. A police or national cybercrime report gives you a reference number for your bank and insurer and helps link cases.

You do not need to report a trojan that antivirus blocked before it ran. Before reporting, write down the dates, the detection name, file names and any messages or transactions linked to the attack; screenshots of antivirus alerts are useful evidence. The country list is in the report section above.

How do I know if my PC has Sirefef?

Often you do not, which is the point of a trojan. Possible signs are an antivirus alert naming Sirefef or a generic trojan detection, unknown programs or scheduled tasks, processes with random names in Task Manager, browser extensions you did not add, security settings turned off, slower performance, or account alerts about logins from unknown places.

The reliable check is a full scan followed by Microsoft Defender's offline scan. If you recently ran a crack, a fake installer or a command a website told you to paste, scan even without symptoms.

Will Fortect remove Sirefef?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Sirefef, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: Sirefef

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year