Worm

Email-Worm.Win32.Klez.j removal guide

Malware Removal

The Email-Worm.Win32.Klez.j is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Email-Worm.Win32.Klez.j virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Email-Worm.Win32.Klez.j?


File Info:

name: 6C334CC04BB52950D0C7.mlw
path: /opt/CAPEv2/storage/binaries/b27b16d941d9f814124848f5b41d4b6d9c841c926858821c56a0af89d08f248c
crc32: 2C1A19FA
md5: 6c334cc04bb52950d0c7e6f7087d14ec
sha1: c40f9f95c014a61fbcc00f39a6a89ca59e21cbe1
sha256: b27b16d941d9f814124848f5b41d4b6d9c841c926858821c56a0af89d08f248c
sha512: dbc9b95f2e4005250355464612fefe8cdcec592159df7fec95f14be005c72ad4ac6617d3a29ff59ad8ef5134a0215a3f7cbbda2ebdcab4c15666ff9714cb9adf
ssdeep: 1536:zaWLF1kxTnUI4CFPtv6iSJnaGlbVUhoch:zaWExTnUTCFPtvanaGlbVUhoc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F683AE27B9908473C796837052A95B259AFFD9321B97E1C3D7018A5B3C706E1DA3B30B
sha3_384: 679c388b15bb9fae4264c8249aad18a4b690f79acabe8f771c3162176195fd69965656136850b84b636cb196593f9359
ep_bytes: 558bec6aff6838d240006874a8400064
timestamp: 2002-01-18 01:22:13

Version Info:

0: [No Data]

Email-Worm.Win32.Klez.j also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Elkern.B
FireEyeGeneric.mg.6c334cc04bb52950
CAT-QuickHealW32.Klez.H
SkyhighBehavesLike.Win32.Klez.mm
ALYacDropped:Win32.Elkern.B
MalwarebytesKlez.Worm.FileInfector.DDS
ZillyaWorm.Klez.Win32.4
K7AntiVirusEmailWorm ( 000805561 )
K7GWEmailWorm ( 000805561 )
Cybereasonmalicious.04bb52
BaiduWin32.Worm.Klez.a
VirITWorm.Win32.Klez.J
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Klez
ZonerWorm.Win32.Klez.27775
APEXMalicious
ClamAVWin.Worm.Klez-2
KasperskyEmail-Worm.Win32.Klez.j
BitDefenderDropped:Win32.Elkern.B
NANO-AntivirusTrojan.Win32.Klez.fwaj
SUPERAntiSpywareWorm.Klez
AvastWin32:Klez-E [Wrm]
F-SecureWorm.WORM/Klez.E
DrWebWin32.HLLM.Klez.6
VIPREDropped:Win32.Elkern.B
TrendMicroWORM_KLEZ.GEN
Trapminemalicious.high.ml.score
SophosW32/Klez-Fam
SentinelOneStatic AI – Malicious PE
JiangminI-Worm/Klez.h
VaristW32/Klez.J@mm
AviraWORM/Klez.E
MAXmalware (ai score=85)
Antiy-AVLWorm[Email]/Win32.Klez
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Trojan.Agent.Gen@67u02
ArcabitWin32.Elkern.B
ViRobotI-Worm.Win32.Klez-gen
ZoneAlarmEmail-Worm.Win32.Klez.j
GDataWin32.Trojan.PSE.11SQ9WV
CynetMalicious (score: 100)
AhnLab-V3Win32/Klez.worm.I
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.fqY@aa5cMjd
VBA32BScope.Trojan.Meredrop
Cylanceunsafe
PandaW32/Klez.H
TrendMicro-HouseCallWORM_KLEZ.GEN
RisingWorm.Klez!1.A1CB (CLASSIC)
YandexTrojan.GenAsa!AMX6vz3TVj8
IkarusEmail-Worm.Win32.Klez.J
MaxSecureWorm.W32.Klez.h
FortinetW32/Klez.fam@mm
AVGWin32:Klez-E [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudBackdoor:Win/Agent.A(dyn)

How to remove Email-Worm.Win32.Klez.j?

Email-Worm.Win32.Klez.j removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment