Worm

Klez.Worm.FileInfector.DDS removal guide

Malware Removal

The Klez.Worm.FileInfector.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Klez.Worm.FileInfector.DDS virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Klez.Worm.FileInfector.DDS?


File Info:

name: D4371BC689911550B45D.mlw
path: /opt/CAPEv2/storage/binaries/bac05b471be6f74926de529dcf03071c3482d40b176bfff22b92378ea9cf0af4
crc32: B53E34DB
md5: d4371bc689911550b45d316ae9bb13c0
sha1: 2cf5aac935425269fbcfb02fdf8d4d47c7e76d95
sha256: bac05b471be6f74926de529dcf03071c3482d40b176bfff22b92378ea9cf0af4
sha512: e33d650bd39540845c6b344b8d938248af6b35ec97b7c6f7195dc059c1661b54ad4f73cbf97dedf79d369e0e73b3e04fab918ad60fad362efcd4237076927288
ssdeep: 1536:zaWLF1kxTnUI4CFPtv6iSJnaGlbVxhog:zaWExTnUTCFPtvanaGlbVxho
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117838D23B9938073D496C27012B99B559AFE98321766E5C3D7018E7B3D70AD1DA3B30B
sha3_384: 59d07d3807488754b186bd4b14702cb10defff3da2dfa7df7c341389a9a6bc5813edfc3ab543e053c7602ac77e87367f
ep_bytes: 558bec6aff6838d240006874a8400064
timestamp: 2002-01-18 01:22:13

Version Info:

0: [No Data]

Klez.Worm.FileInfector.DDS also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Klez.t!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Elkern.B
FireEyeGeneric.mg.d4371bc689911550
CAT-QuickHealW32.Klez.H
SkyhighBehavesLike.Win32.Klez.mm
ALYacDropped:Win32.Elkern.B
Cylanceunsafe
ZillyaWorm.Klez.Win32.4
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 000805561 )
AlibabaMalware:Win32/km_24958.None
K7GWEmailWorm ( 000805561 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Klez.a
VirITWorm.Win32.Klez.J
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Klez
APEXMalicious
TrendMicro-HouseCallWORM_KLEZ.GEN
ClamAVWin.Worm.Klez-2
KasperskyEmail-Worm.Win32.Klez.j
BitDefenderDropped:Win32.Elkern.B
NANO-AntivirusTrojan.Win32.Klez.fwaj
SUPERAntiSpywareWorm.Klez
AvastWin32:Klez-E [Wrm]
TencentWorm.Win32.Klez.c
SophosW32/Klez-Fam
F-SecureWorm.WORM/Klez.E
DrWebWin32.HLLM.Klez.6
VIPREDropped:Win32.Elkern.B
TrendMicroWORM_KLEZ.GEN
Trapminemalicious.high.ml.score
EmsisoftDropped:Win32.Elkern.B (B)
SentinelOneStatic AI – Malicious PE
JiangminI-Worm/Klez.h
WebrootW32.Klez.Gen
GoogleDetected
AviraWORM/Klez.E
VaristW32/Klez.J@mm
Antiy-AVLWorm[Email]/Win32.Klez
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Klez.G@mm
XcitiumTrojWare.Win32.Trojan.Agent.Gen@67u02
ArcabitWin32.Elkern.B
ViRobotI-Worm.Win32.Klez-gen
ZoneAlarmEmail-Worm.Win32.Klez.j
GDataWin32.Trojan.PSE.11SQ9WV
CynetMalicious (score: 100)
AhnLab-V3Win32/Klez.worm.I
Acronissuspicious
McAfeeW32/Klez.f@MM
MAXmalware (ai score=83)
VBA32MalwareScope.Worm.Klez.1
MalwarebytesKlez.Worm.FileInfector.DDS
PandaW32/Klez.H
ZonerWorm.Win32.Klez.27775
RisingWorm.Klez!1.A1CB (CLASSIC)
YandexTrojan.GenAsa!AMX6vz3TVj8
IkarusEmail-Worm.Win32.Klez.J
MaxSecureWorm.W32.Klez.h
FortinetW32/Klez.fam@mm
BitDefenderThetaGen:NN.ZexaF.36744.fqY@aa5cMjd
AVGWin32:Klez-E [Wrm]
Cybereasonmalicious.935425
DeepInstinctMALICIOUS

How to remove Klez.Worm.FileInfector.DDS?

Klez.Worm.FileInfector.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment