Malware

About “W32.Klez.H” infection

Malware Removal

The W32.Klez.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.Klez.H virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine W32.Klez.H?


File Info:

name: F6C366D5A2CF469632E6.mlw
path: /opt/CAPEv2/storage/binaries/1322f52d55159100133e405fea8c8cd6c9d16c5b3a54eefb101522995e050510
crc32: 9D7FDBB0
md5: f6c366d5a2cf469632e6a7a212b6d14d
sha1: 22bb45728fa41e072037c710d54cb6af988efc9a
sha256: 1322f52d55159100133e405fea8c8cd6c9d16c5b3a54eefb101522995e050510
sha512: 6978bc1decce43dc523d2a8eed302458fdacf4e060524d79168056073e68638a03a615d15de25bd3f54a61073ff810916154bfd094078fc0eacc83f28d9f34e9
ssdeep: 1536:nWGxs9kGdYk8wO4CnmmQZzeZhhoba0JLx7GCC4I4PP6PcvPnyp3aOTotXQ:WGfGdYSCnsePhobv1GN86PcvgKOEtg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA84C902432220A7D65434B5C05A7B8A06906FF93DA7E536FE157406FA72BCA4E335FE
sha3_384: 60b3ee8790b7ec36ca5dc1ea6b59e867c3bbdc69182dbb27ac0ab3cd085eec376a3143047884b8cc71c06a7ae0ea2d84
ep_bytes: 5589e96aff6840d240006804ac400064
timestamp: 2002-04-13 01:49:44

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Reader 8.0
FileVersion: 8.0.0.2006102300
LegalCopyright: Copyright 1984-2006 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Reader
ProductVersion: 8.0.0.2006102300
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

W32.Klez.H also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Klez.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.Klez.DAR
ClamAVWin.Trojan.Elkern-2
FireEyeGeneric.mg.f6c366d5a2cf4696
CAT-QuickHealW32.Klez.H
McAfeeW32/Klez.gen@MM
Cylanceunsafe
ZillyaWorm.Klez.Win32.1
SangforSuspicious.Win32.Save.ins
AlibabaWorm:Win32/fragment.33785b10
Cybereasonmalicious.5a2cf4
ArcabitWin32.Worm.Klez.DAR
BitDefenderThetaGen:NN.ZexaF.36250.xu0@a4DfNOji
CyrenW32/Klez.H@mm (corrupted)
SymantecW32.Klez.H@mm
ESET-NOD32a variant of Win32/Klez
ZonerWorm.Win32.Klez.32858
APEXMalicious
CynetMalicious (score: 100)
KasperskyEmail-Worm.Win32.Klez.h
BitDefenderWin32.Worm.Klez.DAR
AvastWin32:Injected-AZ
TencentTrojan.Win32.Klez.b
EmsisoftWin32.Worm.Klez.DAR (B)
BaiduWin32.Worm.Klez.b
F-SecureMalware.W32/Elkern.C
DrWebWin32.HLLM.Klez.4
VIPREWin32.Worm.Klez.DAR
TrendMicroWORM_KLEZ.GEN
McAfee-GW-EditionBehavesLike.Win32.Klez.fm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
JiangminI-Worm/Klez.h
AviraW32/Elkern.C
Antiy-AVLWorm[Email]/Win32.Klez.h
MicrosoftWorm:Win32/Klez.H@mm
ZoneAlarmEmail-Worm.Win32.Klez.h
GDataWin32.Worm.Klez.H
GoogleDetected
VBA32MalwareScope.Worm.Klez.1
ALYacWin32.Worm.Klez.DAR
MAXmalware (ai score=80)
MalwarebytesWorm.Klez
PandaGeneric Suspicious
TrendMicro-HouseCallWORM_KLEZ.GEN
RisingWorm.Klez!1.A1CB (CLASSIC)
YandexTrojan.GenAsa!URVqVkT3TU0
IkarusWorm.Win32.Klez
MaxSecureWorm.W32.Klez.h
FortinetW32/Wacatac.B!tr
AVGWin32:Injected-AZ
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32.Klez.H?

W32.Klez.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment