Malware

About “Win32/Klez” infection

Malware Removal

The Win32/Klez is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Klez virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Klez?


File Info:

name: 4471FAFA6CC8097E6E41.mlw
path: /opt/CAPEv2/storage/binaries/68262fa5f6410f12c460a81850b428a5dd93389d160317df7f1afd8b103f5f79
crc32: 611A8665
md5: 4471fafa6cc8097e6e411d7d2915c422
sha1: 4c8691de77bfe61852ffd3085e1338bebb2a6f38
sha256: 68262fa5f6410f12c460a81850b428a5dd93389d160317df7f1afd8b103f5f79
sha512: f98972cd4c00d177e8d5a888e28d222a7b307a92ade782d81a18401199c9764c9ada75f4e1ba52a699528013e826c9b43bbcb3d43a1a0819b5d710ef3dd81379
ssdeep: 1536:zWGxs9kGdYk8wO4Cn8Nn0FdaGihoba0JLx7GCC4I4PP6PcvPnyp3aOTotXQyzbw:KGfGdYSCnaHVhobv1GN86PcvgKOEtgb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D84DA06432220A7E15434B5C05A7B8A06906FF93DA7E536FE157406FA72BCA4E335FE
sha3_384: 6106201798d0dfc22c84d3ad9877f6cc789236cf23289e4794727462becc066314a7e8f2e4daf69e8a85fbce423d06f0
ep_bytes: 558bc86aff6840d240006804ac400064
timestamp: 2002-04-13 01:49:44

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Reader 8.0
FileVersion: 8.0.0.2006102300
LegalCopyright: Copyright 1984-2006 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Reader
ProductVersion: 8.0.0.2006102300
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

Win32/Klez also known as:

BkavW32.AIDetectMalware
AVGWin32:Injected-AZ
MicroWorld-eScanWin32.Worm.Klez.DAR
FireEyeGeneric.mg.4471fafa6cc8097e
ALYacWin32.Worm.Klez.DAR
Cylanceunsafe
ZillyaWorm.Klez.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0000409e1 )
K7GWTrojan ( 0000409e1 )
Cybereasonmalicious.a6cc80
BaiduWin32.Worm.Klez.b
CyrenW32/Klez.H@mm (corrupted)
SymantecW32.Klez.H@mm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Klez
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Elkern-2
KasperskyEmail-Worm.Win32.Klez.h
BitDefenderWin32.Worm.Klez.DAR
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Injected-AZ
TencentTrojan.Win32.Klez.b
SophosML/PE-A
F-SecureMalware.W32/Elkern.C
DrWebWin32.HLLM.Klez.4
VIPREWin32.Worm.Klez.DAR
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.Klez.fm
Trapminemalicious.high.ml.score
EmsisoftWin32.Worm.Klez.DAR (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Worm.Klez.H
JiangminI-Worm/Klez.h
AviraW32/Elkern.C
MAXmalware (ai score=87)
Antiy-AVLWorm[Email]/Win32.Klez.h
ArcabitWin32.Worm.Klez.DAR
ZoneAlarmEmail-Worm.Win32.Klez.h
MicrosoftWorm:Win32/Klez.H@mm
GoogleDetected
McAfeeW32/Klez.gen@MM
VBA32MalwareScope.Worm.Klez.1
MalwarebytesWorm.Klez
PandaGeneric Suspicious
TrendMicro-HouseCallPAK_Xed-21
RisingWorm.Klez!1.A1CB (CLASSIC)
YandexTrojan.GenAsa!URVqVkT3TU0
IkarusTrojan.Win32.Crypt
MaxSecureWorm.W32.Klez.h
FortinetW32/Wacatac.B!tr
BitDefenderThetaAI:Packer.969B3D361F
ZonerWorm.Win32.Klez.32858
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Klez?

Win32/Klez removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment