Malware

About “Win32/Klez.E” infection

Malware Removal

The Win32/Klez.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Klez.E virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/Klez.E?


File Info:

name: 9B36D5B59631427F2EE5.mlw
path: /opt/CAPEv2/storage/binaries/cdf730256f74757b8078adf2ea82be6dfa01e60271c2ffe04a9a554c860c7b99
crc32: 5C52828B
md5: 9b36d5b59631427f2ee5c259f8ea360d
sha1: 6784ccfcff1867b728793ecda93c11a96bf82b54
sha256: cdf730256f74757b8078adf2ea82be6dfa01e60271c2ffe04a9a554c860c7b99
sha512: 4a843cc6119675cef3d9e1182fc1c0cdf374ce5b3f3e00be608a14827f60dfc6016b17635dbeadaac3a2033258867fcac241c790dc138b05f3599b30198645b3
ssdeep: 1536:TSSnze1gsJ55n/4CkOwwF+bho52UjYnj:+Sn3sziCkd5bho523n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12183BF2776908033D4A7823155AE4B128EFFE8320767EA83DB115A5B3D306D0EE3674B
sha3_384: 0f923e5113d1e4f3d63c9a30ca013f3a3757b2be6e62635ae7eecddb8c7752e1e589bcdcc779f0e44552998b3c19c653
ep_bytes: 558bec6aff6838d240006824a8400064
timestamp: 2002-01-14 08:44:12

Version Info:

0: [No Data]

Win32/Klez.E also known as:

BkavW32.KlezE.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Klez.E@mm
FireEyeGeneric.mg.9b36d5b59631427f
CAT-QuickHealW32.Klez.H
ALYacWin32.Klez.E@mm
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 000805561 )
K7GWEmailWorm ( 000805561 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.fqY@ayzzNh
VirITWin32.Klez.E
SymantecW32.Klez.E@mm
ESET-NOD32Win32/Klez.E
APEXMalicious
TrendMicro-HouseCallWORM_KLEZ.GEN
ClamAVWin.Worm.Klez-2
KasperskyEmail-Worm.Win32.Klez.k
BitDefenderWin32.Klez.E@mm
NANO-AntivirusTrojan.Win32.Klez.gleq
ViRobotI-Worm.Win32.Klez-gen
TencentEmail-Worm.Win32.Klez.ha
BaiduWin32.Worm.Klez.a
F-SecureWorm.WORM/Klez.E
DrWebWin32.HLLM.Klez.1
VIPREWin32.Klez.E@mm
TrendMicroWORM_KLEZ.GEN
Trapminemalicious.high.ml.score
SophosW32/Klez-E
IkarusEmail-Worm.Win32.Klez.E
JiangminWorm/Klez.l
VaristW32/Klez.E@mm
AviraWORM/Klez.E
Antiy-AVLWorm[Email]/Win32.Klez.k
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Klez.E@3bt0
ArcabitWin32.Klez.EA8AF7
SUPERAntiSpywareWorm.Klez
ZoneAlarmEmail-Worm.Win32.Klez.k
GDataWin32.Trojan.PSE.15IDC91
CynetMalicious (score: 100)
AhnLab-V3Win32/Klez.worm.E
Acronissuspicious
VBA32Win32.HLLW.Klez.e
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
Cylanceunsafe
ZonerWorm.Win32.Klez.24278
RisingWorm.Klez!1.A1CB (CLASSIC)
YandexI-Worm.Klez!CIO9ffjdhqs
SentinelOneStatic AI – Malicious PE
FortinetW32/Klez.fam@mm
Cybereasonmalicious.596314
PandaW32/Klez.F
alibabacloudBackdoor:Win/Agent.A(dyn)

How to remove Win32/Klez.E?

Win32/Klez.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment