Ransom Trojan

About “Trojan.Ransom.HermesKD.12613946” infection

Malware Removal

The Trojan.Ransom.HermesKD.12613946 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.HermesKD.12613946 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Network activity detected but not expressed in API logs

How to determine Trojan.Ransom.HermesKD.12613946?


File Info:

crc32: FF6EB97B
md5: a30c407f2bb35d668fe8ec6597f43862
name: A30C407F2BB35D668FE8EC6597F43862.mlw
sha1: 0d65b0b92a54be3481a9b5c4cd20e1d1f59e3f97
sha256: 574d2f84b1e031b8d69a20915e88c367a1ee7e79549e97992046c0d8081ac0db
sha512: c56cc55009b2060b236ed4b153084c938cf87540bdf421af5942433967e9ebc26db9cbe5051e38aabc7abc97222f001060a17b071eea3b2bcbb1fe535744ff4e
ssdeep: 1536:FdS4cSRJo3LYNWP0L3cEkYq6v35UOH88ev/8PO:FI2ALjODlq45UsGUPO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: Yellow
FileVersion: 3.5.7.3
CompanyName: Tor Software
ProductName: California
ProductVersion: 1.8.7.7
FileDescription: Esoo
OriginalFilename: Promo
Translation: 0x0409 0x04b0

Trojan.Ransom.HermesKD.12613946 also known as:

K7AntiVirusTrojan ( 0050b3ab1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.10700
ALYacTrojan.Ransom.Hermes
MalwarebytesMalware.AI.2987458909
SangforRansom.Win32.Hermez.i
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0050b3ab1 )
Cybereasonmalicious.f2bb35
SymantecRansom.KeyBTC
ESET-NOD32a variant of Win32/Filecoder.Hermes.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Hermez.i
BitDefenderTrojan.Ransom.HermesKD.12613946
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.Ransom.HermesKD.12613946
TencentWin32.Trojan.Hermez.Liqe
Ad-AwareTrojan.Ransom.HermesKD.12613946
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaE.34790.fu0@aO1y4Kmi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HERMES.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.a30c407f2bb35d66
EmsisoftTrojan.FileCoder (A)
JiangminTrojan.Hermez.f
Antiy-AVLTrojan/Generic.ASMalwS.22BC542
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.Ransom.HermesKD.12613946
AhnLab-V3Win-Trojan/Gandcrab08.Exp
McAfeeArtemis!A30C407F2BB3
VBA32TrojanRansom.Hermez
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HERMES.SM
RisingRansom.Hermes!1.B651 (CLASSIC)
YandexTrojan.Hermez!xRC8199g64c
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder_Hermes.A!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Ransom.Hermes.HgAASRIA

How to remove Trojan.Ransom.HermesKD.12613946?

Trojan.Ransom.HermesKD.12613946 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment