Ransom Trojan

Trojan.Ransom.HermesKD.12731187 removal instruction

Malware Removal

The Trojan.Ransom.HermesKD.12731187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.HermesKD.12731187 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior

How to determine Trojan.Ransom.HermesKD.12731187?


File Info:

crc32: 3E34DB06
md5: ca31f507704b339c50218c9a41fe6c5a
name: CA31F507704B339C50218C9A41FE6C5A.mlw
sha1: 88439878c4661821d49be86fac6a0b0fd923ae09
sha256: 0cb0a0f75baaafd9a0c816a3935025c3f2223b338fef9977862df6287a8473f8
sha512: 8b9ef8ee7d0ccd042188bd76560341899da70c33ebed234771380484caa47617c2cb06d2c9bdeb0eb58b874cf746459a9392fddf681509bc4b90f84049d53f5e
ssdeep: 3072:KudXQ5v6R+hjrDtFNzbU4afR1omrlPqHhKn06iUiQBLiK0L+T7/pJIA:KaR+jrFsxomRC4zlBDG23
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.HermesKD.12731187 also known as:

BkavW32.Common.C19C65D7
K7AntiVirusTrojan ( 0056e92f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10700
CynetMalicious (score: 100)
ALYacTrojan.Ransom.HermesKD.12731187
CylanceUnsafe
ZillyaTrojan.Gen.Win32.1629
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0056e92f1 )
Cybereasonmalicious.7704b3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GBEX
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Hermez.gx
BitDefenderTrojan.Ransom.HermesKD.12731187
NANO-AntivirusTrojan.Win32.GenKryptik.ewqqen
MicroWorld-eScanTrojan.Ransom.HermesKD.12731187
TencentWin32.Trojan.Gen.Syhl
Ad-AwareTrojan.Ransom.HermesKD.12731187
SophosMal/Generic-S
ComodoMalware@#3c2zljs3eeomt
BitDefenderThetaGen:NN.ZexaF.34628.vGW@auDJMWbi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.ca31f507704b339c
EmsisoftTrojan.Ransom.HermesKD.12731187 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1127187
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/Vigorf.A
ArcabitTrojan.Ransom.HermesKD.DC24333
AegisLabTrojan.Win32.Generic.j!c
GDataTrojan.Ransom.HermesKD.12731187
AhnLab-V3Win-Trojan/Sagecrypt.Gen
McAfeeGeneric.cxn
MAXmalware (ai score=97)
VBA32Trojan-Ransom.Gen
MalwarebytesMalware.Heuristic.1001
PandaTrj/CI.A
RisingRansom.Wyhymyz!8.E822 (CLOUD)
IkarusTrojan-Ransom.GandCrab
FortinetW32/GenKryptik.BKGZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Hermes.HwoCEpsA

How to remove Trojan.Ransom.HermesKD.12731187?

Trojan.Ransom.HermesKD.12731187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment