Ransom Trojan

How to remove “Trojan-Ransom.Win32.Hermez.ig”?

Malware Removal

The Trojan-Ransom.Win32.Hermez.ig is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Hermez.ig virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Hermez.ig?


File Info:

crc32: 5E9D6CBF
md5: 4e931b437d027ae1bdc2fa47f6d43624
name: 4E931B437D027AE1BDC2FA47F6D43624.mlw
sha1: 4041060691f51d87afd8966eeb55765543657f50
sha256: 378690f58db4abd148b9036cfa079eda47357aac4d19034915b230a083f29a8d
sha512: 66ba2e504f96cf92c53aa151739c584fd30eeb42e07c311f497098b48048b584577e37a1a2b49542791bfefa5b33877293e50c050f75ffcee89ba7bee8c2d345
ssdeep: 3072:INYlI9ogb8eovMPDT1e/rm7DZIXgHGS/p6uA:IwO8eo4h8rmXsgHGQ6u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, phpdummiess
FileVersion: 6.3.6.8
ProductVersion: 6.3.6.8
Translation: 0x0809 0x04b0

Trojan-Ransom.Win32.Hermez.ig also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
LionicTrojan.Win32.NeutrinoPOS.tpgC
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad4.931
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.Generic.Win32.316084
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Hermez.60857af2
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.37d027
CyrenW32/S-dea5fd14!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCPG
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Emotet-6440497-0
KasperskyTrojan-Ransom.Win32.Hermez.ig
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.NeutrinoPOS.exlshm
ViRobotTrojan.Win32.R.Agent.134144.L
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentTrojan.Win32.Gandcrypt.b
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/Kryptik-BL
ComodoApplication.Win32.IStartSurf.PS@8c4m91
BitDefenderThetaGen:NN.ZexaF.34088.iu0@aCTJBwEG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
FireEyeGeneric.mg.4e931b437d027ae1
EmsisoftTrojan.BRMon.Gen.3 (B)
JiangminTrojan.Banker.NeutrinoPOS.bw
AviraHEUR/AGEN.1126869
Antiy-AVLTrojan/Generic.ASMalwS.244B096
MicrosoftTrojan:Win32/Gandcrab.GM!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataTrojan.BRMon.Gen.3
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeePacked-ZG!4E931B437D02
MAXmalware (ai score=99)
VBA32BScope.Trojan.Suloc
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingRansom.GandCrab!1.B152 (CLASSIC)
YandexTrojan.GenAsa!q1Y64ZBrNgw
IkarusTrojan.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.BAZY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Ransom.Win32.Hermez.ig?

Trojan-Ransom.Win32.Hermez.ig removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment