Malware

Should I remove “Win32/Filecoder.Hermes.L”?

Malware Removal

The Win32/Filecoder.Hermes.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Hermes.L virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory

How to determine Win32/Filecoder.Hermes.L?


File Info:

crc32: 2C14A95C
md5: ae133677e3fe3672edc0220196b315c0
name: AE133677E3FE3672EDC0220196B315C0.mlw
sha1: 89f4ca964fe0e99aa7c8d3e77700ab677f23d3f7
sha256: 564e568925698bec4eaf4e70c62cc823d73c16ec5b2db27c936941b030a0c257
sha512: 3dc63df436165d9cda7f8647678755ee4043b563209690447f6158e28de3679f1c77c01b819ffb6cc904a925cbdbd4662b75f682d71b1ce5ee92a37a208cbb6a
ssdeep: 6144:7ECSI8H8VW+v8vime8XwtTm+f0fPxl4ADSKgkBQLGJN5PiSe3xFc9gBYruYEe:QCEcUimJXwtTmMSKMQ6S7c9C/YEe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: All rights reserved. Glassdoor
CompanyName: Glassdoor
FileDescription: Workspace Htjava 80586
ProductName: UsersTremendous
ProductVersion: 1.3.8.6
PrivateBuild: 1.3.8.6
Translation: 0x0409 0x04b0

Win32/Filecoder.Hermes.L also known as:

K7AntiVirusTrojan ( 0053cc031 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26486
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.339
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Hermez.30e5dbc5
K7GWTrojan ( 0053cc031 )
Cybereasonmalicious.7e3fe3
SymantecTrojan.Gen.2
ESET-NOD32Win32/Filecoder.Hermes.L
AvastWin32:DangerousSig [Trj]
KasperskyTrojan-Ransom.Win32.Hermez.fq
NANO-AntivirusTrojan.Win32.Encoder.fjgmbe
SophosMal/Generic-S
ComodoMalware@#8jtduh787o7n
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.dzf
FireEyeGeneric.mg.ae133677e3fe3672
JiangminTrojan.Encoder.ck
AviraTR/Hermes.iznpw
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.288FE53
MicrosoftTrojan:Win32/Occamy.C
McAfeeGeneric.dzf
MAXmalware (ai score=100)
VBA32TrojanRansom.Encoder
PandaTrj/RnkBend.A
YandexTrojan.Encoder!G9H9rxGf7PA
IkarusTrojan-Spy.Remcos
FortinetW32/Kryptik.GKEA!tr.ransom
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Win32/Filecoder.Hermes.L?

Win32/Filecoder.Hermes.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment