Ransom

Ransom.Prometheus.1 (B) information

Malware Removal

The Ransom.Prometheus.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Prometheus.1 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ransom.Prometheus.1 (B)?


File Info:

name: 2D46F30408F2C7EF6F1A.mlw
path: /opt/CAPEv2/storage/binaries/7fe20522fc5d49b7430cecda309dbf3c2b1d8baee3f5f93acd165da60f9d8490
crc32: AAFCDB2C
md5: 2d46f30408f2c7ef6f1a4fdebd2a7498
sha1: 4119dde5eb870c75250bef02d7f85319d7a12cd9
sha256: 7fe20522fc5d49b7430cecda309dbf3c2b1d8baee3f5f93acd165da60f9d8490
sha512: 504e001ddf00f5db002cd477b309d21866016c094f952440f3c7e75d7bf8388f2867bfd362b023d53474b021411b123bf9d1672e5f8c96e4dfaa188e94075dae
ssdeep: 24576:bilKuDqhXSQdCTxP0X2HsmQXpOkWagYBLS+qTtIZaZ2c4vylc/g1AeHw8:bEKukhQP7ZQ5OkWag1+qpIQV4vEcLe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13285AE027E44CE02F40D5633C6FF456887B0A8556AA6E31B7DBA376E59123A73C0D9CB
sha3_384: b5cfedccce4364b71b9600c3f9544bc54d43c655d0103d70ff084cc0be0c325120fcd5ece06d433ac130d68d31a4a12c
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-05-04 16:03:35

Version Info:

ProductName: xRPQeu1L2iadoqLWhkatvEn52O4JR
CompanyName: Ik
InternalName: YtVQcANIcK.exe
LegalCopyright: BYsVcVkV
Comments: yLjeTYNdl41Y2UJ6mF4jWWA
OriginalFilename: p3rfoX6Sv6vMn36WvsZ1S0IEwY.exe
ProductVersion: 373.50.346.994
FileVersion: 146.773.953.705
Translation: 0x0409 0x0514

Ransom.Prometheus.1 (B) also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Prometheus.1
FireEyeGeneric.mg.2d46f30408f2c7ef
CAT-QuickHealTrojan.DCRat.S29707587
SkyhighBehavesLike.Win32.AgentTesla.tc
McAfeeTrojan-FUJL!2D46F30408F2
MalwarebytesGeneric.Spyware.Stealer.DDS
ZillyaTrojan.BasicGen.Win32.4
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0058ec321 )
K7GWSpyware ( 0058ec321 )
Cybereasonmalicious.408f2c
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Spy.Agent.DTP
APEXMalicious
ClamAVWin.Packed.Msilmamut-9950860-0
KasperskyHEUR:Backdoor.MSIL.DCRat.gen
BitDefenderGen:Variant.Ransom.Prometheus.1
AvastWin32:RATX-gen [Trj]
TencentBackdoor.MSIL.Stealer.11025419
EmsisoftGen:Variant.Ransom.Prometheus.1 (B)
F-SecureHeuristic.HEUR/AGEN.1323984
DrWebTrojan.PWS.StealerNET.124
VIPREGen:Variant.Ransom.Prometheus.1
SophosTroj/DCRat-N
IkarusTrojan.MSIL.Injector
GoogleDetected
AviraHEUR/AGEN.1323984
VaristW32/MSIL_Agent.LQ.gen!Eldorado
Kingsoftmalware.kb.c.872
MicrosoftBackdoor:MSIL/DCRat!MTB
ArcabitTrojan.Ransom.Prometheus.1
ZoneAlarmHEUR:Backdoor.MSIL.DCRat.gen
GDataGen:Variant.Ransom.Prometheus.1
AhnLab-V3Trojan/Win.FUJL.C5130705
Acronissuspicious
ALYacGen:Variant.Ransom.Prometheus.1
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.DcRat!8.129D9 (TFE:D:FJgJjfd5R0Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DVA!tr
BitDefenderThetaGen:NN.ZemsilF.36802.Wr0@am6sYwni
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom.Prometheus.1 (B)?

Ransom.Prometheus.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment