Ransom

Should I remove “Ransom.Prometheus.1”?

Malware Removal

The Ransom.Prometheus.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Prometheus.1 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ransom.Prometheus.1?


File Info:

name: 0F3F5527912E8CE219C2.mlw
path: /opt/CAPEv2/storage/binaries/9fce15b07369076f5ddf8315cb73df89d00b8694b53346b8fb71adfebf287272
crc32: 495ADC32
md5: 0f3f5527912e8ce219c2cd15cb36fd3a
sha1: 8d00b7437768d114f8581137cb5823664e0c9ac6
sha256: 9fce15b07369076f5ddf8315cb73df89d00b8694b53346b8fb71adfebf287272
sha512: 245a9b0434635daacb9c2862eb5696e1cc89c2289d7f9059b0887f6b51802e1eda5cd48dc60135b590ae9178ef60bc1ef54ef2c293356c6f793173905ef67071
ssdeep: 24576:pO85CcCWsR0y2VeODD+BHgAANI0ZWWhmmOjkAGcE+gtzuEz:T5Ls6peLBmNI0ZWWhb1JgG5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0858C017E44CA11F0091673C3EF454887B0E9516BA6E31B7DBA77AE65123A7BC0DACB
sha3_384: 7c7ccbd105866354a2abba095eff7082f4196d738c52b2281f00bb094758a7e1978ef9cbb3d379652bee56d398bd29a7
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-05-04 16:03:35

Version Info:

ProductName: x74FmZACzrgD
CompanyName: P2svK3SujtCDwg3esRZCVDaR
InternalName: wJGOmW4AXUgiroRp0Ee1BXxGaHM.exe
LegalCopyright: AwLSU1lz
Comments: S0IHDDT
OriginalFilename: 5IzIry8Hq.exe
ProductVersion: 256.723.181.868
FileVersion: 182.582.528.146
Translation: 0x0409 0x0514

Ransom.Prometheus.1 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.DCRat.4!c
tehtrisGeneric.Malware
DrWebTrojan.PWS.StealerNET.124
MicroWorld-eScanGen:Variant.Ransom.Prometheus.1
ClamAVWin.Packed.Msilmamut-9950860-0
FireEyeGeneric.mg.0f3f5527912e8ce2
CAT-QuickHealTrojan.DCRat.S29707587
SkyhighBehavesLike.Win32.Generic.tc
McAfeeTrojan-FUJL!0F3F5527912E
Cylanceunsafe
ZillyaTrojan.BasicGen.Win32.4
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0058ec321 )
AlibabaBackdoor:MSIL/DCRat.d95b34eb
K7GWSpyware ( 0058ec321 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ransom.Prometheus.1
BitDefenderThetaGen:NN.ZemsilF.36608.Pr0@aivTZzmi
VirITTrojan.Win32.MSIL_Heur.A
SymantecTrojan.Whispergate
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.DTP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.DCRat.gen
BitDefenderGen:Variant.Ransom.Prometheus.1
AvastWin32:RATX-gen [Trj]
TencentBackdoor.MSIL.Stealer.11025419
SophosTroj/DCRat-N
F-SecureHeuristic.HEUR/AGEN.1323984
VIPREGen:Variant.Ransom.Prometheus.1
TrendMicroTROJ_GEN.R002C0DJE23
EmsisoftGen:Variant.Ransom.Prometheus.1 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.MSILZilla
GoogleDetected
AviraHEUR/AGEN.1323984
Antiy-AVLTrojan[Backdoor]/MSIL.DCRat
KingsoftMSIL.Backdoor.DCRat.gen
XcitiumMalware@#h914r2o7p56w
MicrosoftBackdoor:MSIL/DCRat!MTB
ZoneAlarmHEUR:Backdoor.MSIL.DCRat.gen
GDataGen:Variant.Ransom.Prometheus.1
VaristW32/MSIL_Agent.LQ.gen!Eldorado
AhnLab-V3Trojan/Win.FUJL.C5130705
Acronissuspicious
ALYacGen:Variant.Ransom.Prometheus.1
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Spyware.Stealer.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DJE23
RisingBackdoor.DcRat!8.129D9 (CLOUD)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.119961507.susgen
FortinetMSIL/Agent.DVA!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.37768d
DeepInstinctMALICIOUS

How to remove Ransom.Prometheus.1?

Ransom.Prometheus.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment