Ransom

Ransom.Prometheus.2 removal guide

Malware Removal

The Ransom.Prometheus.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Prometheus.2 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom.Prometheus.2?


File Info:

name: C5371698EF69DA9A1B7D.mlw
path: /opt/CAPEv2/storage/binaries/5c5d4c844384517264f431ec4e04b00600d108b3a195e276c47b53a5c2fe6f03
crc32: F9F738B4
md5: c5371698ef69da9a1b7d2e925bd473a7
sha1: 0afa0cbe668917a1933e108ed14ed95936c725ed
sha256: 5c5d4c844384517264f431ec4e04b00600d108b3a195e276c47b53a5c2fe6f03
sha512: 463b45f12c88641bcb6981504afe0fda6e675317c2bf29aecbb7146d51d29dc64810dc8154861cc0b45918288b63820e8f6b24ead400a7d4ffdc9516eceb8893
ssdeep: 24576:+k5M77tjJciNArhB7EzFiWoiJauvcW/XRww1+1Y9saxDLu:+kWPtjNItCwWVL9s+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B557D01BE44CE11F0191633C2FF454847B0A95166EAEB2B7DBA37AD59123AB3D0D9CB
sha3_384: 890d0c10fa3deccea7e035e7690578ef1f163890ff0c5c7c4884b1a28fe95b60f23f3fe7aa90595ba00edcea8f54a068
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-05-04 16:03:35

Version Info:

FileVersion: 5.15.2.0
OriginalFilename: libGLESv2.dll
ProductName: libGLESv2
ProductVersion: 5.15.2.0
Translation: 0x0409 0x04b0

Ransom.Prometheus.2 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.DCRat.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.124
MicroWorld-eScanGen:Variant.Ransom.Prometheus.2
ClamAVWin.Packed.Msilmamut-9950860-0
FireEyeGeneric.mg.c5371698ef69da9a
CAT-QuickHealTrojan.DCRat.S29707587
SkyhighBehavesLike.Win32.Generic.tc
McAfeeTrojan-FUJL!C5371698EF69
MalwarebytesGeneric.Spyware.Stealer.DDS
ZillyaTrojan.BasicGen.Win32.4
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/DCRat.d3b5f164
K7GWSpyware ( 0058ebd51 )
K7AntiVirusSpyware ( 0058ebd51 )
BitDefenderThetaGen:NN.ZemsilF.36744.sr0@a4BS6jhi
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Spy.Agent.DTP
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.DCRat.gen
BitDefenderGen:Variant.Ransom.Prometheus.2
AvastWin32:RATX-gen [Trj]
TencentTrojan.Msil.Dcrat.xa
EmsisoftGen:Variant.Ransom.Prometheus.2 (B)
F-SecureHeuristic.HEUR/AGEN.1323984
VIPREGen:Variant.Ransom.Prometheus.2
SophosTroj/DCRat-N
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.Prometheus.2
GoogleDetected
AviraHEUR/AGEN.1323984
Kingsoftmalware.kb.c.994
ArcabitTrojan.Ransom.Prometheus.2
ZoneAlarmHEUR:Backdoor.MSIL.DCRat.gen
MicrosoftBackdoor:MSIL/DCRat!MTB
VaristW32/MSIL_Agent.LQ.gen!Eldorado
AhnLab-V3Trojan/Win.FUJL.C5119684
Acronissuspicious
ALYacGen:Variant.Ransom.Prometheus.2
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.DcRat!8.129D9 (CLOUD)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.DVA!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.e66891
DeepInstinctMALICIOUS

How to remove Ransom.Prometheus.2?

Ransom.Prometheus.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment