Trojan

Trojan.Win64.Prometei removal guide

Malware Removal

The Trojan.Win64.Prometei is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Prometei virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • CAPE detected the CoinMiner02 malware family
  • A cryptomining command was executed
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win64.Prometei?


File Info:

name: 5577ACE07883F41DF297.mlw
path: /opt/CAPEv2/storage/binaries/9e1325414424673f40eeb9f11652cd9461944027a6b38e233350f1d14c27392e
crc32: 51D6B885
md5: 5577ace07883f41df297048e24148ee8
sha1: b2df26d9e2776efa005e95973d5bec28f94c06da
sha256: 9e1325414424673f40eeb9f11652cd9461944027a6b38e233350f1d14c27392e
sha512: d080d3726b9d8f59b8418c1faf3d7853014c95afd5055dd67b8daadf04dd35ff8e02d9559edc50d9f39de026bbfee401f49ec634a79a496a87d04c796c29fe9b
ssdeep: 196608:rgiN3uRxPhzDE8Z0qvr1uHJU9/x/nbivve/IJ6k/ltbf5PhbVMiyYUmS4/rz:rgE3uRxPa8Z0qDkJUFoewJ3/FpxMlmSU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6963322BA97C47CF3F744318447F0029E7BEE5A4B7250A3AA90770A597A4E08F365D7
sha3_384: b967f1cb3b0de0b0068716e8991b9469c5e3941fcf8bf5ffd3c2aa1f46a680c3b64ecdf4da5b620be1993a10a15cae38
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Trojan.Win64.Prometei also known as:

LionicTrojan.Win64.Prometei.4!c
Elasticmalicious (high confidence)
DrWebTool.BtcMine.2423
MicroWorld-eScanTrojan.GenericKD.68086991
CAT-QuickHealScript.Trojan.38726
SkyhighBehavesLike.Win32.Dropper.rc
McAfeeArtemis!5577ACE07883
Cylanceunsafe
VIPRETrojan.GenericKD.68086991
SangforTrojan.Win64.Prometei.gp
K7AntiVirusTrojan ( 005697011 )
AlibabaTrojan:Win32/Coinminer.2cc
K7GWTrojan ( 005697011 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/CoinMiner.QB potentially unwanted
ClamAVWin.Coinminer.Generic-7151250-0
Kasperskynot-a-virus:RiskTool.BAT.BitCoinMiner.ab
BitDefenderTrojan.GenericKD.68086991
NANO-AntivirusRiskware.Win64.BitMiner.hktycg
AvastBV:Miner-HA [PUP]
RisingHackTool.XMRMiner!1.C2EC (CLASSIC)
EmsisoftTrojan.GenericKD.68086991 (B)
F-SecurePotentialRisk.PUA/AD.CoinMiner.clxc
TrendMicroCoinminer.Win64.TOOLXMR.SMA
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win64.Vmprotect
GDataWin64.Application.Coinminer.CO (2x)
JiangminRiskTool.BitMiner.cabb
GoogleDetected
AviraPUA/AD.CoinMiner.clxc
VaristW64/Coinminer.BN.gen!Eldorado
Antiy-AVLRiskWare[RiskTool]/Win32.BitMiner
XcitiumApplicUnwnt@#c4msrlc7qii1
ArcabitTrojan.Generic.D40EECCF [many]
ZoneAlarmnot-a-virus:RiskTool.BAT.BitCoinMiner.ab
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.BitMiner.R350823
VBA32Trojan.Win64.Prometei
ALYacTrojan.GenericKD.68086991
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CGG21
TencentWin64.Risk.Bitminer.Tnkl
FortinetRiskware/BitMiner
AVGBV:Miner-HA [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (D)

How to remove Trojan.Win64.Prometei?

Trojan.Win64.Prometei removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment