GravityRat Trojan Malware Removal

Parasite may reinstall itself multiple times if you don't delete its core files. We recommend downloading SpyHunter to scan for malicious programs installed with it. This may save you hours and cut down your time to about 15 minutes. 

Download SpyHunter Anti-Malware

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

How irritating is this problem? (1 votes, average: 5.00)

This page aims to help you remove GravityRat. Our removal instructions work for every version of Windows.

What is a Trojan horse? How harmful could those types of viruses be? Where can such threats lurk and how to protect your PC? All these questions will be discussed in details by our “How to remove” experts in the paragraphs that follow. A common version of a Trojan-based virus, named GravityRat, will also be reviewed here. So don’t miss the information that we have published below, especially if you have doubts that this infection might have sneaked inside your system. Our team has prepared a detailed Removal Guide at the end of this article, which can help you remove the nasty Trojan, hopefully, before it manages to cause you a serious harm.

What is a Trojan horse infection?

Trojans are awfully unpredictable and multifunctional malicious tools, which can have really devastating effects on any computer. These threats may be programmed to perform literally anything harmful you could think of, and can even change their purpose, once they complete the initial task they have been set to complete. Almost every online user has heard about the dreadful Trojan-based viruses at least once, and a large number of the people, who surf the web, have had a close encounter with this type of malware in one way or another.

What types of harm could a Trojan like GravityRat cause?

Threats like GravityRat might be very unpredictable and you could never know what type of harm they might be programmed to perform unless you actually face its consequences. This is the main reason why the Trojan-based infections are so popular among the cyber criminals and the hackers with malicious intentions. Such viruses, could delete your data or crack your system with the same effectiveness with which they would exploit a vulnerability in your OS and insert a Ransomware, for example.

In fact, most of the Trojans that we know of could easily be used to infiltrate your machine in complete stealth, launch some data tracking activities, transmit confidential information to remote servers and steal passwords, login credentials and banking details from the victims without any visible symptoms. With the help of a malware like GravityRat, the hackers can gain complete remote access to the infected machine and modify, corrupt, and exploit its settings and resources for their criminal intentions. The crooks may even spy on their victims by hacking into their mic or camera and keep a track on their conversations and personal or professional life. Horrific, isn’t it?

And, sadly, this is just a very small portion of what an experienced criminal could do with this type of malware under his control. That’s why, if you are infected with a Trojan such as GravityRat or you have even the slightest doubt that such malware might be hiding in your system, you should scan your PC with reliable antivirus software and remove the infection immediately.

Remove GravityRat



Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).



We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. We recommend downloading SpyHunter to see if it can detect parasite files for you.

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab. Try to determine which processes are dangerous. 


Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at:

Scan Results

Virus Scanner Result

After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 


Hold together the Start Key and R. Type appwiz.cpl –> OK.


You are now in the Control Panel. Look for suspicious entries. Uninstall it/them. If you see a screen like this when you click Uninstall, choose NO:



Type msconfig in the search field and hit enter. A window will pop-up:


Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.

  • Remember this step – if you have reason to believe a bigger threat (like ransomware) is on your PC, check everything here.

Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.


To remove parasite on your own, you may have to meddle with system files and registries. If you were to do this, you need to be extremely careful, because you may damage your system.

If you want to avoid the risk, we recommend downloading SpyHunter
a professional malware removal tool.

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

Type Regedit in the windows search field and press Enter.

Once inside, press CTRL and F together and type the virus’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Potential sources of Trojan-based infections:

As you can see, Trojans could be really harmful, that’s why it is really vital to protect your system by all possible means and try to prevent viruses like GravityRat from entering your machine. For that, you need to rely on reputed antivirus software and to know what to avoid and where these threats lurk the most. As per our observations, the greater number of infections with Trojans happens when the users don’t have reliable security software and interact with some well-camouflaged malicious transmitters, which could appear in different forms. And since the hackers want to infect as many people as possible, they try to hide their malware in some seemingly harmless files, attachments, email links, ads or intriguing offers and pop-ups. The crooks may also distribute the infection via contagious web pages, torrents, fake software installers or update requests. That’s why, you should do your best to limit your interaction with unfamiliar or unreliable content because if you happen to interact with an infected carrier, you may end up with a nasty virus without even knowing it.

Effective prevention and Trojan removal tips:

In order to limit the possibility of a nasty threat such as GravityRat to enter your system, you have to ensure that your OS is fully updated and does not contain system vulnerabilities or critical issues, which could be exploited. For that, always keep informed about the latest security patches and do not forget to install them on time. Also, make sure that your anti-malware program scans your system regularly and is provided with the latest virus definitions. If a Trojan still manages to trick you and slips into the PC, do not lose time but try to remove it with your security software or a professional malware removal tool.


Name GravityRat
Type Trojan
Danger Level  High (Trojans are often used as a backdoor for Ransomware)
Symptoms  It is really difficult to notice any visible symptoms of the infection without a professional seucrity software.
Distribution Method  This malware could be distributed via spam, infected email attachments, fake software installers and updates, torrents, illegal web pages, phising sites.
Detection Tool

Leave a Comment