Trojan

Should I remove “Trojan-Banker.Win32.Emotet.gckw”?

Malware Removal

The Trojan-Banker.Win32.Emotet.gckw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gckw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Spoofs its process name and/or associated pathname to appear as a legitimate process

How to determine Trojan-Banker.Win32.Emotet.gckw?


File Info:

crc32: 8A64BF50
md5: 2a38e12e22dbf595ed750fc12ddc6d48
name: Qcgfcte0fPgWH.exe
sha1: 4b14b36525a3015b9e753794a2a2a4aa5c79cf1e
sha256: 1f75a4b1edeedde217eb4c92749f64ecb3dbc1bdd38b1903447fb84fb9553a2c
sha512: a64b6b6568b103466a1339b1b6aba5ed55ceb118e6b45e509fb9fc4f281b9b4996b0216b0d8bd8673dd0a105d60cd33d3163f30f825fddeb2d3ba9cb4f47c2fb
ssdeep: 6144:ykps/EJxl4tfji9K/9AFnXQkT2r+t0ooMSAFjNr4DyVebdMH:ykpsClQLMK/qXQkT2r+tFVSA4DyVOdMH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Emotet.gckw also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ranapama.ALN
FireEyeGeneric.mg.2a38e12e22dbf595
Qihoo-360Win32/Trojan.f55
ALYacTrojan.Ranapama.ALN
CylanceUnsafe
ZillyaTrojan.Emotet.Win32.24945
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Emotet.be1325c1
K7GWRiskware ( 0040eff71 )
InvinceaMal/Generic-R + Troj/Emotet-CLR
CyrenW32/Emotet.AQZ.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyTrojan-Banker.Win32.Emotet.gckw
BitDefenderTrojan.Ranapama.ALN
NANO-AntivirusTrojan.Win32.Emotet.hsykpj
AegisLabTrojan.Win32.Injuke.trtE
TencentMalware.Win32.Gencirc.10cdee34
Ad-AwareTrojan.Ranapama.ALN
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/Crypt.Agent.xagmy
DrWebTrojan.Emotet.1005
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.EMOTET.THIODBO
SophosTroj/Emotet-CLR
JiangminTrojan.Banker.Emotet.off
AviraTR/Crypt.Agent.xagmy
MAXmalware (ai score=81)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.PED!MTB
ArcabitTrojan.Ranapama.ALN
ViRobotTrojan.Win32.Emotet.368640.B
ZoneAlarmTrojan-Banker.Win32.Emotet.gckw
GDataWin32.Trojan.PSE.102C2D4
AhnLab-V3Trojan/Win32.Emotet.R349205
McAfeeEmotet-FRW!2A38E12E22DB
TACHYONTrojan/W32.Ranapama.368760
VBA32Trojan.Injuke
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HFSS
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THIODBO
RisingTrojan.Kryptik!8.8 (TFE:5:ydis0SUJu3V)
YandexTrojan.Kryptik!YynuydlFA+A
IkarusTrojan-Banker.Emotet
FortinetW32/Zenpak.AUSL!tr
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.105913872.susgen

How to remove Trojan-Banker.Win32.Emotet.gckw?

Trojan-Banker.Win32.Emotet.gckw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment