Threat Database Malware Ghdrive32.exe

Ghdrive32.exe

By Domesticus in Malware

Ghdrive32.exe is a file that is often installed by dangerous Trojans onto your computer. This dangerous file is used to transfer information between your computer and a third party. The Ghdrive32.exe file will often manifest itself in changes to your Firewall settings, and unknown files and processes on your computer. ESG malware researchers recommend removing the Trojan threat that is usually underlying the presence of Ghdrive32.exe on your computer.
 

Where Did the Ghdrive32.exe File Originate?

The Ghdrive32.exe file was first seen in Spring of 2011. Because of this, your anti-malware program should be updated up to this date to be able to remove Ghdrive32.exe from your computer. Ghdrive32.exe is usually a byproduct of the Troj/DwnLdr-IXK Trojan. To find the Ghdrive32.exe file lurking on your hard drive, look inside the Windows system folders. ESG malware researchers also recommend that you look for new entries into the Windows Registry and for randomly-name processes in the Task Manager. As of Summer of 2011, the main areas of the world associated with attacks from the Ghdrive32.exe threat include Australia, Sweden, Israel, and Mexico. If you are worried about a possible Ghdrive32.exe infection, take extra care when handling files or visiting websites from these countries.
 

What Does the Ghdrive32.exe File Do?

The Ghdrive32.exe file has been associated by PC security researchers to the unauthorized opening of ports for inbound and outbound traffic. This file is also capable of producing unauthorized Traffic itself. This allows the Ghdrive32.exe file to work in tandem with the malware designed to steal data and relay it to a third party, or with a malware designed to allow a third party to take control of your computer. This kind of malware is extremely dangerous, since the Ghdrive32.exe file may allow criminals to use your computer for illegal actions, such as the distribution of child pornography, send out spam email, or perform DDoS attacks in coordination with other infected computers.
 

Removing the Ghdrive32.exe File from Your Computer

The Ghdrive32.exe cannot install itself. The presence of Ghdrive32.exe on your computer will almost always indicate an underlying Trojan or malware infection on your computer. ESG security researchers advise removing the cause of Ghdrive32.exe in order to stop its harmful effects. To do this, use a trustworthy anti-malware utility and run a full system scan. If the Trojan causing Ghdrive32.exe is preventing you from scanning your computer, ESG malware researchers recommend starting up Windows in Safe Mode or from an external memory device.

File System Details

Ghdrive32.exe may create the following file(s):
# File Name Detections
1. C:\WINDOWS\ghdrive32.exe

Registry Details

Ghdrive32.exe may create the following registry entry or registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup: "C:\WINDOWS\ghdrive32.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Microsoft Driver Setup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Microsoft Driver Setup: "C:\WINDOWS\ghdrive32.exe"

Trending

Most Viewed

Loading...