Home Malware Programs Trojans Jodrive32.exe

Jodrive32.exe

Posted: May 2, 2011

Jodrive32.exe is a malicious file that's distributed by a wide range of Trojans. You may not notice Jodrive32.exe on your PC due to its Windows folder location that avoids giving away its presence. Jodrive32.exe will use startup Registry entries to launch itself automatically, and related infections may attack your firewall to allow Jodrive32.exe to ignore your security settings. All of these are signs of a high-level threat that could download malware to your PC, serve as spyware or enable remote attacks. Therefore, removing Jodrive32.exe and related threats to your PC should be accomplished as quickly as possible with anti-malware software help.

Jodrive32.exe - The New PC Threat on the Block

Jodrive32.exe is an extremely new PC threat - most sources have only identified Jodrive32.exe since April 14th of 2011. This places high importance on keeping your security and anti-malware software fully up to date if you want to have a chance of catching Jodrive32.exe ASAP. The currently suspected region of origin for Jodrive32.exe is India, and you may want to exercise a little additional care when interacting with file sources from that country.

Jodrive32.exe will almost never be the sole infection on your PC; Jodrive32.exe is delivered by Trojans like Troj/Backdr-EY and may not be the only thing the Trojan installs on your computer.

Because Jodrive32.exe is so new, relatively few details about Jodrive32.exe's behavior have been recorded. However, it's known that Jodrive32.exe creates startup entries in the Windows Registry to run automatically. The actual file Jodrive32.exe is known to hide in your Windows OS directory, and may use Hidden or System attributes to make its concealment even more perfect. Jodrive32.exe may also:

  • Block downloads by creating fake warnings or simply by canceling them outright.
  • Create errors like the following:

    Windows Internet Explorer
    Internet Explorer cannot open the Internet site [URL]
    Operation Aborted

Other Traits of Jodrive32.exe You May Not Be Expecting

Jodrive32.exe can't be identified by file size alone, since Jodrive32.exe is known to have at least three different sizes: 51.8kb, 56.6kb and 114.3kb. This is most likely due to simple compression or packing techniques that help Jodrive32.exe avoid being detected by anti-malware scanners.

The most dangerous trait related to Jodrive32.exe is the fact that its presence often coincides with an attack on your firewall. Your firewall may be left active, but exceptions will be created to allow Jodrive32.exe to operate freely without the firewall restricting its operations. This can allow Jodrive32.exe to transmit private information on your to remote criminals or let remote criminals install other malware onto the PC.

Because of the high level of security and privacy threat Jodrive32.exe poses, removing Jodrive32.exe should be a top priority. Manual removal of Jodrive32.exe should be your last choice, since other infections are likely to be cooperating with Jodrive32.exe and should be removed by an anti-malware software scan. If you run this scan in Safe Mode, then deleting Jodrive32.exe should prove to be relatively easy.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %APPDATA%\140870.EXE
    2 %APPDATA%\CVGMP.EXE
    3 %SYSTEM%\EXSYS.EXE
    4 %TEMP%\GOOGLE_WPAGES2.TMP
    5 %WINDIR%\JODRIVE32.EXE
    6 C:\WINDOWS\jodrive32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Config Setup: "C:\WINDOWS\jodrive32.exe"HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Microsoft Config Setup: "C:\WINDOWS\jodrive32.exe"

One Comment

Loading...