Process Search

egathdrv.sys

Associated Program: IBM eGatherer
Programm Category: Tools, Utilities, and Drivers Software

What is  egathdrv.sys

The file egathdrv.sys, known as IBM eGatherer Kernel Module, belongs to software IBM eGatherer. This program is called Active Support because it collects system configuration information in order to help diagnosis problems reported to IBM for Microsoft Windows and Linux-based operating systems. Although a legitimate program, this application makes the computer vulnerable because Active Support allows a remote attacker to gain access through the ActiveX component of IBM eGatherer, which can be used to execute arbitrary codes on the system. It creates a specially crafted Web-page that uses the SelDebugging and RunEgatherer to write a file in the victim's startup folder once the Web page is visited. When the system restarts, the created folder is launched and enables the attacker to use the privilege of the victim to exploit this vulnerability by hosting the malicious Web page on a Web site or by sending it to a victim as an HTML email.

How can I stop egathdrv.sys and should I?

Most non-system processes that are running can be stopped because they are not involved in running your operating system. egathdrv.sys. is used by IBM eGatherer, If you shut down egathdrv.sys, it will likely start again at a later time either after you restart your computer or after an application start. To stop egathdrv.sys, permanently you need to uninstall the application that runs this process which in this case is IBM eGatherer, from your system.
After uninstalling applications it is a good idea to scan you Windows registry for any left over traces of applications. Registry Reviver by ReviverSoft is a great tool for doing this.

Is this a virus or other security concern?

ReviverSoft Security Verdict

The ReviverSoft experts have not yet reviewed egathdrv.sys




What is a process and how do they affect my computer?

A process usually a part of an installed application such as IBM eGatherer, or your operating system that is responsible for running in functions of that application. Some application require that they have processes running all the time so they can do things such as check for updates or notify you when you get an instant message. Some poorly written applications have many processes that run that may not be required and take up valuable processing power within your computer.

Is egathdrv.sys known to be bad for my computer's performance?

We have not received any complaint about this process having higher than normal impact on PC performance. If you have had bad experiences with it please let us know in a comment below and we will investigate it further.

What can I do if egathdrv.sys is causing errors on my computer?

The first thing you should do if egathdrv.sys. is causing errors on your computer is to run a Windows registry scan with Registry Reviver If you are still seeing errors after this you should uninstall the program that egathdrv.sys, belongs to, in this case IBM eGatherer

About Mark Beare

Founder of ReviverSoft and lover of tweaking and maintaining computers. Ask me a question and comment on my posts. I love feedback!

leave a comment

do you have any questions
about egathdrv.sys?
Feel free to ask our experts from around the world and to receive professional answers for it.
ask your question
Other processes tied to this application

No related processes

Copyright © 2024 Corel Corporation. All rights reserved. Terms Of Use | Privacy | Cookies
follow us
Save 80% Now
Boost YOUR PC with our best bundle deal ever