ErrorSafe 1.3.168.1
ErrorSafe is a disabled data repair utility that nags the user to purchase it in order to fix the problems reported in its scan. ErrorSafe is typically installed through security exploits and bundled with spyware/malware.
General information:
Malware Name: |
ErrorSafe 1.3.168.1 |
Malware Type: |
Rogue Security Program |
Company Name: |
WinSoftware, Ltd |
Company URL: |
http://errorsafe.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
ErrorSafe detects and repairs corrupt files, removes useless data, cleans up clogged Windows registry and fixes hard drive errors. This useful utility helps you maintain an error-free PC and achieve 100% system performance.
Spyware Description:
ErrorSafe is a disabled data repair utility that nags the user to purchase it in order to fix the problems reported in its scan. ErrorSafe is typically installed through security exploits and bundled with spyware/malware.
Characteristics/Symptoms:
-> It nags the user to purchase it in order to fix the problems reported in its scan. -> It is installed through security exploits and bundled with spyware/malware -> It also sets a registry key to automatically launch the program
on startup.
Additional information might be found here:
Processes Running:
uers.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Program Files\ErrorSafe Free\resource.xml |
7562283 |
XML Document |
C:\Program Files\ErrorSafe Free\sr.log |
125 |
Text Document |
C:\Program Files\ErrorSafe Free\updater.dat |
253 |
DAT File |
Folder information Created after Installation:
Folder Location |
C:\Documents and Settings\All Users\Start Menu\Programs\Error Safe Unregistered Versio |
C:\Program Files\ErrorSafe Free\Backu |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Classes\CLSID\{C5531D07-22C2-418B-85B9-D829AF1498B0}\InProcServer32 |
ThreadingModel |
HKEY_LOCAL_MACHINE |
\SOFTWARE\Classes\TypeLib\{F585CB1F-F17D-4007-A573-B663197EF500} |
|
HKEY_LOCAL_MACHINE |
\SOFTWARE\Error Safe Free |
mxhrs |