ErrorSafe 1.3.168.1

ErrorSafe is a disabled data repair utility that nags the user to purchase it in order to fix the problems reported in its scan. ErrorSafe is typically installed through security exploits and bundled with spyware/malware.

General information:

Malware Name: ErrorSafe 1.3.168.1
Malware Type: Rogue Security Program
Company Name: WinSoftware, Ltd
Company URL: http://errorsafe.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

ErrorSafe detects and repairs corrupt files, removes useless data, cleans up clogged Windows registry and fixes hard drive errors. This useful utility helps you maintain an error-free PC and achieve 100% system performance.

Spyware Description:

ErrorSafe is a disabled data repair utility that nags the user to purchase it in order to fix the problems reported in its scan. ErrorSafe is typically installed through security exploits and bundled with spyware/malware.

Characteristics/Symptoms:

    -> It nags the user to purchase it in order to fix the problems reported in its scan. -> It is installed through security exploits and bundled with spyware/malware -> It also sets a registry key to automatically launch the program on startup.

Additional information might be found here:

google Search at Google for ErrorSafe 1.3.168.1
bing Search at Bing for ErrorSafe 1.3.168.1
yahoo Search at Yahoo for ErrorSafe 1.3.168.1

Processes Running:

uers.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\ErrorSafe Free\resource.xml 7562283 XML Document
C:\Program Files\ErrorSafe Free\sr.log 125 Text Document
C:\Program Files\ErrorSafe Free\updater.dat 253 DAT File

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\Error Safe Unregistered Versio
C:\Program Files\ErrorSafe Free\Backu

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\CLSID\{C5531D07-22C2-418B-85B9-D829AF1498B0}\InProcServer32 ThreadingModel
HKEY_LOCAL_MACHINE \SOFTWARE\Classes\TypeLib\{F585CB1F-F17D-4007-A573-B663197EF500}
HKEY_LOCAL_MACHINE \SOFTWARE\Error Safe Free mxhrs