Should I block it?

90%
90% of PCs block this file from running.
Possible reason:
Multiple malware detections

VersionsAdditional versions

1.0.0.2522 66.67%
1.0.0.2405 16.67%
1.0.0.1982 16.67%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ConvertStringSidToSidW, AdjustTokenPrivileges, DuplicateTokenEx, LookupPrivilegeValueW, SetTokenInformation, CreateProcessAsUserW, GetTokenInformation, OpenProcessToken, RegQueryValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ControlService, ReportEventW, QueryServiceStatusEx, SetServiceStatus, ChangeServiceConfigW, StartServiceW, ChangeServiceConfig2W, DeregisterEventSource, RegisterServiceCtrlHandlerExW, RegCreateKeyW, EnumDependentServicesW, StartServiceCtrlDispatcherW, DeleteService, RegisterEventSourceW, CreateServiceW, RegSetValueExW, RegOpenKeyExW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, RegCloseKey, RegCreateKeyExW
comctl32.dll
InitCommonControls
kernel32.dll
GetSystemWindowsDirectoryW, GetCurrentThread, WideCharToMultiByte, LoadLibraryW, SetThreadPriority, LocalAlloc, GetShortPathNameW, LocalFree, GlobalAlloc, CreateFileW, DeviceIoControl, GetVolumeInformationW, GetSystemDefaultLangID, GetFileSize, SetFilePointer, SetEndOfFile, CreateDirectoryW, WriteFile, ReadFile, GetLocalTime, DeleteFileW, GetCurrentProcessId, SetFileAttributesW, GetFileAttributesW, FlushFileBuffers, GetQueuedCompletionStatus, RaiseException, InterlockedExchange, ResetEvent, GetExitCodeThread, PostQueuedCompletionStatus, GetSystemInfo, WaitForMultipleObjects, CreateIoCompletionPort, lstrlenW, GetLogicalDriveStringsW, OpenProcess, GetSystemDirectoryW, ProcessIdToSessionId, QueryDosDeviceW, WriteConsoleW, SetStdHandle, GetEnvironmentVariableW, GetCurrentThreadId, GetProcessHeap, GetTickCount, OutputDebugStringW, HeapFree, HeapAlloc, GlobalFree, MultiByteToWideChar, CreateThread, CreateEventW, GetLastError, TerminateThread, SetEvent, SetPriorityClass, WaitForSingleObject, Sleep, MoveFileExW, CloseHandle, GetProcAddress, GetModuleFileNameW, GetModuleHandleW, GetCurrentProcess, DeleteCriticalSection, LockResource, EnterCriticalSection, LeaveCriticalSection, GetVersionExW, SizeofResource, InitializeCriticalSectionAndSpinCount, FindResourceExW, InitializeCriticalSection, LoadResource, FindResourceW, ReadConsoleW, GetConsoleMode, GetConsoleCP, SetFilePointerEx, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetFileType, GetStdHandle, GetModuleHandleExW, ExitProcess, GetOEMCP, GetACP, IsValidCodePage, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, GetStartupInfoW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, TerminateProcess, SetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCPInfo, RtlUnwind, LoadLibraryExW, ExitThread, IsProcessorFeaturePresent, IsDebuggerPresent, GetSystemTimeAsFileTime, GetCommandLineW, HeapSize, HeapReAlloc, HeapDestroy, GetStringTypeW, DecodePointer, EncodePointer, InterlockedDecrement, InterlockedIncrement, lstrcpy
psapi.dll
GetModuleFileNameExW, EnumProcessModules, EnumProcesses
sensapi.dll
IsNetworkAlive
shell32.dll
ShellExecuteExW, SHGetFolderPathW, SHChangeNotify
shlwapi.dll
StrChrW, SHDeleteKeyW, StrCpyW, StrTrimW
user32.dll
wsprintfW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpOpenRequest, WinHttpReceiveResponse, WinHttpReadData, WinHttpCrackUrl, WinHttpGetProxyForUrl, WinHttpAddRequestHeaders, WinHttpOpen, WinHttpQueryDataAvailable, WinHttpQueryHeaders, WinHttpCloseHandle, WinHttpConnect, WinHttpWriteData, WinHttpSendRequest, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSetOption, WinHttpSetTimeouts
wininet.dll
InternetCheckConnectionW, InternetOpenW, InternetOpenUrlW, HttpQueryInfoW, InternetCloseHandle, InternetCrackUrlW, InternetReadFile, InternetConnectW, HttpSendRequestW, InternetSetOptionW, HttpAddRequestHeadersW, HttpOpenRequestW

eGdpSvc.exe

eSafe Security Control by Banyan Tree Technology Limited (Signed)

Remove eGdpSvc.exe
Version:   1.0.0.1982
MD5:   a048327067d7bab53402b0cdc5a11754
SHA1:   17dc98e507152360afae4ce4889edfa880ddeb99
SHA256:   a2ce3c318d4280281e2b5e029fab980470cf88d2d17274b01b83fedfe09a41d0
Warning 7 antivirus scanners has detected malware.

Overview

egdpsvc.exe is malware that runs as a service under the name eSafeSvc (eSafeSvc) with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including eSafe Security Control 1.0.0.1982 published by eSafe Security Co., Ltd. and Wsys Control 10.2.1.2612 published by Banyan Tree Technology Limited. The file is digitally signed by Banyan Tree Technology Limited which was issued by the GlobalSign nv-sa certificate authority (CA).

DetailsDetails

File name:egdpsvc.exe
Publisher:eSafe Security Co., Ltd.
Product name:eSafe Security Control
Description:eSafe Security Control 1.0.0.2522
Typical file path:C:\ProgramData\esafe\egdpsvc.exe
File version:1.0.0.1982
Size:946.56 KB (969,280 bytes)
Build date:3/6/2013 11:37 AM
Certificate
Issued to:Banyan Tree Technology Limited
Authority (CA):GlobalSign nv-sa
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Banyan Tree Technology Limited
  68% remove
Wsys Control also known as Delta-homes.com is a potentially unwanted web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search. It is typically defined as a unwanted application by various malware vendors.
eSafe Security Co., Ltd.
  66% remove
eSafe Security Control, also known as Delta-Home is a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search. The software acts as an adware type application and is typically defined as a unwanted application by various malware vendor...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • eSafeSvc
  • 'eSafeSvc' (eSafe Service)

MalwareMalware detections

Based on 40+ industry antivirus scanners, 7 of them detected the following malware.
Antivirus engineEngine versionDetection
AhnLab V3 Internet Security 2013.09.18 Trojan/Win32.Staser
AVG 13.0.0.3169 Generic34.AWYH
Bkav Security 1.3.0.4246 HW32.CDB.Cd20
ESET NOD32 7.8813 Win32/ELEX.F
Kaspersky 9.0.0.837 Trojan.Win32.Staser.fv
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
VIPRE Antivirus 21586 Elex Installer (fs)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00006241%
0.028634%
Kernel CPU:0.00003089%
0.013761%
User CPU:0.00003152%
0.014873%
Kernel CPU time:4,150 ms/min
100,923,805ms/min
Memory
Private memory:6.86 MB
21.59 MB
Private (maximum):7.62 MB
Private (minimum):6.97 MB
Non-paged memory:6.86 MB
21.59 MB
Virtual memory:85.45 MB
140.96 MB
Virtual memory (peak):96.8 MB
169.69 MB
Working set:7.53 MB
18.61 MB
Working set (peak):10.28 MB
37.95 MB
Resource allocations
Threads:40
12
Handles:223
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:C:\ProgramData\esafe\egdpsvc.exe
Owner:SYSTEM
Windows Service
Service name:eSafeSvc
Display name:eSafeSvc
Description:“System eSafe update service”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
sechost.dll
Total CPU:0.00010996%
0.272967%
Kernel CPU:0.00010996%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:37,350/sec
5,741,424/sec
Memory:100 KB
1.16 MB
eGdpSvc.exe (main module)
Total CPU:0.00010903%
Kernel CPU:0.00003788%
User CPU:0.00007115%
CPU cycles:24,599/sec
Memory:2.09 MB
ntdll.dll
Total CPU:0.00000647%
Kernel CPU:0.00000647%
User CPU:0.00000000%
CPU cycles:12,689/sec
Memory:1.23 MB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 50.00%
Windows 7 Home Premium 33.33%
Microsoft Windows XP 16.67%

Distribution by countryDistribution by country

Argentina installs about 33.33% of eSafe Security Control.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 50.00%
ASUS 50.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE