Should I block it?

98%
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
AdjustTokenPrivileges, DuplicateTokenEx, LookupPrivilegeValueW, ConvertStringSidToSidW, SetTokenInformation, CreateProcessAsUserW, GetTokenInformation, OpenProcessToken, RegQueryValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ControlService, ReportEventW, QueryServiceStatusEx, SetServiceStatus, ChangeServiceConfigW, StartServiceW, ChangeServiceConfig2W, DeregisterEventSource, RegisterServiceCtrlHandlerExW, RegCreateKeyW, EnumDependentServicesW, StartServiceCtrlDispatcherW, DeleteService, RegisterEventSourceW, CreateServiceW, RegSetValueExW, RegOpenKeyExW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, RegCloseKey, RegCreateKeyExW
kernel32.dll
GetCurrentThread, WideCharToMultiByte, LoadLibraryW, SetThreadPriority, LocalAlloc, GetShortPathNameW, LocalFree, GlobalAlloc, CreateFileW, DeviceIoControl, GetVolumeInformationW, GetSystemDefaultLangID, GetLocalTime, DeleteFileW, GetFileSize, CreateDirectoryW, WriteFile, GetFileAttributesW, ReadFile, FlushFileBuffers, GetSystemWindowsDirectoryW, SetFileAttributesW, SetFilePointer, GetQueuedCompletionStatus, InitializeCriticalSectionAndSpinCount, RaiseException, InterlockedExchange, ResetEvent, GetExitCodeThread, PostQueuedCompletionStatus, GetSystemInfo, CreateIoCompletionPort, lstrlenW, GetLogicalDriveStringsW, OpenProcess, GetSystemDirectoryW, ProcessIdToSessionId, QueryDosDeviceW, SetEndOfFile, WriteConsoleW, GetEnvironmentVariableW, GetCurrentThreadId, GetProcessHeap, GetTickCount, OutputDebugStringW, HeapFree, HeapAlloc, GlobalFree, MultiByteToWideChar, CreateThread, CreateEventW, GetLastError, TerminateThread, SetEvent, SetPriorityClass, WaitForSingleObject, Sleep, MoveFileExW, CloseHandle, GetProcAddress, GetModuleFileNameW, GetModuleHandleW, GetCurrentProcess, DeleteCriticalSection, LockResource, EnterCriticalSection, LeaveCriticalSection, GetVersionExW, SizeofResource, InitializeCriticalSection, LoadResource, FindResourceW, FindResourceExW, SetStdHandle, ReadConsoleW, SetFilePointerEx, GetConsoleMode, GetConsoleCP, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCurrentProcessId, QueryPerformanceCounter, GetFileType, GetStdHandle, GetModuleHandleExW, ExitProcess, GetOEMCP, GetACP, IsValidCodePage, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, GetStartupInfoW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, TerminateProcess, SetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCPInfo, RtlUnwind, LoadLibraryExW, ExitThread, IsProcessorFeaturePresent, IsDebuggerPresent, GetSystemTimeAsFileTime, GetCommandLineW, HeapSize, HeapReAlloc, HeapDestroy, GetStringTypeW, DecodePointer, EncodePointer, InterlockedDecrement, InterlockedIncrement
psapi.dll
GetModuleFileNameExW, EnumProcessModules, EnumProcesses
sensapi.dll
IsNetworkAlive
shell32.dll
SHChangeNotify, SHGetFolderPathW, ShellExecuteExW
shlwapi.dll
StrTrimW, StrCpyW, SHDeleteKeyW, StrChrW
user32.dll
wsprintfW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpReceiveResponse, WinHttpSetTimeouts, WinHttpReadData, WinHttpCrackUrl, WinHttpGetProxyForUrl, WinHttpOpenRequest, WinHttpOpen, WinHttpQueryDataAvailable, WinHttpQueryHeaders, WinHttpCloseHandle, WinHttpConnect, WinHttpWriteData, WinHttpSendRequest, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSetOption, WinHttpAddRequestHeaders
wininet.dll
InternetCheckConnectionW, InternetOpenUrlW, HttpQueryInfoW, InternetCloseHandle, InternetCrackUrlW, InternetReadFile, InternetConnectW, HttpSendRequestW, InternetSetOptionW, HttpAddRequestHeadersW, HttpOpenRequestW, InternetOpenW

esafesvc.exe

eSafe Security Control by Banyan Tree Technology Limited (Signed)

Remove esafesvc.exe
Version:   1.0.0.2359
MD5:   f31572c8035eeb5cfecfe406925ebadd
SHA1:   086f56fa97a392ae2113718e2b3a71b1874927bb
SHA256:   3f502030ae1fbd66b033bf236dbe65acac526a203cb7be1594e21de486c2558e
Warning 16 antivirus scanners has detected malware.

Overview

esafesvc.exe is malware that runs as a service under the name eSafeSvc (eSafeSvc) with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including eSafe Security Control 1.0.0.2359 published by eSafe Security Co., Ltd., eSafe Security Control 1.0.0.2522 from Banyan Tree Technology Limited and eSafe Security Control 1.0.0.2522 by Banyan Tree Technology Limited. The file is digitally signed by Banyan Tree Technology Limited which was issued by the GlobalSign nv-sa certificate authority (CA).

DetailsDetails

File name:esafesvc.exe
Publisher:eSafe Security Co., Ltd.
Product name:eSafe Security Control
Description:eSafe Security Control 1.0.0.2359
Typical file path:C:\ProgramData\esafe\esafesvc.exe
Original name:eGdpSvc.exe
File version:1.0.0.2359
Size:352.06 KB (360,512 bytes)
Build date:4/24/2013 12:43 AM
Certificate
Issued to:Banyan Tree Technology Limited
Authority (CA):GlobalSign nv-sa
Effective date:Wednesday, January 9, 2013
Expiration date:Saturday, January 10, 2015
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Banyan Tree Technology Limited
  83% remove
eSafe is a potentially unwanted web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser.
Banyan Tree Technology Limited
  68% remove
Wsys Control also known as Delta-homes.com is a potentially unwanted web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search. It is typically defined as a unwanted application by various malware vendors.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • eSafeSvc
  • 'eSafeSvc' (eSafe Service)

MalwareMalware detections

Based on 40+ industry antivirus scanners, 16 of them detected the following malware.
Antivirus engineEngine versionDetection
AhnLab V3 Internet Security 2013.09.17 Trojan/Win32.Staser
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Staser
Dr.Web 8.13.9.30 Adware.Siggen.25992
ESET NOD32 7.8807 a variant of Win32/ELEX.M
Jiangmin 16.0.100 Trojan/Generic.bgmke
K7 AntiVirus 9.172.9576 Trojan
Kaspersky 9.0.0.837 Trojan.Win32.Staser.fv
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
McAfee 5.600.1067 PUP-FCT!F31572C8035E
McAfee Gateway Anti-Malware v2013-dat PUP-FCT!F31572C8035E
PC Tools 9.0.0.2 SecurityRisk.exqWebSearch
Symantec 20131.1.5.61 exqWebSearch
Trend Micro 9.740.0.1012 TROJ_GEN.F0C2C0KHT13
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.R0CBH05IA13
Vba32 AntiVirus 3.12.24.2 Trojan.Staser
VIPRE Antivirus 21528 Elex Installer (fs)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00140819%
0.028634%
Kernel CPU:0.00097026%
0.013761%
User CPU:0.00043794%
0.014873%
Kernel CPU time:427 ms/min
100,923,805ms/min
CPU cycles:112,614/sec
17,470,203/sec
Memory
Private memory:3.44 MB
21.59 MB
Private (maximum):7.12 MB
Private (minimum):6.6 MB
Non-paged memory:3.44 MB
21.59 MB
Virtual memory:68.47 MB
140.96 MB
Virtual memory (peak):72.33 MB
169.69 MB
Working set:6.96 MB
18.61 MB
Working set (peak):7.3 MB
37.95 MB
Page faults:4,087/min
2,039/min
I/O
I/O read transfer:40 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:232 Bytes/sec
448.09 KB/min
I/O other operations:14/sec
1,671/min
Resource allocations
Threads:16
12
Handles:181
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command lines:
  • C:\ProgramData\esafe\egdpsvc.exe
  • C:\ProgramData\esafe\esafesvc.exe
Owner:SYSTEM
Windows Service
Service name:eSafeSvc
Display name:eSafeSvc
Description:“System eSafe update service”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.00540944%
0.272967%
Kernel CPU:0.00540944%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:13,085/sec
5,741,424/sec
Memory:276 KB
1.16 MB
ntdll.dll
Total CPU:0.00373592%
Kernel CPU:0.00373592%
User CPU:0.00000000%
CPU cycles:24,377/sec
Memory:1.23 MB
eSafeSvc.exe (main module)
Total CPU:0.00054978%
Kernel CPU:0.00034071%
User CPU:0.00020906%
CPU cycles:10,262/sec
Memory:372 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 Single Language 33.33%
Windows 7 Ultimate 33.33%
Microsoft Windows XP 16.67%
Windows 8 16.67%

Distribution by countryDistribution by country

Saudi Arabia installs about 33.33% of eSafe Security Control.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 44.44%
Hewlett-Packard 33.33%
ASUS 22.22%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE