Should I block it?

98%
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections

VersionsAdditional versions

1.0.0.2522 66.67%
1.0.0.2405 16.67%
1.0.0.1982 16.67%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
ConvertStringSidToSidW, AdjustTokenPrivileges, DuplicateTokenEx, LookupPrivilegeValueW, SetTokenInformation, CreateProcessAsUserW, GetTokenInformation, OpenProcessToken, RegQueryValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ControlService, ReportEventW, QueryServiceStatusEx, SetServiceStatus, ChangeServiceConfigW, StartServiceW, ChangeServiceConfig2W, DeregisterEventSource, RegisterServiceCtrlHandlerExW, RegCreateKeyW, EnumDependentServicesW, StartServiceCtrlDispatcherW, DeleteService, RegisterEventSourceW, CreateServiceW, RegSetValueExW, RegOpenKeyExW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, RegCloseKey, RegCreateKeyExW
comctl32.dll
InitCommonControls
kernel32.dll
GetSystemWindowsDirectoryW, GetCurrentThread, WideCharToMultiByte, LoadLibraryW, SetThreadPriority, LocalAlloc, GetShortPathNameW, LocalFree, GlobalAlloc, CreateFileW, DeviceIoControl, GetVolumeInformationW, GetSystemDefaultLangID, GetFileSize, SetFilePointer, SetEndOfFile, CreateDirectoryW, WriteFile, ReadFile, GetLocalTime, DeleteFileW, GetCurrentProcessId, SetFileAttributesW, GetFileAttributesW, FlushFileBuffers, GetQueuedCompletionStatus, RaiseException, InterlockedExchange, ResetEvent, GetExitCodeThread, PostQueuedCompletionStatus, GetSystemInfo, WaitForMultipleObjects, CreateIoCompletionPort, lstrlenW, GetLogicalDriveStringsW, OpenProcess, GetSystemDirectoryW, ProcessIdToSessionId, QueryDosDeviceW, WriteConsoleW, SetStdHandle, GetEnvironmentVariableW, GetCurrentThreadId, GetProcessHeap, GetTickCount, OutputDebugStringW, HeapFree, HeapAlloc, GlobalFree, MultiByteToWideChar, CreateThread, CreateEventW, GetLastError, TerminateThread, SetEvent, SetPriorityClass, WaitForSingleObject, Sleep, MoveFileExW, CloseHandle, GetProcAddress, GetModuleFileNameW, GetModuleHandleW, GetCurrentProcess, DeleteCriticalSection, LockResource, EnterCriticalSection, LeaveCriticalSection, GetVersionExW, SizeofResource, InitializeCriticalSectionAndSpinCount, FindResourceExW, InitializeCriticalSection, LoadResource, FindResourceW, ReadConsoleW, GetConsoleMode, GetConsoleCP, SetFilePointerEx, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetFileType, GetStdHandle, GetModuleHandleExW, ExitProcess, GetOEMCP, GetACP, IsValidCodePage, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, GetStartupInfoW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, TerminateProcess, SetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCPInfo, RtlUnwind, LoadLibraryExW, ExitThread, IsProcessorFeaturePresent, IsDebuggerPresent, GetSystemTimeAsFileTime, GetCommandLineW, HeapSize, HeapReAlloc, HeapDestroy, GetStringTypeW, DecodePointer, EncodePointer, InterlockedDecrement, InterlockedIncrement, lstrcpy
psapi.dll
GetModuleFileNameExW, EnumProcessModules, EnumProcesses
sensapi.dll
IsNetworkAlive
shell32.dll
ShellExecuteExW, SHGetFolderPathW, SHChangeNotify
shlwapi.dll
StrChrW, SHDeleteKeyW, StrCpyW, StrTrimW
user32.dll
wsprintfW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpOpenRequest, WinHttpReceiveResponse, WinHttpReadData, WinHttpCrackUrl, WinHttpGetProxyForUrl, WinHttpAddRequestHeaders, WinHttpOpen, WinHttpQueryDataAvailable, WinHttpQueryHeaders, WinHttpCloseHandle, WinHttpConnect, WinHttpWriteData, WinHttpSendRequest, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSetOption, WinHttpSetTimeouts
wininet.dll
InternetCheckConnectionW, InternetOpenW, InternetOpenUrlW, HttpQueryInfoW, InternetCloseHandle, InternetCrackUrlW, InternetReadFile, InternetConnectW, HttpSendRequestW, InternetSetOptionW, HttpAddRequestHeadersW, HttpOpenRequestW

eGdpSvc.exe

eSafe Security Control by Banyan Tree Technology Limited (Signed)

Remove eGdpSvc.exe
Version:   1.0.0.2405
MD5:   e536d1cde3f600f49d606aded29a50e2
SHA1:   7e717e51a164deca6b12555d900341b01dc34e1a
SHA256:   92379f3a8c3dfb0b35360714c34947daeeb086eb45262215899e05aaff388c59
Warning 13 antivirus scanners has detected malware.

Overview

egdpsvc.exe is malware that runs as a service under the name eSafeSvc (eSafeSvc) within the local user context. It is installed with a couple of know programs including eSafe Security Control 1.0.0.2522 published by Banyan Tree Technology Limited and Wsys Control 10.2.1.2634 published by Banyan Tree Technology Limited. The file is digitally signed by Banyan Tree Technology Limited which was issued by the GlobalSign nv-sa certificate authority (CA).

DetailsDetails

File name:egdpsvc.exe
Publisher:eSafe Security Co., Ltd.
Product name:eSafe Security Control
Description:eSafe Security Control 1.0.0.2522
Typical file path:C:\ProgramData\esafe\egdpsvc.exe
File version:1.0.0.2405
Size:352.06 KB (360,512 bytes)
Build date:5/29/2013 4:46 AM
Certificate
Issued to:Banyan Tree Technology Limited
Authority (CA):GlobalSign nv-sa
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Banyan Tree Technology Limited
  83% remove
eSafe is a potentially unwanted web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser.
Banyan Tree Technology Limited
  66% remove
Wsys Control also known as Delta-homes.com is a potentially unwanted web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search. It is typically defined as a unwanted application by various malware vendors.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • eSafeSvc
  • 'eSafeSvc' (eSafe Service)

MalwareMalware detections

Based on 40+ industry antivirus scanners, 13 of them detected the following malware.
Antivirus engineEngine versionDetection
AhnLab V3 Internet Security 2013.09.20 Trojan/Win32.Staser
Antiy Labs AVL 2.0.3.7 Trojan/Win32.Staser
AVG 13.0.0.3169 Banan.B
Dr.Web 8.13.10.5 Adware.Siggen.25992
ESET NOD32 7.8821 a variant of Win32/ELEX.M
Jiangmin 16.0.100 Trojan/Generic.bgmke
Kaspersky 9.0.0.837 Trojan.Win32.Staser.fv
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
McAfee 5.600.1067 PUP-FCT!E536D1CDE3F6
McAfee Gateway Anti-Malware v2013-dat PUP-FCT!E536D1CDE3F6
PC Tools 9.0.0.2 SecurityRisk.exqWebSearch
Symantec 20131.1.5.61 exqWebSearch
VIPRE Antivirus 21646 Elex Installer (fs)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 50.00%
Windows 7 Home Premium 33.33%
Microsoft Windows XP 16.67%

Distribution by countryDistribution by country

Argentina installs about 33.33% of eSafe Security Control.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 50.00%
ASUS 50.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE