间谍软件ErrorSafe
概述
类别
Adware : 在网页上方或后方的弹出广告的软件,此时主用户界面还不可见,或与产品没有什么关联。
Annoyance: 仅对用户造成妨碍的任何特洛伊木马程序,例如将屏幕上的文字上下颠倒,或使鼠标莫名其妙地移动。
发源
作者
ErrorSafe
发源日期
2006年1月
检测和删除
手工删除
按照以下步骤从您的机器删除ErrorSafe。先备份您的注册表和系统,并设置一个还原点,防止发生错误。
停止运行进程:
利用任务管理器停止以下运行进程:
errorsafescannersetup2222.exe
programfilesdir+errorsafeers.exe
errorsafescannerinstall_de.exe
df_kme.exe
programfilesdir+errorsafeinstall.exe
programfilesdir+errorsafesr.exe
programfilesdir+errorsafeunins001.exe
programfilesdir+errorsafeunins000.exe
撤消 DLL 的注册:
使用 Regsvr32 撤销以下 DLLs 的注册,然后重启:
programfilesdir+errorsafestrres.dll
programfilesdir+errorsafemmfix.dll
programfilesdir+errorsafeftrec.dll
programfilesdir+errorsafeflfxr5.dll
programfilesdir+errorsafefixcore.dll
programfilesdir+errorsafeffwraper.dll
programfilesdir+errorsafeesspcheck.dll
programfilesdir+errorsafeespcheck.dll
programfilesdir+errorsafeecc.dll
programfilesdir+errorsafedf_proxy.dll
programfilesdir+errorsafedf_fixer.dll
删除自动运行的引用:
访问 HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
如果找到值 HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversion
un errorsafe,立即删除并重启机器
清除注册表:
使用注册表编辑器清除以下注册项(如果存在):
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTclsid
HKEY_CLASSES_ROOTescompcleancore.esappcleaner
HKEY_CLASSES_ROOTescompcleancore.esappcleaner.1
HKEY_CLASSES_ROOTescompcleancore.esccquickscan
HKEY_CLASSES_ROOTescompcleancore.esccquickscan.1
HKEY_CLASSES_ROOTescompcleancore.esfilecleaner
HKEY_CLASSES_ROOTescompcleancore.esfilecleaner.1
HKEY_CLASSES_ROOTescompcleancore.esinetcleaner
HKEY_CLASSES_ROOTescompcleancore.esinetcleaner.1
HKEY_CLASSES_ROOTescompcleancore.esregcleaner
HKEY_CLASSES_ROOTescompcleancore.esregcleaner.1
HKEY_CLASSES_ROOTescompcleancore.essystemcleaner
HKEY_CLASSES_ROOTescompcleancore.essystemcleaner.1
HKEY_CLASSES_ROOTesdf_fixer.esfixer
HKEY_CLASSES_ROOTesdf_fixer.esfixer.1
HKEY_CLASSES_ROOTesdf_proxy.esdrivermanipulate
HKEY_CLASSES_ROOTesdf_proxy.esdrivermanipulate.1
HKEY_CLASSES_ROOTesffwraper.esffenginwraper
HKEY_CLASSES_ROOTesffwraper.esffenginwraper.1
HKEY_CLASSES_ROOTesfixcore.esmmfixcore
HKEY_CLASSES_ROOTesfixcore.esmmfixcore.1
HKEY_CLASSES_ROOTesmmfixctrl.escofixengine
HKEY_CLASSES_ROOTesmmfixctrl.escofixengine.1
HKEY_CLASSES_ROOTesspcheck.esspcheck
HKEY_CLASSES_ROOTesspcheck.esspcheck.1
HKEY_CLASSES_ROOTflfxr5.flfixer5
HKEY_CLASSES_ROOTflfxr5.flfixer5clsid
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CLASSES_ROOTypelib
HKEY_CURRENT_USERsoftwareerrorsafe
HKEY_CURRENT_USERsoftwareerrorsafeerrorsafe
HKEY_LOCAL_MACHINEsoftwareerrorsafe
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversion
un errorsafe
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallers_is1
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallersu_is1
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetenum
ootlegacy_erssdd
HKEY_LOCAL_MACHINEsystemcurrentcontrolsetserviceserssdd
删除文件:
使用资源管理器删除以下文件(如果存在):
errorsafescannersetup2222.exe
ers.exe
erssdd.sys
espcheck.dll
esspcheck.dll
ffwraper.dll
fixcore.dll
flfxr5.dll
ftrec.dll
install.exe
license.rtf
mmfix.dll
sr.exe
strres.dll
commonprograms+errorsafecontact customer support.lnk
commonprograms+errorsafeerrorsafe deinstallieren.lnk
commonprograms+errorsafeerrorsafe im netz.lnk
commonprograms+errorsafeerrorsafe on the web.lnk
commonprograms+errorsafeerrorsafe.lnk
commonprograms+errorsafekundendienst kontaktieren.lnk
commonprograms+errorsafeuninstall errorsafe.lnk
desktopdir+errorsafe.lnk
profilepath+race.log
programfilesdir+errorsafeactivate.dat
programfilesdir+errorsafenlink.dat
programfilesdir+errorsafedatabase.sav
df_fixer.dll
df_kme.exe
df_proxy.dll
ecc.dll
errorsafescannerinstall_de.exe
programfilesdir+errorsafedf_fixer.dll
programfilesdir+errorsafedf_proxy.dll
programfilesdir+errorsafeecc.dll
programfilesdir+errorsafeers.exe
programfilesdir+errorsafeers.url
programfilesdir+errorsafeerssdd.sys
programfilesdir+errorsafeespcheck.dll
programfilesdir+errorsafeesspcheck.dll
programfilesdir+errorsafeffwraper.dll
programfilesdir+errorsafefixcore.dll
programfilesdir+errorsafeflash.ini
programfilesdir+errorsafeflfxr5.dll
programfilesdir+errorsafeftrec.dll
programfilesdir+errorsafeunins001.exe
programfilesdir+errorsafeinstall.exe
programfilesdir+errorsafelapv.dat
programfilesdir+errorsafelicense.rtf
programfilesdir+errorsafelock.dat
programfilesdir+errorsafemmfix.dll
programfilesdir+errorsafeprogram.sav
programfilesdir+errorsafepv.dat
programfilesdir+errorsafestrres.dll
programfilesdir+errorsafesupport.url
programfilesdir+errorsafeemplate.dbx
programfilesdir+errorsaferace.log
programfilesdir+errorsafeunins000.dat
programfilesdir+errorsafesr.exe
programfilesdir+errorsafesr.log
programfilesdir+errorsafeunins000.exe
programfilesdir+errorsafeunins001.dat
删除目录:
使用资源管理器删除以下目录(如果存在):
programfilesdir+errorsafe
programfilesdir+errorsafeackup
programfilesdir+errorsafemp3db
programfilesdir+errorsafempegdb
programfilesdir+errorsafe
epaired
programfilesdir+errorsafeasks
programfilesdir+errorsafewavedb
调查
文件分析
ErrorSafe
调查方式
间谍软件研究中心