Adware.Agent2!aevvS3U8FM8

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Adware.Agent2!aevvS3U8FM8 also known as Application.Winfixer.AG, ADSPY/SafeError.A.6.

Malware Analysis of Adware.Agent2!aevvS3U8FM8 – FXCORE.DLL

Created files:

%Program Files%\ErrorSafe Free\FRec.dll
%Program Files%\ErrorSafe Free\FWraper.dll
%Program Files%\ErrorSafe Free\FxCore.dll
%Program Files%\ErrorSafe Free\InstHelp.exe
%Program Files%\ErrorSafe Free\lapv.dat

Autostart registry keys:

HKLM\Software\Classes\CLSID\{06170642-FA65-4FB6-AC79-5F235CB99BC2}\InProcServer32\: “%Program Files%\ErrorSafe Free\FxCore.dll”
HKLM\Software\Classes\CLSID\{1640DE0E-75E4-4a83-B5D1-2492BC7EBA8F}\InprocServer32\: “%Program Files%\ErrorSafe Free\MMFx.dll”
HKLM\Software\Classes\CLSID\{647B8364-79E0-48e2-A4CA-233ABADA0C2D}\InprocServer32\: “%Program Files%\ErrorSafe Free\ESSPChck.dll”
HKLM\Software\Classes\CLSID\{9E87077C-380C-407d-8DAB-EEDAD95C0A5D}\InprocServer32\: “%Program Files%\ErrorSafe Free\FWraper.dll”
HKLM\Software\Classes\CLSID\{B0F4BC0F-EAEA-43B5-8CE6-DAD3CC9B29A2}\InProcServer32\: “%Program Files%\ErrorSafe Free\MMFx.dll”
HKLM\Software\Classes\CLSID\{CCAABCDD-7C16-4215-B12E-150BFB994CF0}\InprocServer32\: “%Program Files%\ErrorSafe Free\FxCore.dll”
HKLM\Software\Classes\CLSID\{F63E3B76-F82F-46EB-851C-8C0A221686BB}\InprocServer32\: “C:\PROGRA~1\ERRORS~1\FlFxr15.dll”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1\DisplayName: “ErrorSafe 1.3.156.2”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1\UninstallString: “”%Program Files%\ErrorSafe Free\unins000.exe””
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Error Safe Free: “%Program Files%\ErrorSafe Free\uers.exe /scan”

Detected by UnHackMe:

FXCORE.DLL
Default location: %PROGRAM FILES%\ERRORSAFE FREE\FXCORE.DLL

Dropper hash(md5): 05bd88a1e30b455386568c9654ec00d1

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera