eorezotools_18.dll

Bibliothèque de liaison dynamique EoRezoTools

Eorezo

This is part of the Eorezo downloader which may bundle additional offers on the PC, mostly adware and other potentially unwanted software. The module eorezotools_18.dll by Eorezo has been detected as adware by 8 anti-malware scanners. This browser extension displays targeted advertising by monitoring the URLs viewed in the web browser.
Publisher:
Eorezo  (signed and verified)

Product:
Bibliothèque de liaison dynamique EoRezoTools

Description:
EoRezoTools DLL

Version:
1, 0, 0, 1

MD5:
aebc927c4ba29e129f5d67e9ff310d81

SHA-1:
b7f3316cb5d07eb57d2eeca96cf41c414a325074

SHA-256:
a39e6fb605eda513472ea2da291630b38f0e5e175900dd5d7c3e4a598d765c62

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
4/24/2024 11:23:14 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Eorezo-F [PUP]
2014.9-150129

AVG
Generic5
2016.0.3215

IKARUS anti.virus
AdWare.Win32.EoRezo
t3scan.2.0.127

Microsoft Security Essentials
1.163.1557.3

Reason Heuristics
PUP.Eorezo
15.1.29.7

Trend Micro House Call
ADW_EOREZO
7.2.29

Trend Micro
ADW_EOREZO
10.465.29

VIPRE Antivirus
Adware.Eorezo.a
22988

File size:
829.8 KB (849,744 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2005

Original file name:
EoRezoTools.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
French (France)

Common path:
C:\Program Files\eorezo\eorezotools_18.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/14/2008 2:00:00 AM

Valid to:
10/15/2009 1:59:59 AM

Subject:
CN=Eorezo, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Eorezo, L=Paris, S=Ile de France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5158654305438A3E707630D3BFDE7C69

File PE Metadata
Compilation timestamp:
7/6/2007 4:55:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:sn0UksOE8lFpkNaz+uGNsRD++ZLf6rav2M:yv8CejLf6G2M

Entry address:
0x3D1F7

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, C0, 94, 06, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, E0, 38, 06, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, 79, 40, FD, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
272 KB (278,528 bytes)

Remove eorezotools_18.dll - Powered by Reason Core Security