Eorezo

Publisher Information

Eorezo is a software publisher located in Paris, Ile De France in France*. The company is a primary distributor of unwanted software. EoRezo is an adware company that distributes various web borwser extensions and plugin for the purpose of context advertsing. The software is designed to deliver pop-ups and change the home page and search engine used by Internet Explorer, Chrome and Firefox. Thre are 2 additional code signing certificates issued to this publisher.
Remove Eorezo Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
10/14/2008 2:00:00 AM

Valid to:
10/15/2009 1:59:59 AM

Subject:
CN=Eorezo, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Eorezo, L=Paris, S=Ile de France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5158654305438a3e707630d3bfde7c69

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BHO.Eorezo.J, PUP.Eorezo.I, PUP.Eorezo.P, PUP.Eorezo.K, PUP.Eorezo.M, PUP.Eorezo.F, PUP.Eorezo (M), PUP.Eorezo.Installer (M)
100.00%

VIPRE Antivirus
Adware.Eorezo.a
79.31%

avast!
Win32:Eorezo-N [PUP], Win32:Eorezo-M [PUP], Win32:Eorezo-AI [PUP], Win32:PUP-gen [PUP], Win32:Eorezo-F [PUP]
79.31%

Trend Micro House Call
TROJ_GEN.F47V0405, ADW_EOREZO, TROJ_GEN.F47V1103
51.72%

Trend Micro
ADW_EOREZO
44.83%

Microsoft Security Essentials
Adware:Win32/EoRezo
41.38%

AVG
Generic4, Generic5
37.93%

IKARUS anti.virus
AdWare.Win32.EoRezo
37.93%

AhnLab V3 Security
Adware/Win32.Eorezo
31.03%

Malwarebytes
Rogue.Eorezo, Trojan.Eorezo
13.79%

1 / 68      (Adware)
EoRezoBHO.dll (EoRezoBHO by EoRezo)  (44439a8f6cebb97cb61aac19a692ff79)

1 / 68      (Adware)

1 / 68      (Adware)
EoEngine.EXE (Application EoEngine)  (13dc2e2c77d1d4f4f2385d6c7e3a6298)

1 / 68      (Adware)
setup_eowiki_eo.exe (by EoRezo)  (2330ded58327dd3638029fb5e847850b)

1 / 68      (Adware)
EoEngine.EXE (Application EoEngine)  (d80e045580bd65069879d96be328c88c)

1 / 68      (Adware)

9 / 68      (Adware)
eorezotools_30.dll  (4e2b381f1e169d331d2bbb3bbddb2720)

8 / 68      (Adware)
eorezotools_29.dll  (00dfabf8054bebcf8d808e21dbf76bfc)

8 / 68      (Adware)
eorezotools_28.dll  (dc344b35310578aeb15a2b728e876f5e)

9 / 68      (Adware)

10 / 68    (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

8 / 68      (Adware)

9 / 68      (Adware)

10 / 68    (Adware)

24 / 68    (Adware)
SoftwareUpdateHP.exe (SoftwareHelper by EoRezo)  (5ecd3c3b70b6b50f284dbaf6016b2ddf)

14 / 68    (Adware)
SoftwareUpdate.exe (SoftwareUpdate by EoRezo)  (a5de97601c97d5d337ccf4455ef63163)

4 / 68      (Adware)
EoAdv.DLL (Bibliothèque de liaison dynamique EoAdv)  (d59d74211a4197b1e8d03a25fd54df27)

5 / 68      (Adware)

4 / 68      (Adware)

5 / 68      (Adware)

3 / 68      (Adware)

3 / 68      (Adware)

5 / 68      (Adware)

4 / 68      (Adware)

4 / 68      (Adware)

8 / 68      (Adware)
EoEngine.EXE (Application EoEngine)  (7629c07c6df3e7f662da4c6d55994f46)

4 / 68      (Adware)
EoRezoBHO.dll (EoRezoBHO by EoRezo)  (d00a9b03a5c97f55016a404b3c4f2fac)

The certificates below are also signed by Eorezo.

1C6BCF65EA37004BFC9D8ABAF7BE4E73  (Oct 12, 2010 to Oct 14, 2012)

5EDC28477A0DFD565E10C4389B873701  (Dec 03, 2009 to Oct 15, 2010)

Remove Eorezo Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Eorezo by VeriSign, Inc. on October 14, 2008 with the serial number '5158654305438a3e707630d3bfde7c69'.