eorezotools_17.dll

Bibliothèque de liaison dynamique EoRezoTools

Eorezo

This is part of the Eorezo downloader which may bundle additional offers on the PC, mostly adware and other potentially unwanted software. The module eorezotools_17.dll by Eorezo has been detected as adware by 9 anti-malware scanners. This browser extension displays targeted advertising by monitoring the URLs viewed in the web browser.
Publisher:
Eorezo  (signed and verified)

Product:
Bibliothèque de liaison dynamique EoRezoTools

Description:
EoRezoTools DLL

Version:
1, 0, 0, 1

MD5:
1f2c25f72ae57d1f4bc881d8aafbb49a

SHA-1:
5e01dde9cb9e62cb6490ef99ce0f708da1a41ef0

SHA-256:
0b9e401effd9719ffd31c30c228e58de36c3d1a93cdc317783701264d6ee9ccc

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
11/15/2024 9:54:06 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.Eorezo
2013.11.03

avast!
Win32:Eorezo-F [PUP]
2014.9-150129

AVG
Generic5
2016.0.3215

IKARUS anti.virus
AdWare.Win32.EoRezo
t3scan.2.0.127

Microsoft Security Essentials
1.163.1557.3

Reason Heuristics
PUP.Eorezo
15.1.29.7

Trend Micro House Call
ADW_EOREZO
7.2.29

Trend Micro
ADW_EOREZO
10.465.29

VIPRE Antivirus
Adware.Eorezo.a
22988

File size:
829.8 KB (849,744 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2005

Original file name:
EoRezoTools.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
French (France)

Common path:
C:\Program Files\eorezo\eorezotools_17.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/14/2008 2:00:00 AM

Valid to:
10/15/2009 1:59:59 AM

Subject:
CN=Eorezo, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Eorezo, L=Paris, S=Ile de France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5158654305438A3E707630D3BFDE7C69

File PE Metadata
Compilation timestamp:
6/15/2007 3:49:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:rn0UksOE8lFpkoNz+uGNsRD++ZLf6rav2n:zvwCejLf6G2n

Entry address:
0x3D1F7

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, C0, 94, 06, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, E0, 38, 06, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, 79, 40, FD, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
272 KB (278,528 bytes)

Remove eorezotools_17.dll - Powered by Reason Core Security