eorezotools_20.dll

Bibliothèque de liaison dynamique EoRezoTools

Eorezo

This is part of the Eorezo downloader which may bundle additional offers on the PC, mostly adware and other potentially unwanted software. The module eorezotools_20.dll by Eorezo has been detected as adware by 9 anti-malware scanners. This browser extension displays targeted advertising by monitoring the URLs viewed in the web browser.
Publisher:
Eorezo  (signed and verified)

Product:
Bibliothèque de liaison dynamique EoRezoTools

Description:
EoRezoTools DLL

Version:
1, 0, 0, 1

MD5:
a89bb4410e4627cb2a4c0f9b480ab57e

SHA-1:
2e08d049fd8f28ec67178358b0661e1bb25fbfb1

SHA-256:
993b4d57ac24b8200f706958ee2d17bbab628fc7467d261e1021ce8760022106

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
11/15/2024 9:24:47 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.Eorezo
2013.11.03

avast!
Win32:Eorezo-F [PUP]
2014.9-150129

AVG
Generic5
2016.0.3215

IKARUS anti.virus
AdWare.Win32.EoRezo
t3scan.2.0.127

Microsoft Security Essentials
1.163.1557.3

Reason Heuristics
PUP.Eorezo
15.1.29.7

Trend Micro House Call
ADW_EOREZO
7.2.29

Trend Micro
ADW_EOREZO
10.465.29

VIPRE Antivirus
Adware.Eorezo.a
22988

File size:
849.8 KB (870,224 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2005

Original file name:
EoRezoTools.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
French (France)

Common path:
C:\Program Files\eorezo\eorezotools_20.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/14/2008 2:00:00 AM

Valid to:
10/15/2009 1:59:59 AM

Subject:
CN=Eorezo, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Eorezo, L=Paris, S=Ile de France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5158654305438A3E707630D3BFDE7C69

File PE Metadata
Compilation timestamp:
8/24/2007 5:15:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:e5sCgjYtiroXnjIeFz+uWNsxD++ZLf6eoB3:OPDnjfFC6jLf6eoB3

Entry address:
0x40F17

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, 00, E5, 06, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, E0, 88, 06, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, 79, 07, FD, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
288 KB (294,912 bytes)

Remove eorezotools_20.dll - Powered by Reason Core Security