eorezotools_26.dll

Bibliothèque de liaison dynamique EoRezoTools

Eorezo

This is part of the Eorezo downloader which may bundle additional offers on the PC, mostly adware and other potentially unwanted software. The module eorezotools_26.dll by Eorezo has been detected as adware by 10 anti-malware scanners. This browser extension displays targeted advertising by monitoring the URLs viewed in the web browser.
Publisher:
Eorezo  (signed and verified)

Product:
Bibliothèque de liaison dynamique EoRezoTools

Description:
EoRezoTools DLL

Version:
1, 0, 0, 1

MD5:
7d1b81055c752fd1d7c77d983d898e35

SHA-1:
c4d51664edaa1f478b44ff45c32e575b55126226

SHA-256:
4268683dfb54cc4c74eeb0af111eba002c7fbf2242b367af724d46bb3c667f04

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
11/15/2024 9:59:43 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

AhnLab V3 Security
Adware/Win32.Eorezo
2013.11.03

avast!
Win32:Eorezo-F [PUP]
2014.9-150129

AVG
Generic5
2016.0.3215

IKARUS anti.virus
AdWare.Win32.EoRezo
t3scan.2.0.127

Microsoft Security Essentials
1.163.1557.3

Reason Heuristics
PUP.Eorezo
15.1.29.7

Trend Micro House Call
ADW_EOREZO
7.2.29

Trend Micro
ADW_EOREZO
10.465.29

VIPRE Antivirus
Adware.Eorezo.a
22988

File size:
877.8 KB (898,896 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2005

Original file name:
EoRezoTools.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
French (France)

Common path:
C:\Program Files\eorezo\eorezotools_26.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/14/2008 2:00:00 AM

Valid to:
10/15/2009 1:59:59 AM

Subject:
CN=Eorezo, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Eorezo, L=Paris, S=Ile de France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5158654305438A3E707630D3BFDE7C69

File PE Metadata
Compilation timestamp:
7/8/2008 11:44:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:9ESpKk/L20h2oNCfEBOfkGusZ0+u2NsrD++ZLf6o2:32oNCfEBOfLu8vwjLf6r

Entry address:
0x42A27

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, F0, 43, 07, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, 24, DF, 06, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, A9, EC, FC, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
296 KB (303,104 bytes)

Remove eorezotools_26.dll - Powered by Reason Core Security