Adware

Adware.EoRezo.Gen removal

Malware Removal

The Adware.EoRezo.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.EoRezo.Gen virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to execute a powershell command with suspicious parameter/s
  • Attempts to identify installed AV products by registry key

Related domains:

ads.cloud4ads.com
ads.noforyoubutyoucantry.com

How to determine Adware.EoRezo.Gen?


File Info:

crc32: 2AD75741
md5: d6c62272635a941d86db2967a071e935
name: D6C62272635A941D86DB2967A071E935.mlw
sha1: f58c8578a11788cc82315390a05572efa5ab75dc
sha256: dd5e3e74985ce8b9a95d7ef7178d56b9ef93b9e7a2983968b04784c57c40c8c0
sha512: b0dea4215518857ba5f6923d0f31a30f828cc178295f6e4e9ad6c4a8551ff0a407c10801f0198dddcd80fd84e6d0f062bfd490e2b4aea07a0ea5b9b17c8368ed
ssdeep: 12288:2QiGtg6ubROmJyVbXMwBPBWoAM7hL8+iDfqyw921+EjRRjsh7YY9rqYNjZyzyE9:2QiItu1CXM8PbAM7585yMR9AzEp9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: 493
ProductVersion:
FileDescription: 493 Setup
Translation: 0x0000 0x04b0

Adware.EoRezo.Gen also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Adware.Adseo.1
FireEyeGen:Adware.Adseo.1
McAfeeArtemis!D6C62272635A
MalwarebytesAdware.EoRezo.Gen
ZillyaDownloader.Upatre.Win32.56367
Cybereasonmalicious.2635a9
SymantecTrojan.Gen.2
APEXMalicious
AvastNSIS:Adware-ADQ [PUP]
Kasperskynot-a-virus:AdWare.Win32.Eorezo.aysx
BitDefenderGen:Adware.Adseo.1
NANO-AntivirusRiskware.InnoSetup.Eorezo.ebgmok
Paloaltogeneric.ml
AegisLabAdware.Win32.Eorezo.mCTW
TencentWin32.Adware.Eorezo.Wtdm
Ad-AwareGen:Adware.Adseo.1
SophosEorezo (PUA)
DrWebAdware.Eorezo.806
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.dc
EmsisoftGen:Adware.Adseo.1 (B)
GDataScript.Adware.EoRezo.K
JiangminAdWare.Eorezo.api
AviraADWARE/EoRezo.1022988
Antiy-AVLGrayWare[AdWare]/Win32.EoRezo.ay
ZoneAlarmnot-a-virus:AdWare.Win32.Eorezo.aysx
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.EoRezo.R175844
ALYacGen:Adware.Adseo.1
ESET-NOD32multiple detections
YandexPUA.Eorezo!RE/E2mqqm7g
MAXmalware (ai score=61)
FortinetRiskware/EoRezo
AVGNSIS:Adware-ADQ [PUP]
PandaTrj/CI.A
Qihoo-360Win32/Virus.Adware.948

How to remove Adware.EoRezo.Gen?

Adware.EoRezo.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment