Adware

Adware.Eorezo.TE (B) removal tips

Malware Removal

The Adware.Eorezo.TE (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Eorezo.TE (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Adware.Eorezo.TE (B)?


File Info:

name: E9030B2983FB33D915B7.mlw
path: /opt/CAPEv2/storage/binaries/a54bc2e2f96ebf27a38580751e17bb4f3a4e5fa45d7379026b667a35aa31b9f2
crc32: B185DDAD
md5: e9030b2983fb33d915b7308962ea7c64
sha1: 44db13ef7abd11aad320a3057a12e01e30a4ad9c
sha256: a54bc2e2f96ebf27a38580751e17bb4f3a4e5fa45d7379026b667a35aa31b9f2
sha512: 8c2ef3b190d80a1b57114c892724509fe8aa7d4dcaadc5a0c3d8babb13b89d1a5837ef09b71fb99ee02d353a0b26b4126d4b839517d9d8a72943a93ce45a1f1a
ssdeep: 24576:Kd+v45tpQac0ZO3E0x1wEL56rKt/7TF2Ps0AnaNWA38izMSlthTlG/3U03IauIcr:QFQaVox3N6rK9XMAng3jl73eJWObi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108A523118F666EEAC7584636307F5F1A0BF19E81041DE96B7AE069C62B8FB01930791F
sha3_384: 18f79ba7936ba7b48f4808a0b4976902dc6562bb9390baedb2e3f2f6dfa9895acfeb4b9b6f6f969c6723ec966b15a363
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-10-09 11:45:59

Version Info:

Translation: 0x0000 0x04b0
Comments: WONX
CompanyName: WONX3P
FileDescription: WONX3P
FileVersion: 3.7.0.2
InternalName: SystemWork.exe
LegalCopyright: Copyright © 5080
LegalTrademarks:
OriginalFilename: SystemWork.exe
ProductName: WONX3P6V
ProductVersion: 3.7.0.2
Assembly Version: 8.5.4.2

Adware.Eorezo.TE (B) also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebAdware.WizzMonetize.1
MicroWorld-eScanAdware.Eorezo.TE
FireEyeGeneric.mg.e9030b2983fb33d9
McAfeeAdware-HUpdate
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1275927
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005662db1 )
AlibabaTrojan:MSIL/Kryptik.d8399d58
K7GWTrojan ( 005662db1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitAdware.Eorezo.TE
BitDefenderThetaGen:NN.ZemsilF.34084.eo0@a4lZh6d
CyrenW32/S-d20e79d3!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.LGY
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderAdware.Eorezo.TE
NANO-AntivirusTrojan.Win32.EoRezo.etkoxf
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Generic.Airj
Ad-AwareAdware.Eorezo.TE
EmsisoftAdware.Eorezo.TE (B)
ComodoApplicUnwnt@#8i66bf1ctbm4
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosMal/Kryptik-BF
IkarusTrojan.MSIL.Crypt
JiangminTrojan.Generic.blrch
AviraADWARE/EoRezo.Gen7
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataAdware.Eorezo.TE
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/ADM01.Exp
Acronissuspicious
ALYacAdware.Eorezo.TE
MAXmalware (ai score=99)
APEXMalicious
YandexTrojan.Agent!h74TslxDAuM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Kryptik.KZF!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.983fb3
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Adware.Eorezo.TE (B)?

Adware.Eorezo.TE (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment