PUA

Should I remove “PUP.Optional.EoRezo”?

Malware Removal

The PUP.Optional.EoRezo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.EoRezo virus can do?

  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs

How to determine PUP.Optional.EoRezo?


File Info:

crc32: F5485860
md5: 933dc66d6b4b4a427a964cc8f59a7494
name: 933DC66D6B4B4A427A964CC8F59A7494.mlw
sha1: a24e52409a62f779d930230627f33398d834e45f
sha256: dd79feae2a1a032cae0071fcc834cfb1625792885c18375be6299e2f91ea58e1
sha512: 4bd303726202d0495c7f4a2e20c83c85d922cf29e79b83d3952b839f4fe2093b410ab5024d3cdf9938e60ab10430b06e47aca629e798911a92f38e1a91c1d03b
ssdeep: 24576:DLX4kcZABT1ZVZD+uRBh68dv0Tsw+eZ8igVVe2qqX0/X1JM8jxCoFvLH91DKBuG:DLXdZ3LBDd9aV/x1J5xjoun1Wpl/A
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 8.8.7.6
InternalName: TKO.exe
FileVersion: 8.6.4.8
CompanyName: @GT
LegalTrademarks: @
Comments: @G
ProductName: @GT
ProductVersion: 8.6.4.8
FileDescription:
OriginalFilename: TKO.exe

PUP.Optional.EoRezo also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CAJB
FireEyeGeneric.mg.933dc66d6b4b4a42
Qihoo-360Generic/Trojan.99b
McAfeeGenericRXAM-DQ!933DC66D6B4B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005662db1 )
BitDefenderTrojan.Agent.CAJB
K7GWTrojan ( 005662db1 )
Cybereasonmalicious.d6b4b4
BitDefenderThetaGen:NN.ZemsilF.34804.Zn0@a0hxZek
CyrenW32/S-514471e4!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Eorezo.eiotjw
Ad-AwareTrojan.Agent.CAJB
SophosMal/Kryptik-BF
ComodoTrojWare.MSIL.Injector.QABV@6ljz86
F-SecureTrojan.TR/Dropper.Gen
DrWebAdware.Eorezo.947
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftTrojan.Agent.CAJB (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.amnos
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Dropper]/MSIL.Injector.qab
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Agent.CAJB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.CAJB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Dynamer.R190076
MalwarebytesPUP.Optional.EoRezo
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Injector.QAB
YandexTrojan.Agent!r+keCpICRK8
IkarusTrojan.MSIL.Injector
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Injector.QTZ!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PUP.Optional.EoRezo?

PUP.Optional.EoRezo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment