Dmitry Sokolov recommends UnHackMe!
UnHackMe is a powerful tool against malware.UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!
Win32.Application.Agent.45TLXO also known as Win32:Eorezo-F [PUP], Adware.Eorezo.a (v), Adware:Win32/EoRezo.
Malware Analysis of Win32.Application.Agent.45TLXO – EOREZOTOOLS_21.DLL
Created files:
%Program Files%\EoRezo\EoRezoTools_18.dll
%Program Files%\EoRezo\EoRezoTools_20.dll
%Program Files%\EoRezo\EoRezoTools_21.dll
%Program Files%\EoRezo\EoRezoTools_26.dll
%Program Files%\EoRezo\EoRezoTools_27.dll
Autostart registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\EoWeather: “”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\eorezo_fr_4: “”%Program Files%\eorezo_fr_4\eorezo_fr_4.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\EoEngine: “”%Program Files%\EoRezo\EoEngine.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1\DisplayName: “eoEngine 13.1”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1\UninstallString: “”%Program Files%\eoRezo\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eorezo_fr_4_is1\DisplayName: “eorezo_fr_4”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eorezo_fr_4_is1\UninstallString: “”%Program Files%\eorezo_fr_4\unins000.exe””
Detected by UnHackMe:
EOREZOTOOLS_21.DLL
Default location: %PROGRAM FILES%\EOREZO\EOREZOTOOLS_21.DLL
Dropper hash(md5): ed9074a9ac60929e0aaecc69b827a90d
UnHackMe
removes malware invisible for your antivirus!
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.