How to remove A0037472.dll

A0037472.dll

The module A0037472.dll has been detected as Adware.Downloader

A0037472.dll
MD5: c32356ea507ac49133eab298f63ced6d
Size: 105 KB
First Published: 2017-05-25 09:04:30 (8 years ago)
Latest Published: 2025-03-30 23:01:40 (3 months ago)
Status: Adware.Downloader (on last analysis)
Analysis Date: 2025-03-30 23:01:40 (3 months ago)
Signed By: Catalina Group Limited
Status: Valid
%localappdata%\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries\win
%profile%\bd\local settings\application data\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries\win
%profile%\ser\local settings\application data\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries\win
%profile%\annan6\local settings\application data\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries\win
%sysdrive%\system volume information\_restore{707e28ae-030b-44df-b89d-07076ebdcb41}\rp269
%localappdata%\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries
%sysdrive%\system volume information\_restore{c52b72cc-fd71-4681-b415-f03a3112c2d4}
%profile%\enatual\local settings\application data\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries
%profile%\dministrador\configuración local\datos de programa\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_0\binaries
%localappdata%\catalinagroup\citrio\user data\default\extensions\dcagnhpbnggmbihndfkkhfjojgbaaedo\1.2.40_1\binaries
pywintypes34.dll
A0037472.dll
A0456497.dll
26.3%
8.0%
5.1%
5.1%
4.4%
4.4%
4.4%
3.6%
2.9%
2.9%
2.2%
2.2%
1.5%
1.5%
1.5%
1.5%
1.5%
1.5%
1.5%
1.5%
1.5%
1.5%
1.5%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
Windows 10 42.4%
Windows 7 33.8%
Windows 8.1 17.3%
Windows XP 5.8%
Windows 8 0.7%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x1e7a0000
Entry Address: 0x0000b55d

PE Sections:

Name Size of data MD5
.text 45056 2583db7e84b7741bc0f43e02953bcc20
.rdata 47104 4c40d64e01b351f68aa2fdab2f8a9f97
.data 6144 9e7ec68c59cf7debd0e656aa1547110f
.reloc 5632 d4726e50c798326da22ef56f0918246d

More information:

Download GridinSoft Anti-Malware - Removal tool for A0037472.dll