How to remove A0037812.dll
- File Details
- Overview
- Analysis
A0037812.dll
The module A0037812.dll has been detected as Adware.Downloader
File Details
Product Name: |
|
Company Name: |
|
MD5: |
a49d3128555a7368bbe316c7a8002b2f |
Size: |
1 MB |
First Published: |
2017-05-25 09:04:35 (7 years ago) |
Latest Published: |
2019-06-23 20:47:00 (5 years ago) |
Status: |
Adware.Downloader (on last analysis) |
|
Analysis Date: |
2019-06-23 20:47:00 (5 years ago) |
Overview
%localappdata%\catalinagroup\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_0\binaries\win |
%profile%\bd\local settings\application data\catalinagroup\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_0\binaries\win |
%sysdrive%\$recycle.bin\s-1-5-21-765936078-3930851037-2199667764-1000\$rgd8ruq\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_0\binaries\win |
%profile%\annan6\local settings\application data\catalinagroup\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_0\binaries\win |
%sysdrive%\system volume information\_restore{707e28ae-030b-44df-b89d-07076ebdcb41}\rp269 |
%localappdata%\catalinagroup\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_0\binaries |
%sysdrive%\system volume information\_restore{c52b72cc-fd71-4681-b415-f03a3112c2d4} |
%localappdata%\catalinagroup\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_1\binaries |
%profile%\enatual\local settings\application data\catalinagroup\citrio\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_1\binaries |
%profile%\明正\my documents\downloads\瀏覽器\citrio browser 香吉士瀏覽器 47.0.2526.268 免安裝中文版 - 支援bt下載的類chrome瀏覽器\user data\default\extensions\kffhmkdleanehaigkpknpdolaokhflpn\0.5.6_0\binaries |
AdSafeBrowsing.dll |
A0037812.dll |
A0456837.dll |
|
30.3% |
|
|
6.7% |
|
|
6.7% |
|
|
5.0% |
|
|
5.0% |
|
|
4.2% |
|
|
4.2% |
|
|
4.2% |
|
|
3.4% |
|
|
2.5% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
Windows 10 |
35.0% |
|
Windows 7 |
33.3% |
|
Windows 8.1 |
20.0% |
|
Windows XP |
11.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x00082399 |
Name |
Size of data |
MD5 |
.text |
706560 |
27dc0c6c27f8d670147aa56fc195ee29 |
.rdata |
263680 |
9c3ae6af31332790ae0e63cf6242f299 |
.data |
75264 |
6f58a75141fa5f3d7d9a087609b2f98a |
.tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.rsrc |
8704 |
b0e6370791f38333080748af919b34c5 |
.reloc |
52224 |
e89e2c63444cdb4e5f6440d24035b2e6 |