Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, CryptDecrypt, CryptCreateHash, CryptSetHashParam, CryptSignHashA, CryptDestroyHash, CryptExportKey, CryptGetUserKey, CryptGetProvParam, CryptDestroyKey, CryptEnumProvidersA, CryptAcquireContextA, CryptGenRandom, CryptReleaseContext, ReportEventW, RegisterEventSourceW, ReportEventA, RegCloseKey, RegQueryValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegEnumValueW, GetUserNameW, RegDeleteKeyW, DeregisterEventSource, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegDeleteValueW, RegCreateKeyExW, RegisterEventSourceA
comctl32.dll
ImageList_Destroy, ImageList_Draw, InitCommonControlsEx, ImageList_LoadImageW, _TrackMouseEvent, DestroyPropertySheetPage, ImageList_Create, ImageList_ReplaceIcon, ImageList_AddMasked, ImageList_Remove, CreatePropertySheetPageW, PropertySheetW, ImageList_GetIconSize
crypt32.dll
CertEnumCertificatesInStore, CertDuplicateCertificateContext, CertCloseStore, CertFreeCertificateContext, CertFindCertificateInStore, CertOpenStore, CertGetCertificateContextProperty
gdi32.dll
CreateDIBSection, CreateBitmap, PatBlt, CreatePen, LineTo, MoveToEx, GetOutlineTextMetricsW, SetTextAlign, TextOutW, CreateRectRgnIndirect, ExcludeClipRect, CreateRectRgn, CombineRgn, FillRgn, GetObjectA, CreateDCA, StretchBlt, SetStretchBltMode, GetTextExtentPoint32W, SetViewportOrgEx, CreatePatternBrush, CreateSolidBrush, SetBkColor, ExtTextOutW, BitBlt, SetTextColor, SetBkMode, CreateCompatibleBitmap, GetStockObject, DeleteDC, GetObjectW, GetDeviceCaps, DeleteObject, SelectObject, CreateCompatibleDC, CreateFontIndirectW, GetBitmapBits
gdiplus.dll
GdipDeleteBrush, GdipGetPropertyItem, GdipGetPropertyItemSize, GdipCloneBrush, GdipDrawImageI, GdipImageGetFrameCount, GdipImageGetFrameDimensionsList, GdipLoadImageFromFile, GdipLoadImageFromFileICM, GdipCreatePen1, GdipAlloc, GdipDeletePen, GdipCreateLineBrushFromRectI, GdipDrawRectangleI, GdipFillRectangleI, GdipImageGetFrameDimensionsCount, GdipGetImagePixelFormat, GdiplusStartup, GdiplusShutdown, GdipCloneImage, GdipDrawImageRectI, GdipCreateFromHDC, GdipGetImageHeight, GdipGetImageWidth, GdipDisposeImage, GdipFree, GdipLoadImageFromStreamICM, GdipLoadImageFromStream, GdipDeleteGraphics, GdipImageSelectActiveFrame, GdipCreateFontFromLogfontA, GdipCreateFontFromDC, GdipDrawString, GdipSetStringFormatTrimming, GdipSetStringFormatLineAlign, GdipSetStringFormatAlign, GdipSetStringFormatFlags, GdipCreateSolidFill, GdipDeleteFont, GdipDeleteStringFormat, GdipCreateStringFormat
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain
msimg32.dll
GradientFill
ole32.dll
CoInitialize, CoUninitialize, FreePropVariantArray, PropVariantClear, CoInitializeEx, ReleaseStgMedium, CoTaskMemRealloc, CoRegisterClassObject, CoRevokeClassObject, CoTaskMemFree, OleUninitialize, OleInitialize, CoTaskMemAlloc, CoCreateInstance, CLSIDFromString, CLSIDFromProgID, CoGetClassObject, OleLockRunning, StringFromGUID2, CreateStreamOnHGlobal
shell32.dll
SHBrowseForFolderW, Shell_NotifyIconW, DragQueryFileW, SHOpenFolderAndSelectItems, SHGetPathFromIDListW, ShellExecuteW, SHGetFolderPathW, SHChangeNotify, SHGetFileInfoW
shlwapi.dll
PathFindFileNameW, PathIsDirectoryW, PathFileExistsW, PathIsDirectoryEmptyW, UrlUnescapeW, SHCreateStreamOnFileW, PathCreateFromUrlW, PathRemoveFileSpecW
user32.dll
SystemParametersInfoW, SetWindowLongW, MessageBoxA, GetProcessWindowStation, GetUserObjectInformationW, CloseClipboard, EmptyClipboard, OpenClipboard, SetClipboardData, CharLowerBuffW, UnregisterClassA, CreateWindowExW, GetWindowLongW, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, SetWindowPos, GetClientRect, UpdateWindow, InvalidateRect, GetDlgItem, IsWindow, LoadBitmapW, LoadStringW, GetParent, DrawTextW, DrawFrameControl, DrawStateW, GetMessagePos, SetForegroundWindow, IsDialogMessageW, GetWindowThreadProcessId, GetActiveWindow, ModifyMenuW, DeleteMenu, CreateMenu, InsertMenuItemW, wsprintfW, GetSubMenu, TrackPopupMenu, PostQuitMessage, MonitorFromPoint, DestroyMenu, SetMenuItemInfoW, GetMenuItemInfoW, GetMenuItemCount, LoadMenuW, SetActiveWindow, FindWindowExW, RegisterClipboardFormatW, PeekMessageW, GetMessageW, TranslateMessage, DispatchMessageW, IsDlgButtonChecked, EqualRect, UnionRect, IsWindowVisible, DialogBoxIndirectParamW, MessageBoxW, BringWindowToTop, GetClassLongW, MapDialogRect, SetWindowContextHelpId, SetLayeredWindowAttributes, RegisterWindowMessageW, UpdateLayeredWindow, CreateAcceleratorTableW, DestroyAcceleratorTable, GetDesktopWindow, RedrawWindow, InvalidateRgn, MoveWindow, CreateDialogParamW, GetNextDlgTabItem, RegisterClassExW, SetRect, DestroyIcon, GetClassInfoExW, IsChild, ShowWindow, CopyRect, InflateRect, DrawEdge, KillTimer, SetTimer, ClientToScreen, EndDialog, LoadImageW, MonitorFromWindow, GetMonitorInfoW, MapWindowPoints, AdjustWindowRectEx, GetMenu, SetDlgItemInt, GetDlgItemInt, EnableWindow, MessageBeep, PostMessageW, SetDlgItemTextW, GetWindowDC, GetSystemMetrics, DrawTextExW, FrameRect, GetSysColorBrush, GetTopWindow, GetWindow, GetWindowRect, DialogBoxParamW, GetClassNameW, LoadCursorW, GetCapture, ReleaseCapture, EndPaint, BeginPaint, GetSysColor, GetFocus, GetCursorPos, SetCursor, DrawFocusRect, PtInRect, FillRect, CallWindowProcW, GetDlgCtrlID, SetFocus, SetCapture, IsWindowEnabled, ScreenToClient, DestroyWindow, OffsetRect, SetRectEmpty, ReleaseDC, GetDC, CharNextW, DefWindowProcW, SendMessageW
uxtheme.dll
CloseThemeData, OpenThemeData, GetThemeInt, GetThemePartSize, SetWindowTheme, DrawThemeBackground
version.dll
VerQueryValueW
wininet.dll
InternetGetCookieA

MegaCloud.exe

MegaCloud by MegaCloud Ltd (Signed)

Remove MegaCloud.exe
Version:   1.0.2.3915
MD5:   b9890b670d1fbe899bb384b592eeecfe
SHA1:   b56d757adb735dca3dab1bdecc9212d8981b279c

Overview

megacloud.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. During installation, it (or a shortcut) is added to the user's startup folder which is designed to automatically launch when the user logs into Windows. This is typically installed with the program MegaCloud published by MegaCloud Ltd.. The file is digitally signed by MegaCloud Ltd which was issued by the COMODO CA Limited certificate authority (CA). This particular version is usually found on Windows 7 Starter (6.1.7601.65536).

DetailsDetails

File name:megacloud.exe
Product name:MegaCloud
Typical file path:C:\users\user\appdata\roaming\megacloud\megacloud.exe
File version:1.0.2.3915
Size:14.61 MB (15,322,880 bytes)
Certificate
Issued to:MegaCloud Ltd
Authority (CA):COMODO CA Limited
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
MegaCloud Ltd.
9% remove

BehaviorsBehaviors

User start menu folder
Shortcut pointer placed in '%appdata%\Microsoft\Windows\Start Menu'
  • Shortcut to 'megacloud.exe'
Network connections
  • [TCP] 216.155.157.44.choopa.net (216.155.157.44:443)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00140688%
    0.028634%
    Kernel CPU:0.00083625%
    0.013761%
    User CPU:0.00057063%
    0.014873%
    Kernel CPU time:149,292,957 ms/min
    100,923,805ms/min
    Memory
    Private memory:39.17 MB
    21.59 MB
    Private (maximum):29.66 MB
    Private (minimum):5.16 MB
    Non-paged memory:39.17 MB
    21.59 MB
    Virtual memory:177.81 MB
    140.96 MB
    Virtual memory (peak):179.25 MB
    169.69 MB
    Working set:8.5 MB
    18.61 MB
    Working set (peak):32.09 MB
    37.95 MB
    Resource allocations
    Threads:31
    12
    Handles:501
    600
    GUI GDI count:180
    103
    GUI GDI peak:184
    142
    GUI USER count:144
    49
    GUI USER peak:145
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:32-bit
    Command line:"C:\users\user\appdata\roaming\megacloud\megacloud.exe" /startup
    Owner:User
    Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Starter 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE