Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

11c47 12.50%
96077 12.50%
ddb10 12.50%
46564 12.50%
ac0d8 12.50%
1e462 12.50%
eb51c 12.50%
2923d 12.50%
(Note, LLC Mail.Ru publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryInfoKeyW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegEnumKeyExW
gdi32.dll
GetTextExtentPoint32W, SetTextColor, CreateSolidBrush, SetBkMode, TextOutW, DeleteObject, GetDeviceCaps
kernel32.dll
GetModuleHandleW, DisableThreadLibraryCalls, GetVersionExW, FreeLibrary, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, LockResource, FindResourceExW, CompareStringW, WideCharToMultiByte, FlushFileBuffers, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetProcAddress, ReadFile, SetEndOfFile, SetStdHandle, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, GetConsoleMode, GetConsoleCP, SetFilePointer, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, InterlockedDecrement, InterlockedIncrement, GetModuleFileNameW, lstrcmpiW, GetLastError, DeleteCriticalSection, lstrlenW, RaiseException, GetFileAttributesW, OpenFileMappingW, MapViewOfFile, CloseHandle, UnmapViewOfFile, GetSystemDefaultLCID, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, SetHandleCount, CreateFileW, CreateFileA, GetFileType, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, IsValidCodePage, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, RtlUnwind, GetCurrentThreadId, GetCommandLineA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, VirtualFree, VirtualAlloc, HeapCreate, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, GetCPInfo, GetACP, GetOEMCP
ole32.dll
CoTaskMemRealloc, CoTaskMemFree, CoCreateInstance, StringFromGUID2, CoTaskMemAlloc, ReleaseStgMedium
shell32.dll
DragQueryFileW
user32.dll
GetMenuItemInfoW, GetMenuItemCount, InsertMenuItemW, GetClassNameW, SendMessageW, DestroyMenu, RegisterWindowMessageW, CharNextW, GetDesktopWindow, GetDC, ReleaseDC, GetMenuState, GetSysColor, FillRect, DrawIconEx, LoadIconW, DestroyIcon, GetKeyState, PostMessageW, EnumWindows, LoadImageW, CreatePopupMenu
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

mramenu.dll

By LLC Mail.Ru (Signed)

Remove mramenu.dll
MD5:   2923de6bc08125fac9cc835a4bbd2d35
SHA1:   254cff1b001e199e88ef5420d5f26071253d8d63

Overview

mramenu.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by LLC Mail.Ru which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:mramenu.dll
Typical file path:C:\users\user\appdata\roaming\mail.ru\agent\mra\dll\mramenu.dll
Size:300.53 KB (307,744 bytes)
Build date:10/17/2013 9:37 PM
Certificate
Issued to:LLC Mail.Ru
Authority (CA):Thawte
Effective date:Monday, September 12, 2011
Expiration date:Wednesday, July 2, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Context menu handler
Located in '*\shellex\ContextMenuHandlers'
  • Name: 'MRACMenu'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 75.00%
Windows 7 Home Basic 12.50%
Windows 8 Pro 12.50%

Distribution by countryDistribution by country

Kazakstan installs about 37.50% of mramenu.dll.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
American Megatrends 66.67%
Samsung 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE