Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

11c47 12.50%
96077 12.50%
ddb10 12.50%
46564 12.50%
ac0d8 12.50%
1e462 12.50%
eb51c 12.50%
2923d 12.50%
(Note, LLC Mail.Ru publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryInfoKeyW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegEnumKeyExW
gdi32.dll
GetTextExtentPoint32W, SetTextColor, CreateSolidBrush, SetBkMode, TextOutW, DeleteObject, GetDeviceCaps
kernel32.dll
GetModuleHandleW, DisableThreadLibraryCalls, GetVersionExW, FreeLibrary, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, LockResource, FindResourceExW, CompareStringW, WideCharToMultiByte, FlushFileBuffers, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetProcAddress, ReadFile, SetEndOfFile, SetStdHandle, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, GetConsoleMode, GetConsoleCP, SetFilePointer, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, InterlockedDecrement, InterlockedIncrement, GetModuleFileNameW, lstrcmpiW, GetLastError, DeleteCriticalSection, lstrlenW, RaiseException, GetFileAttributesW, OpenFileMappingW, MapViewOfFile, CloseHandle, UnmapViewOfFile, GetSystemDefaultLCID, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, SetHandleCount, CreateFileW, CreateFileA, GetFileType, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, IsValidCodePage, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, RtlUnwind, GetCurrentThreadId, GetCommandLineA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, VirtualFree, VirtualAlloc, HeapCreate, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, GetCPInfo, GetACP, GetOEMCP
ole32.dll
CoTaskMemRealloc, CoTaskMemFree, CoCreateInstance, StringFromGUID2, CoTaskMemAlloc, ReleaseStgMedium
shell32.dll
DragQueryFileW
user32.dll
GetMenuItemInfoW, GetMenuItemCount, InsertMenuItemW, GetClassNameW, SendMessageW, DestroyMenu, RegisterWindowMessageW, CharNextW, GetDesktopWindow, GetDC, ReleaseDC, GetMenuState, GetSysColor, FillRect, DrawIconEx, LoadIconW, DestroyIcon, GetKeyState, PostMessageW, EnumWindows, LoadImageW, CreatePopupMenu
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

mramenu.dll

By LLC Mail.Ru (Signed)

Remove mramenu.dll
MD5:   ac0d8a37e1468b1c8ca4b56ba5ab4936
SHA1:   4ca15c66adcbb57e84456c5f6981b3fd1f7506c6
SHA256:   e554c75fba5e5fb343865c11279df3ea524e284c12d3203844dec85b419b9d4b

Overview

mramenu.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by LLC Mail.Ru which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:mramenu.dll
Typical file path:C:\users\user\appdata\roaming\mail.ru\agent\mra\dll\mramenu.dll
Size:126.69 KB (129,728 bytes)
Certificate
Issued to:LLC Mail.Ru
Authority (CA):Thawte
Effective date:Monday, September 12, 2011
Expiration date:Wednesday, July 2, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Context menu handler
Located in '*\shellex\ContextMenuHandlers'
  • Name: 'MRACMenu'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 75.00%
Windows 7 Home Basic 12.50%
Windows 8 Pro 12.50%

Distribution by countryDistribution by country

Kazakstan installs about 37.50% of mramenu.dll.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
American Megatrends 66.67%
Samsung 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE