Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

0.50.0 Unicode 92.31%
0.48.0 Unicode 7.69%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptAcquireContextA, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, CryptReleaseContext, CryptGenRandom, RegCloseKey
comctl32.dll
ImageList_Remove, ImageList_Create, ImageList_DragLeave, ImageList_DragEnter, ImageList_DragShowNolock, ImageList_DragMove, ImageList_EndDrag, ImageList_BeginDrag, ImageList_GetImageCount, CreatePropertySheetPageW, DestroyPropertySheetPage, ImageList_Destroy, ImageList_AddMasked, ImageList_GetIconSize, ImageList_GetIcon, ImageList_SetOverlayImage, ImageList_DrawEx, ImageList_GetImageInfo, ImageList_Draw, ImageList_ReplaceIcon, _TrackMouseEvent, ImageList_Add, ImageList_LoadImageW, PropertySheetW, ImageList_SetBkColor
crypt32.dll
CryptEncryptMessage, CertFreeCertificateContext, CertCloseStore, CertFindCertificateInStore, CertNameToStrW, CertGetNameStringW, CertGetCertificateContextProperty, CertOpenSystemStoreW
gdi32.dll
SetPixelV, SetBoundsRect, GetBitmapDimensionEx, SetBitmapDimensionEx, SetBkMode, CombineRgn, GetWindowOrgEx, GetViewportOrgEx, CreateRectRgn, Escape, RectVisible, PtVisible, GetWindowExtEx, GetViewportExtEx, GetMapMode, GetBkColor, GetBitmapBits, SetBitmapBits, CreateDIBSection, SetDIBColorTable, GdiFlush, CreateRectRgnIndirect, Rectangle, RealizePalette, CreatePalette, Ellipse, LPtoDP, CreateEllipticRgn, GetRgnBox, SelectPalette, CreatePatternBrush, ScaleWindowExtEx, SetWindowExtEx, SetWindowOrgEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectClipRgn, MoveToEx, LineTo, IntersectClipRect, ExcludeClipRect, SetMapMode, SetROP2, SetPolyFillMode, CreatePolygonRgn, FillRgn, OffsetRgn, SetRectRgn, SaveDC, GetClipBox, ExtSelectClipRgn, SetStretchBltMode, SetDIBitsToDevice, RestoreDC, GetDIBits, PatBlt, CreatePen, CreateSolidBrush, Polygon, SetTextAlign, GetTextColor, CreateCompatibleBitmap, GetPixel, SetPixel, CreateCompatibleDC, SelectObject, SetBkColor, BitBlt, SetTextColor, DeleteDC, GetStockObject, DPtoLP, GetDeviceCaps, CreateBitmap, CreateBrushIndirect, DeleteObject
kernel32.dll
HeapDestroy, GetStartupInfoA, SetHandleCount, GetCommandLineW, GetCommandLineA, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetStdHandle, HeapSize, SetStdHandle, CreateThread, ExitThread, VirtualQuery, GetSystemInfo, VirtualAlloc, GetDateFormatA, GetTimeFormatA, PeekNamedPipe, GetFileType, TerminateProcess, GetSystemTimeAsFileTime, HeapReAlloc, RtlUnwind, GlobalFlags, SetErrorMode, VirtualProtect, TlsFree, LocalReAlloc, HeapCreate, VirtualFree, LCMapStringA, IsBadWritePtr, GetOEMCP, GetStringTypeA, GetCurrentDirectoryA, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, HeapAlloc, GetDriveTypeA, SetEnvironmentVariableA, SetFilePointer, GetFileInformationByHandle, InterlockedDecrement, GlobalSize, CreateFileA, InterlockedExchange, GetACP, GetLocaleInfoA, FindClose, GetTimeZoneInformation, MulDiv, GetSystemDirectoryA, GetWindowsDirectoryA, GetModuleFileNameA, GetModuleHandleA, CompareStringA, LocalAlloc, LocalLock, LocalUnlock, SetThreadPriority, FreeResource, WaitForMultipleObjects, ResetEvent, QueryPerformanceFrequency, QueryPerformanceCounter, GetLocalTime, GetOverlappedResult, WriteFile, GetProcessHeap, TlsSetValue, TlsAlloc, TlsGetValue, GlobalHandle, GlobalReAlloc, GetCurrentThread, lstrcmpiA, ConvertDefaultLocale, HeapFree, lstrlenA, IsBadReadPtr, TerminateThread, DeviceIoControl, Beep, SetLastError, IsBadCodePtr, LocalFree, ReadFile, InterlockedIncrement, SetUnhandledExceptionFilter, GetCurrentProcessId, ExitProcess, SetEvent, ResumeThread, WritePrivateProfileStringA, GetPrivateProfileStringA, GetThreadLocale, SetThreadLocale, GlobalAlloc, GlobalFree, SetConsoleCtrlHandler, GlobalLock, GlobalUnlock, GetCurrentProcess, LoadLibraryA, FreeLibrary, RaiseException, GetFileSize, GetTickCount, GetCurrentThreadId, GetLastError, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, WaitForSingleObject, CloseHandle, Sleep, LoadResource, LockResource, SizeofResource, GetVersion, EnumResourceLanguagesW, GlobalDeleteAtom, GetVersionExA, GetFileTime, FileTimeToLocalFileTime, FileTimeToSystemTime, ReleaseMutex, DuplicateHandle, UnlockFile, LockFile, FlushFileBuffers, SuspendThread, lstrcmpA, SetEndOfFile
ole32.dll
CoCreateInstance, CoTaskMemFree, StgOpenStorage, CoTaskMemAlloc, OleSetContainedObject, OleCreateStaticFromData, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, ReleaseStgMedium, OleDuplicateData, CoInitialize, CLSIDFromProgID, CLSIDFromString, OleUninitialize, CoFreeUnusedLibraries, OleInitialize, RegisterDragDrop, CoLockObjectExternal, RevokeDragDrop, OleGetClipboard, CoGetClassObject, StgOpenStorageOnILockBytes, CoRevokeClassObject, OleIsCurrentClipboard, OleFlushClipboard, CoRegisterMessageFilter, CoInitializeSecurity, CoUninitialize, CreateStreamOnHGlobal
shell32.dll
SHGetMalloc, DragFinish, SHAppBarMessage
shlwapi.dll
PathFileExistsW, PathRenameExtensionW, PathRemoveFileSpecW, PathIsRelativeW, PathRemoveExtensionW, PathFindExtensionW, PathFindFileNameW, PathRemoveBackslashW, PathAddBackslashW, PathIsURLW, PathCanonicalizeW, PathBuildRootW, PathStripToRootW, PathStripPathW, PathGetDriveNumberW, PathGetArgsW, PathIsRootW, PathCombineW, PathIsUNCW, UrlUnescapeW, PathMatchSpecW
urlmon.dll
FindMimeFromData
user32.dll
DllMain
wininet.dll
HttpQueryInfoW, InternetCanonicalizeUrlW, InternetReadFile, InternetCloseHandle, InternetErrorDlg, InternetOpenUrlW, InternetWriteFile, InternetSetFilePointer, InternetGetLastResponseInfoW, InternetCrackUrlW, InternetQueryDataAvailable, InternetQueryOptionW, InternetOpenW, InternetSetStatusCallbackW, InternetConnectW, HttpOpenRequestW, HttpAddRequestHeadersW, HttpSendRequestW
winmm.dll
timeGetTime, timeGetDevCaps, timeBeginPeriod, timeEndPeriod
winspool.drv
ClosePrinter

emule.exe

eMule by http://www.emule-project.net

Remove emule.exe
Version:   0.48.0 Unicode
MD5:   1dd562ca4f8978594b0220d98b599977
SHA1:   e034b9b244f8f9647a324b60504cdc8c53f2aebe

Overview

emule.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked.

DetailsDetails

File name:emule.exe
Publisher:http://www.emule-project.net
Product name:eMule
Typical file path:C:\Program Files\emule\emule.exe
File version:0.48.0 Unicode
Size:6.49 MB (6,807,552 bytes)
Build date:6/17/2007 3:02 PM
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'eMuleAutoStart' → C:\Program Files\eMule\emule.exe -AutoStart
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\emule2008\emule.exe'
  • Firewall exception for 'C:\Programas\eMule\emule.exe'
  • Firewall exception for 'C:\Program Files\eMule\emule.exe'
  • Firewall exception for 'C:\Program Files\eMule\emule.exe'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 46.15%
Windows 7 Home Premium 38.46%
Windows 8 7.69%
Windows 7 Ultimate 7.69%

Distribution by countryDistribution by country

United States installs about 30.77% of eMule.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 37.50%
Acer 37.50%
American Megatrends 25.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE