MailRuUpdater.exe
MailRuUpdater by LLC Mail.Ru (Signed)
Warning 7 antivirus scanners has detected malware in various versions of MailRuUpdater.exe.
Overview
mailruupdater.exe has 5 known versions, the most recent one is 1, 0, 0, 123. mailruupdater.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. The average file size is about 1.5 MB. It is an authenticode code-signed executable issued to LLC Mail.Ru by the certification authority Thawte. During the process's lifecycle, the typical CPU resource utilization is about 0.0010% including both foreground and background operations, the average private memory consumption is about 2.72 MB with the maximum memory reaching around 7.19 MB. Addionally, typically read and write I/O disk operations is about 6 Bytes per minute for reads and 0 Bytes per minute for writes.
What is mailruupdater.exe?
Mail.Ru updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found. The updater will check for updates remotely and install them based on an internal schedule.
Details |
File name: | mailruupdater.exe |
Publisher: | Mail.Ru |
Product name: | MailRuUpdater |
Description: | Mail.Ru updater |
Typical file path: | C:\users\user\appdata\local\mail.ru\mailruupdater.exe |
Certificate |
Issued to: | LLC Mail.Ru |
Authority (CA): | Thawte |
Effective date: | Monday, September 12, 2011 |
Expiration date: | Wednesday, July 2, 2014 |
Behaviors
(Note, the behaviors below are for all versions of mailruupdater.exe, select a unique version for details.)
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'MailRuUpdater' → C:\users\user\appdata\Local\Mail.Ru\MailRuUpdater.exe
Malware detections
Based on 40+ industry antivirus scanners, 7 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
avast! |
8.0.1489.320 |
Win32:Downloader-TPW [PUP] |
1, 0, 0, 91 |
AVG |
2014.0.3629 |
Generic30.COUX |
1, 0, 0, 40 |
Kingsoft |
2013.4.9.267 |
Win32.HeurC.KVM019.a.(kcloud) |
1, 0, 0, 98 |
Rising Antivirus |
24.57.03.04 |
Suspicious |
1, 0, 0, 40 |
Rising Antivirus |
24.68.01.04 |
Suspicious |
1, 0, 0, 91 |
Rising Antivirus |
24.83.01.04 |
Suspicious |
1, 0, 0, 98 |
Rising Antivirus |
24.83.04.04 |
Suspicious |
1, 0, 0, 123 |
All file variations of mailruupdater.exe
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
40.00% |
|
Microsoft Windows XP |
33.33% |
|
Windows 7 Home Basic |
20.00% |
|
Windows 7 Home Premium |
6.67% |
|
Distribution by country
UA installs about 46.67% of MailRuUpdater.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Lenovo |
50.00% |
|
ASUS |
37.50% |
|
Hewlett-Packard |
6.25% |
|
Acer |
6.25% |
|