Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

1, 0, 0, 123 46.67%
1, 0, 0, 98 6.67%
1, 0, 0, 98 6.67%
1, 0, 0, 91 20.00%
1, 0, 0, 40 20.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegEnumKeyExW, GetTokenInformation, AllocateAndInitializeSid, EqualSid, FreeSid, RegOpenKeyExW, RegCreateKeyExW, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, OpenProcessToken, LookupAccountSidW, ConvertSidToStringSidW
comctl32.dll
InitCommonControlsEx
gdi32.dll
DeleteObject, SelectObject, DeleteDC, CreateCompatibleBitmap, CreateCompatibleDC, GetStockObject, BitBlt, GetDeviceCaps, CreateSolidBrush, GetObjectW
kernel32.dll
DllMain
ole32.dll
CoCreateGuid, StringFromCLSID, CoInitialize, CoUninitialize, OleUninitialize, OleInitialize, CreateStreamOnHGlobal, CLSIDFromString, CLSIDFromProgID, CoGetClassObject, OleLockRunning, StringFromGUID2, CoTaskMemFree, CoCreateInstance, CoTaskMemRealloc, CoTaskMemAlloc
shell32.dll
CommandLineToArgvW, SHGetSpecialFolderPathW, ShellExecuteExW, SHGetFolderPathW
urlmon.dll
CoInternetParseUrl
user32.dll
SetWindowLongW, SetCapture, RedrawWindow, GetDesktopWindow, GetWindowLongW, DefWindowProcW, CharNextW, GetSysColor, MoveWindow, SetWindowPos, wsprintfW, LoadStringA, GetClientRect, ClientToScreen, ScreenToClient, GetDC, ReleaseDC, InvalidateRect, UnregisterClassA, MessageBoxW, RegisterWindowMessageW, GetWindowTextLengthW, GetWindowTextW, SetWindowTextW, CreateAcceleratorTableW, CreateWindowExW, RegisterClassExW, LoadCursorW, GetClassInfoExW, IsWindow, SendMessageW, SetFocus, GetFocus, GetWindow, DestroyAcceleratorTable, IsChild, BeginPaint, EndPaint, CallWindowProcW, DestroyWindow, FillRect, ReleaseCapture, GetClassNameW, GetDlgItem, GetParent, InvalidateRgn, LoadStringW
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
ws2_32.dll
getaddrinfo, WSASocketW, WSASend, WSARecv, freeaddrinfo
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSFreeMemory

MailRuUpdater.exe

MailRuUpdater by LLC Mail.Ru (Signed)

Remove MailRuUpdater.exe
Version:   1, 0, 0, 98
MD5:   9538eb8399520c837df7725c62d22b6a
SHA1:   abea7476131dd91617f6c5c2d0c0fa7650559ce8
SHA256:   2396b79a1e056a38caf4af586cbcf2c7ec398f5d51ccd47b2b09fdaf29e9d098

What is MailRuUpdater.exe?

Mail.Ru updater is the software updater program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found. The updater will check for updates remotely and install them based on an internal schedule.

Overview

mailruupdater.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). The file is digitally signed by LLC Mail.Ru which was issued by the Thawte certificate authority (CA). Note, some antivirus scanners have flagged this file, however it is not necessarily considered malware (see below for details).

DetailsDetails

File name:mailruupdater.exe
Publisher:Mail.Ru
Product name:MailRuUpdater
Description:Mail.Ru updater
Typical file path:C:\users\user\appdata\local\mail.ru\mailruupdater.exe
File version:1, 0, 0, 98
Size:1.53 MB (1,608,736 bytes)
Build date:6/8/2013 2:42 PM
Certificate
Issued to:LLC Mail.Ru
Authority (CA):Thawte
Effective date:Monday, September 12, 2011
Expiration date:Wednesday, July 2, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'MailRuUpdater' → C:\users\user\appdata\Local\Mail.Ru\MailRuUpdater.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00015089%
0.028634%
Kernel CPU:0.00006401%
0.013761%
User CPU:0.00008688%
0.014873%
Kernel CPU time:43,056,276 ms/min
100,923,805ms/min
Context switches:1/sec
284/sec
Memory
Private memory:3.87 MB
21.59 MB
Private (maximum):8.03 MB
Private (minimum):4 MB
Non-paged memory:3.87 MB
21.59 MB
Virtual memory:67.19 MB
140.96 MB
Virtual memory (peak):70.5 MB
169.69 MB
Working set:5 MB
18.61 MB
Working set (peak):8.42 MB
37.95 MB
Resource allocations
Threads:8
12
Handles:112
600
GUI GDI count:9
103
GUI GDI peak:9
142
GUI USER count:2
49
GUI USER peak:2
71

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command line:"C:\users\user\appdata\local\mail.ru\mailruupdater.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 40.00%
Microsoft Windows XP 33.33%
Windows 7 Home Basic 20.00%
Windows 7 Home Premium 6.67%

Distribution by countryDistribution by country

UA installs about 46.67% of MailRuUpdater.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 50.00%
ASUS 37.50%
Hewlett-Packard 6.25%
Acer 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE