Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

11c47 12.50%
96077 12.50%
ddb10 12.50%
46564 12.50%
ac0d8 12.50%
1e462 12.50%
eb51c 12.50%
2923d 12.50%
(Note, LLC Mail.Ru publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryInfoKeyW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegEnumKeyExW
gdi32.dll
GetTextExtentPoint32W, SetTextColor, CreateSolidBrush, SetBkMode, TextOutW, DeleteObject, GetDeviceCaps
kernel32.dll
GetModuleHandleW, DisableThreadLibraryCalls, GetVersionExW, FreeLibrary, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, LockResource, FindResourceExW, CompareStringW, WideCharToMultiByte, FlushFileBuffers, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetProcAddress, ReadFile, SetEndOfFile, SetStdHandle, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, GetConsoleMode, GetConsoleCP, SetFilePointer, LoadLibraryA, InitializeCriticalSectionAndSpinCount, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, InterlockedDecrement, InterlockedIncrement, GetModuleFileNameW, lstrcmpiW, GetLastError, DeleteCriticalSection, lstrlenW, RaiseException, GetFileAttributesW, OpenFileMappingW, MapViewOfFile, CloseHandle, UnmapViewOfFile, GetSystemDefaultLCID, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, SetHandleCount, CreateFileW, CreateFileA, GetFileType, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, IsValidCodePage, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, RtlUnwind, GetCurrentThreadId, GetCommandLineA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, VirtualFree, VirtualAlloc, HeapCreate, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, GetCPInfo, GetACP, GetOEMCP
ole32.dll
CoTaskMemRealloc, CoTaskMemFree, CoCreateInstance, StringFromGUID2, CoTaskMemAlloc, ReleaseStgMedium
shell32.dll
DragQueryFileW
user32.dll
GetMenuItemInfoW, GetMenuItemCount, InsertMenuItemW, GetClassNameW, SendMessageW, DestroyMenu, RegisterWindowMessageW, CharNextW, GetDesktopWindow, GetDC, ReleaseDC, GetMenuState, GetSysColor, FillRect, DrawIconEx, LoadIconW, DestroyIcon, GetKeyState, PostMessageW, EnumWindows, LoadImageW, CreatePopupMenu
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

mramenu.dll

By LLC Mail.Ru (Signed)

Remove mramenu.dll
MD5:   ddb103d8599fb33b484f950fcd325a9c
SHA1:   028aeaaec2e4b6fba83d71809eb7feff042e4509
SHA256:   b49b5a67c74079dbffa49446b36156f905ef07c475d828a4177a3efbea7928b2

Overview

mramenu.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by LLC Mail.Ru which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:mramenu.dll
Typical file path:C:\users\user\appdata\roaming\mail.ru\agent\mra\dll\mramenu.dll
Size:127.06 KB (130,112 bytes)
Certificate
Issued to:LLC Mail.Ru
Authority (CA):Thawte
Effective date:Monday, September 12, 2011
Expiration date:Wednesday, July 2, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Context menu handler
Located in '*\shellex\ContextMenuHandlers'
  • Name: 'MRACMenu'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 75.00%
Windows 7 Home Basic 12.50%
Windows 8 Pro 12.50%

Distribution by countryDistribution by country

Kazakstan installs about 37.50% of mramenu.dll.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
American Megatrends 66.67%
Samsung 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE