How to remove mailruupdater.exe
- File Details
- Overview
- Analysis
mailruupdater.exe
The module mailruupdater.exe has been detected as PUP.MailRu
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
b004ff361b22d4dd4734c6acee088356 |
| Size: |
3 MB |
| First Published: |
2017-07-05 20:03:50 (8 years ago) |
| Latest Published: |
2022-11-24 23:52:56 (3 years ago) |
| Status: |
PUP.MailRu (on last analysis) |
|
| Analysis Date: |
2022-11-24 23:52:56 (3 years ago) |
Overview
| %localappdata%\mail.ru |
| %programfiles%\mail.ru\mailruupdater |
| %localappdata%\temp |
| %profile%\dmin.microsof-bb6828.000\local settings\application data\mail.ru |
| %sysdrive%\adwcleaner\quarantine\files\geffpjqbqbcgjmuiqvckkutkujymxouk\mailruupdater |
| %commonappdata%\чистилка\quarantine\2017-07-20-19-00-04\mail.ru updater.zip\c:\program files (x86)\mail.ru\mailruupdater |
| %profile%\dmin\local settings\application data\mail.ru |
| %profile%\dministrator\local settings\application data\mail.ru |
| %profile%\гор 21\local settings\application data\mail.ru |
| %windir%\temp |
| MailRuUpdater.exe |
| mailruupdater.exe |
| mrutmp.exe |
| A0005036.exe |
| A0005035.exe |
|
68.3% |
|
|
12.1% |
|
|
4.9% |
|
|
1.8% |
|
|
1.8% |
|
|
1.8% |
|
|
1.3% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
| Windows 7 |
46.9% |
|
| Windows 10 |
24.1% |
|
| Windows XP |
13.8% |
|
| Windows 8.1 |
12.1% |
|
| Windows Vista |
2.2% |
|
| Windows 8 |
0.9% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x001612c6 |
| Name |
Size of data |
MD5 |
| .text |
3202048 |
97286bb49e7b62558d376d241b8c4782 |
| .rdata |
609792 |
e8d1f3d1b9567e8b3129a8564bb4f659 |
| .data |
69632 |
6fd612ae1eca37c8f664b0733bbd6cff |
| .tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
| .rsrc |
59392 |
30b11d5bce8ff3e67cee6b0e36591969 |
| .reloc |
137728 |
0f6c587dd1532a82f7b42114dbd2bc46 |