How to remove mracdrv.sys

mracdrv.sys

The module mracdrv.sys has been detected as PUP.MailRu

mracdrv.sys

mracdrv.sys is a Windows file recorded in the ThreatInfo database. It is associated with Mail.Ru AntiCheat. The reported company name is LLC Mail.Ru. The current detection status is PUP.MailRu, based on the latest analysis from 2021-02-14 04:21:58 (5 years ago).

If mracdrv.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as PUP.MailRu.

Product Name: Mail.Ru AntiCheat
Company Name: LLC Mail.Ru
MD5: 257aeeebe6dd1d555c885ed65687a2bf
Size: 18 MB
First Published: 2020-05-23 10:42:25 (5 years ago)
Latest Published: 2021-02-14 04:21:58 (5 years ago)
Status: PUP.MailRu (on last analysis)
Analysis Date: 2021-02-14 04:21:58 (5 years ago)

The signature on mracdrv.sys is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%system%
%system%
%system%
%system%
%system%
%system%
%system%
%system%
%system%
%system%

ThreatInfo has observed mracdrv.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

32.3%
19.4%
6.5%
6.5%
6.5%
6.5%
6.5%
3.2%
3.2%
3.2%
3.2%
3.2%

The strongest geographic signal for this file is Russian Federation with 32.3% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 87.5%
Windows 7 9.4%
Windows 8.1 3.1%

The most common operating system signal for mracdrv.sys is Windows 10 with 87.5% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

mracdrv.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000ae006

PE Sections:

Name Size of data MD5
.text 277504 862f577715e354ba5976001f8a602e4e
TEXT3_B 512 8dc38405eaef18847b83e04b52feb54e
.sflb1 356352 bdfa486e50841279e1510a077de88f9e
.oxye 1024 0095a11fe731755d122efe30e6af5afa
.rdata 8704 57b44ba7c97771a8c4555f501613aa03
.data 4096 f753f66db5ec5c1d1424f54d3fcaee70
.pdata 5120 9a2b1cbf970d606fb2db7692308d0f74
.gfids 512 1cf2856b26691be80e10679aee1138e4
.edata 512 eb5b5d690437730ee273af73cd944323
INIT 4608 709423fa6489b8f021899588ad3edd0b
.rsrc 1536 62e1b0210f3ee5d448312d9c6a0f3264
.reloc 512 04f41890d840d003f89b666dad0e656c
.grcode 65536 94c2a1dfcaf871ddff4a66a1df5b09ec
.sfcode 18665472 8166f1c93e28f5a746ccc7b79f7c49ef
.sfdata 16896 6d65d5043ce4db832c6ea340f557c926
.grdata 7168 08a89c3b5957f7913d04a82c51799b58

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for mracdrv.sys