bunez4tray.exe

Backup Now EZ

NTI Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BackupNowEZ4Tray’. This is installed with NTI Backup Now EZ 4.
Publisher:
NTI Corporation  (signed and verified)

Product:
Backup Now EZ

Description:
NTI Backup Now EZ

Version:
4.0.0.67

MD5:
339bdee71c9037eab3ed1b039098288c

SHA-1:
5858dbf08125982a5011b29b5173846bc71c0d9f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 4:44:15 AM UTC  (today)

File size:
1 MB (1,089,224 bytes)

Product version:
4.0.0.67

Copyright:
Copyright (c) 2011-2015, NTI Corporation. All rights reserved.

Original file name:
BackupNowEZtray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\nti\nti backup now ez 4\bunez4tray.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/27/2014 7:00:00 PM

Valid to:
8/27/2015 6:59:59 PM

Subject:
CN=NTI Corporation, O=NTI Corporation, L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0B15F04909D53B077C949035F35A032D

File PE Metadata
Compilation timestamp:
8/3/2015 4:33:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x1D0BA

Entry point:
E8, 9A, 04, 00, 00, E9, 6B, FD, FF, FF, 3B, 0D, 28, C0, 42, 00, 75, 02, F3, C3, E9, 21, 05, 00, 00, CC, FF, 25, 54, 12, 42, 00, 8B, FF, 55, 8B, EC, F6, 45, 08, 02, 57, 8B, F9, 74, 25, 56, 68, 2A, D7, 41, 00, 8D, 77, FC, FF, 36, 6A, 0C, 57, E8, 47, 01, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 35, F9, FF, FF, 59, 8B, C6, 5E, EB, 14, E8, 18, 06, 00, 00, F6, 45, 08, 01, 74, 07, 57, E8, 1E, F9, FF, FF, 59, 8B, C7, 5F, 5D, C2, 04, 00, FF, 25, 68, 12, 42, 00, 6A, 14, 68, B8, 7C, 42, 00, E8, 78, 03, 00, 00, FF, 35...
 
[+]

Entropy:
6.3628

Code size:
126 KB (129,024 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BackupNowEZ4Tray

Command:
"C:\Program Files\nti\nti backup now ez 4\bunez4tray.exe" -k


The file bunez4tray.exe has been discovered within the following program.

NTI Backup Now EZ 4  by NTI Corporation
www.nticorp.com
About 3% of users remove it
 
Powered by Should I Remove It?

Scan bunez4tray.exe - Powered by Reason Core Security