NEGui.EXE

NeExtender GUI client

Dell Software Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SonicWALLNetExtender’. This is installed with Dell SonicWALL NetExtender.
Publisher:
Dell  (signed by Dell Software Inc.)

Product:
NeExtender GUI client

Version:
8, 0, 238, 1

MD5:
e8c771554907f0bc0f955e39003dff15

SHA-1:
d40992ba7b1dd8c3a002e89bea3198c19fe69c6c

SHA-256:
646aa8e9a3bd13bc6cd33f37257c5d3ea3c75d82517e14e483c3a7f8290587d2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:58:58 AM UTC  (today)

File size:
2.4 MB (2,566,288 bytes)

Product version:
8, 0, 238, 1

Copyright:
(C) 2015 Dell

Original file name:
NEGui.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\sonicwall\ssl-vpn\netextender\negui.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
4/14/2015 2:00:00 AM

Valid to:
4/14/2018 1:59:59 AM

Subject:
CN=Dell Software Inc., OU=IS Administration, O=Dell Software Inc., L=Aliso Viejo, S=California, C=US, SERIALNUMBER=4645336, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
44F159BA291DBDFBE929164712BD6681

File PE Metadata
Compilation timestamp:
6/24/2015 7:15:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x70C53

Entry point:
E8, 42, 6F, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 3F, 1A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, C4, 1D, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 2B, 0D, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 9A, 03, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, F0, 19, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD, 6A, 16...
 
[+]

Code size:
596 KB (610,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SonicWALLNetExtender

Command:
"C:\Program Files\sonicwall\ssl-vpn\netextender\negui.exe" -hidegui -clearreboot


The file NEGui.EXE has been discovered within the following program.

Publisher's description - “NetExtender adds more power to the Dell™ SonicWALL™ Secure Remote Access (SRA) 4600 and 1600, adding capabilities such as seamless and secure access to any resource on the corporate network, including servers or custom applications. NetExtender is not a fat client.”
www.sonicwall.com
11% remove it
 
Powered by Should I Remove It?

Scan NEGui.EXE - Powered by Reason Core Security