NWTray.exe

Novell Client for Windows

Novell, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NWTRAY’.
Publisher:
Novell, Inc.  (signed and verified)

Product:
Novell® Client(TM) for Windows®

Description:
Novell Client System Tray Menu

Version:
5.0.31.1799

MD5:
cc8724b11d9c8a0f1d706c67dca47dee

SHA-1:
15f83db9e0b32fb78a34a50fde74955f0adf7397

SHA-256:
4b537da3044e86facf56d9fc4775c4ae152e67538688dd027d5c9c6112b4559f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/25/2024 2:52:09 AM UTC  (today)

File size:
31 KB (31,768 bytes)

Product version:
2 SP1

Copyright:
© 2009 Novell, Inc. All rights reserved.

Original file name:
NWTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\nwtray.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/4/2007 5:30:00 AM

Valid to:
4/28/2010 5:29:59 AM

Subject:
CN="Novell, Inc.", OU=Novell Products Group, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Novell, Inc.", L=Provo, S=Utah, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4808D93B14B8600DBFA18DAB5D15310F

File PE Metadata
Compilation timestamp:
12/18/2009 8:54:48 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x2522

Entry point:
E8, AD, 03, 00, 00, E9, 35, FD, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 38, 44, 40, 00, 89, 0D, 34, 44, 40, 00, 89, 15, 30, 44, 40, 00, 89, 1D, 2C, 44, 40, 00, 89, 35, 28, 44, 40, 00, 89, 3D, 24, 44, 40, 00, 66, 8C, 15, 50, 44, 40, 00, 66, 8C, 0D, 44, 44, 40, 00, 66, 8C, 1D, 20, 44, 40, 00, 66, 8C, 05, 1C, 44, 40, 00, 66, 8C, 25, 18, 44, 40, 00, 66, 8C, 2D, 14, 44, 40, 00, 9C, 8F, 05, 48, 44, 40, 00, 8B, 45, 00, A3, 3C, 44, 40, 00, 8B, 45, 04, A3, 40, 44, 40, 00, 8D, 45, 08, A3, 4C, 44, 40, 00, 8B...
 
[+]

Entropy:
5.7510

Code size:
6.5 KB (6,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NWTRAY

Command:
nwtray.exe


Scan NWTray.exe - Powered by Reason Core Security