Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

1.9.0040.0 44.44%
1.9.0040.0 11.11%
1.9.0040.0 22.22%
1.7.0018.5 11.11%
1.5.0540.0 11.11%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegQueryValueExA, RegOpenKeyExA, RegNotifyChangeKeyValue, RegOpenKeyExW, RegEnumKeyW, RegDeleteValueW, RegQueryInfoKeyW, RegEnumValueW, CryptImportKey, RegEnumKeyExW, RegEnumKeyExA, GetCurrentHwProfileA, GetCurrentHwProfileW, RegEnumKeyA, CryptAcquireContextA, CryptCreateHash, CryptHashData, CryptDeriveKey, CryptDecrypt, CryptDestroyKey, CryptDestroyHash, CryptReleaseContext, OpenThreadToken, GetLengthSid, CopySid, LookupAccountNameW, OpenProcessToken, GetTokenInformation, RegCreateKeyExA, RegSetValueExA
comctl32.dll
InitCommonControlsEx
crypt32.dll
CryptProtectData, CryptUnprotectData, CertEnumCertificatesInStore, CertFindExtension, CryptExportPublicKeyInfo, CertVerifySubjectCertificateContext, CertFreeCertificateContext, CertGetIssuerCertificateFromStore, CertDuplicateCertificateContext, CertCreateCertificateContext, CertCloseStore, CertComparePublicKeyInfo, CertOpenStore
gdi32.dll
SelectObject, CreateCompatibleDC, CreateCompatibleBitmap, CreateFontIndirectW, GetObjectW, CreateDIBSection, BitBlt, SetTextColor, DeleteDC, CreateSolidBrush, SetBkMode, GetStockObject, DeleteObject, GetTextExtentExPointW
kernel32.dll
DllMain
ole32.dll
CLSIDFromProgID, CoCreateGuid, StringFromGUID2, CoSetProxyBlanket, CoFreeUnusedLibraries, CoCreateInstance, CoInitializeEx, CoUninitialize, IIDFromString
setupapi.dll
SetupDiGetDeviceRegistryPropertyW, SetupDiDestroyDeviceInfoList, SetupDiCreateDeviceInfoList, SetupDiGetClassDevsW, SetupDiGetClassDevsA, SetupDiGetDeviceRegistryPropertyA, SetupDiEnumDeviceInfo
shell32.dll
Shell_NotifyIconW, ShellExecuteA, ShellExecuteW, SHAppBarMessage
shlwapi.dll
SHDeleteValueW
user32.dll
PostMessageW, GetMenuItemID, DeleteMenu, GetMenuItemCount, CreateWindowExW, SetWindowLongW, LoadImageW, DestroyIcon, LoadStringW, RegisterWindowMessageW, ShowWindow, UpdateWindow, BroadcastSystemMessageA, wsprintfA, SetMenuDefaultItem, SetWindowPos, SetSysColors, SystemParametersInfoW, GetForegroundWindow, CopyRect, OffsetRect, GetDC, UpdateLayeredWindow, ReleaseDC, MapWindowPoints, InflateRect, SetRect, IsWindow, EndPaint, BeginPaint, SendMessageW, DestroyWindow, DrawTextW, GetFocus, DrawFocusRect, DrawIconEx, GetWindowTextLengthW, SetDlgItemTextW, SendDlgItemMessageW, GetClientRect, GetWindowTextW, GetSysColor, SetLayeredWindowAttributes, InvalidateRect, GetWindowRect, GetDlgItem, GetWindowLongW, EndDialog, GetDlgCtrlID, GetMessageW, TranslateMessage, DispatchMessageW, LoadIconW, LoadCursorW, RegisterClassExW, DefWindowProcW, PostQuitMessage, FindWindowW, IsWindowVisible, GetActiveWindow, DialogBoxParamW, CreateDialogParamW, GetDoubleClickTime, SetTimer, LoadMenuW, GetSubMenu, GetCursorPos, SetForegroundWindow, TrackPopupMenu, DestroyMenu, KillTimer, UnregisterClassA, SystemParametersInfoA, GetDesktopWindow, GetWindowLongA, GetParent, GetSystemMetrics, GetMonitorInfoA, GetClassNameW, SetWindowTextW, SendMessageA
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueA
wininet.dll
InternetSetOptionA, InternetOpenA, InternetErrorDlg, InternetAutodial, InternetGetConnectedState, HttpQueryInfoA, HttpSendRequestA, InternetQueryOptionA, HttpOpenRequestA, InternetConnectA, InternetReadFile, InternetCloseHandle

WgaTray.exe

Microsoft Genuine Advantage by Microsoft Corporation (Signed)

Remove WgaTray.exe
Version:   1.9.0040.0
MD5:   b1296d52b0d2096ec4759eeeb806d759
SHA1:   fdd621992e5d6b2b797f4d2371c2706a1e9ba1f5
SHA256:   4f291e1513d5e79bd3ee54e644138468778a80d6c49df01ea93e291897e433b5

Overview

wgatray.exe executes as a process with the local user's privileges. It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Microsoft Corporation.

DetailsDetails

File name:wgatray.exe
Publisher:Microsoft Corporation
Product name:Microsoft Genuine Advantage
Description:Windows Genuine Advantage Notifications
Typical file path:C:\Windows\System32\wgatray.exe
File version:1.9.0040.0
Size:912.88 KB (934,792 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Tuesday, January 20, 2009
Expiration date:Saturday, March 20, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Windows firewall allowed program
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\WgaTray.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.03176288%
0.028634%
Kernel CPU:0.01614062%
0.013761%
User CPU:0.01562226%
0.014873%
Kernel CPU time:146,510 ms/min
100,923,805ms/min
Context switches:210/sec
284/sec
Memory
Private memory:5.24 MB
21.59 MB
Private (maximum):4.94 MB
Private (minimum):198.67 KB
Non-paged memory:5.24 MB
21.59 MB
Virtual memory:63.72 MB
140.96 MB
Virtual memory (peak):65.89 MB
169.69 MB
Working set:1.23 MB
18.61 MB
Working set (peak):12.01 MB
37.95 MB
Page faults:3,048,013/min
2,039/min
I/O
I/O read transfer:543 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:116 Bytes/sec
448.09 KB/min
I/O other operations:2/sec
1,671/min
Resource allocations
Threads:10
12
Handles:317
600
GUI GDI count:50
103
GUI USER count:32
49

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Undefined
Platform:32-bit
Command line:"C:\Windows\System32\wgatray.exe"
Owner:User
Parent process:winlogon.exe (Windows NT Logon Application by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

Indonesia installs about 50.00% of Microsoft Genuine Advantage.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE