Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetSecurityDescriptorDacl, InitializeSecurityDescriptor
comctl32.dll
InitCommonControlsEx, _TrackMouseEvent
gdi32.dll
GetObjectW, DeleteDC, CombineRgn, ExtCreateRegion, CreateDIBSection, GetTextColor, GetBkColor, CreateFontW, GetTextExtentPointA, GetTextMetricsA, GetObjectA, DeleteObject, SelectObject, BitBlt, CreateCompatibleBitmap, CreateCompatibleDC, CreateSolidBrush, CreateFontIndirectW, GetTextExtentPoint32W
gdiplus.dll
GdipReleaseDC, GdipMeasureString, GdipGetFontHeight, GdipSetStringFormatTrimming, GdipCreateFontFamilyFromName, GdipDeleteFontFamily, GdipGetGenericFontFamilySansSerif, GdipCreateFont, GdipDrawImageRectRect, GdipSetImageAttributesColorKeys, GdipBitmapGetPixel, GdipGetImageHeight, GdipGetImageWidth, GdipDisposeImageAttributes, GdipCreateImageAttributes, GdipCreateHBITMAPFromBitmap, GdipDrawString, GdipSetStringFormatLineAlign, GdipSetStringFormatAlign, GdipSetSolidFillColor, GdipDeleteStringFormat, GdipDeleteFont, GdipCreateFontFromLogfontA, GdipCreateFontFromDC, GdipGetDC, GdipLoadImageFromFile, GdipSetLineSigmaBlend, GdipCreateLineBrushFromRect, GdipDeletePen, GdipCreatePen1, GdipDrawRectangle, GdipFillRectangle, GdipCloneBrush, GdipDeleteBrush, GdipCreateSolidFill, GdipSetSmoothingMode, GdiplusShutdown, GdiplusStartup, GdipCreateBitmapFromFile, GdipDrawImageRect, GdipDeleteGraphics, GdipCreateFromHDC, GdipDisposeImage, GdipCloneImage, GdipAlloc, GdipFree, GdipCreateStringFormat
kernel32.dll
OpenEventW, CreateEventW, ReadFile, MultiByteToWideChar, WaitForSingleObject, SetEvent, CreateThread, HeapAlloc, FormatMessageW, HeapFree, ResetEvent, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, SetLastError, GetPrivateProfileStringW, GetSystemTimeAsFileTime, FindClose, CreateSemaphoreW, GetCurrentProcessId, OpenFileMappingW, WaitForMultipleObjects, GetCommandLineW, GetVolumeInformationW, SetFilePointerEx, lstrlenA, SystemTimeToFileTime, FileTimeToSystemTime, GetTickCount, Sleep, FindResourceW, LoadResource, LockResource, GlobalAlloc, GlobalLock, GlobalUnlock, GlobalReAlloc, GlobalFree, GetVersionExW, GetVersion, InterlockedExchange, InterlockedCompareExchange, GetStartupInfoW, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetCurrentThreadId, GetProcessHeap, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, FindNextFileW, FindFirstFileW, lstrlenW, FreeLibrary, GetProcAddress, LoadLibraryW, lstrcpynW, GetModuleFileNameW, GetFileAttributesW, CloseHandle, GetLastError, CreateFileW, DeviceIoControl, GetLogicalDrives, OutputDebugStringW, SetErrorMode, IsDebuggerPresent, WritePrivateProfileStringW, GetDriveTypeW
mfc90u.dll
DllMain
msvcp90.dll
DllMain
msvcr90.dll
DllMain
ole32.dll
CoInitialize, CoUninitialize, CoCreateInstance, CoTaskMemFree
setupapi.dll
SetupDiGetDeviceInterfaceDetailW, CM_Get_Device_IDW, SetupDiDestroyDeviceInfoList, SetupDiGetClassDevsW, SetupDiEnumDeviceInterfaces, CM_Get_Parent
shell32.dll
SHGetSpecialFolderLocation, ShellExecuteExW, Shell_NotifyIconW, ShellExecuteW, SHGetFileInfoW
shlwapi.dll
PathAddBackslashW, PathIsRootW, PathMatchSpecW, PathFileExistsW, PathRemoveFileSpecW, PathIsDirectoryW
sqlite3.dll
sqlite3_prepare16, sqlite3_column_int, sqlite3_errmsg, sqlite3_open16, sqlite3_column_text16, sqlite3_column_int64, sqlite3_finalize, sqlite3_close, sqlite3_step
user32.dll
GetParent, GetAsyncKeyState, GetCursorPos, ScreenToClient, GetFocus, PtInRect, BeginPaint, EndPaint, ClientToScreen, AdjustWindowRectEx, MoveWindow, SetWindowRgn, SetRect, FindWindowW, LoadMenuW, GetSubMenu, InvalidateRect, TrackPopupMenu, GetMenuItemID, GetClassNameW, EnumChildWindows, SetMenuItemInfoW, SetLayeredWindowAttributes, TrackMouseEvent, DrawIcon, GetSystemMetrics, IsIconic, AppendMenuW, GetSystemMenu, RegisterWindowMessageW, CloseWindow, IsWindow, DestroyIcon, SendMessageW, LoadIconW, RegisterClassW, GetClassInfoW, PostMessageW, GetWindow, KillTimer, SetTimer, SetWindowPos, LoadBitmapW, SetForegroundWindow, GetDesktopWindow, GetClientRect, EnableWindow, CopyRect, GetWindowRect, GetWindowLongW, OffsetRect, SetMenuDefaultItem, GetDlgCtrlID

BackupNowEZtray.exe

NTI Backup Now EZ by NewTech Infosystems (Signed)

Remove BackupNowEZtray.exe
Version:   2.0.2.8
MD5:   d0641fc443eb5980aaa0b357e3028a14
SHA1:   b1bc9577a6b790f96ead6545685a96c4c74da817
SHA256:   bd7d41a3ac698e7e6e18a52b0701eab4f384d5c65faa68551e21cf46e0fbbb90

Overview

backupnoweztray.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program NTI Backup Now EZ published by NewTech Infosystems. The file is digitally signed by NewTech Infosystems which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Windows Vista (TM) Home Premium (6.0.6002.131072).

DetailsDetails

File name:backupnoweztray.exe
Publisher:NewTech Infosystems, Inc.
Product name:NTI Backup Now EZ
Typical file path:C:\Program Files\newtech infosystems\backup now ez\backupnoweztray.exe
File version:2.0.2.8
Size:564.25 KB (577,792 bytes)
Certificate
Issued to:NewTech Infosystems
Authority (CA):VeriSign
Effective date:Sunday, October 26, 2008
Expiration date:Wednesday, December 21, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
NewTech Infosystems
2% remove
Backup Now EZ is a complete backup solution for protecting your entire computer. Our File & Folder Backup method will protect your important files and folders and give you quick access to your backed up files if the need arises. With our Complete System Backup method your entire computer will be backed up including the operating system, all programs, all data files, & computer settings. And with our Cloud Backup method all your importan...

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'BackupNowEZtray' → "C:\Program Files\NewTech Infosystems\Backup Now EZ\BackupNowEZtray.exe" -k

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00008232%
0.028634%
Kernel CPU:0.00004525%
0.013761%
User CPU:0.00003706%
0.014873%
Kernel CPU time:515 ms/min
100,923,805ms/min
CPU cycles:167,452/sec
17,470,203/sec
Memory
Private memory:5.54 MB
21.59 MB
Private (maximum):7.14 MB
Private (minimum):6.52 MB
Non-paged memory:5.54 MB
21.59 MB
Virtual memory:93.26 MB
140.96 MB
Virtual memory (peak):93.26 MB
169.69 MB
Working set:6.55 MB
18.61 MB
Working set (peak):8.95 MB
37.95 MB
Page faults:3,836/min
2,039/min
I/O
I/O read transfer:11.9 KB/sec
1.02 MB/min
I/O read operations:19/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:463 Bytes/sec
448.09 KB/min
I/O other operations:49/sec
1,671/min
Resource allocations
Threads:4
12
Handles:128
600
GUI GDI count:46
103
GUI USER count:24
49

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Medium
Platform:32-bit
Command line:"C:\program
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
BackupNowEZtray.exe (main module)
Total CPU:0.00016205%
0.272967%
Kernel CPU:0.00008789%
0.107585%
User CPU:0.00007416%
0.165382%
CPU cycles:166,299/sec
5,741,424/sec
Memory:572 KB
1.16 MB
gdiplus.dll
Total CPU:0.00000275%
Kernel CPU:0.00000275%
User CPU:0.00000000%
CPU cycles:79/sec
Memory:1.67 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Premium 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE