NVC.exe

Nortel VPN Client

Nortel Networks

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NVC’. This is installed with Penn Medicine VPN Client.
Publisher:
Nortel Networks  (signed and verified)

Product:
Nortel VPN Client

Description:
Nvc.exe

Version:
10.01.103.0

MD5:
18aac6caeff44ad341c2c85208d303eb

SHA-1:
620f4b9a68761fffca1e8f2f6ab8cc368d4dbf7c

SHA-256:
5b80dd54e280fb6f02334956cda0480c074b1a3349fda668bc19a43684a02d0f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:59:35 AM UTC  (today)

File size:
1.7 MB (1,762,640 bytes)

Product version:
10.01.103.0

Copyright:
Copyright © 2008 Nortel Networks

Original file name:
NVC.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\xerox extranet access network\nvc.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/10/2009 2:00:00 AM

Valid to:
7/13/2010 1:59:59 AM

Subject:
CN=Nortel Networks, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Nortel Networks, L=Billerica, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0ED519DC5208A38ABBC13BEDF8F30B6D

File PE Metadata
Compilation timestamp:
8/6/2009 1:33:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:/kUxkUYkUCkUhkUMkU0kU4kUjkU/kUBkU+kUIkU/kUmkUJUWkU2E:/kUxkUYkUCkUhkUMkU0kU4kUjkU/kUB8

Entry address:
0x19ED2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.8776

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.6 MB (1,691,648 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NVC

Command:
"C:\Program Files\xerox extranet access network\nvc.exe" -autostart


The file NVC.exe has been discovered within the following program.

Penn Medicine VPN Client  by Nortel Networks
www.nortel.com
About 8% of users remove it
 
Powered by Should I Remove It?

Scan NVC.exe - Powered by Reason Core Security