nbSched.exe

NEC Battery Refresh Utility

NEC Personal Computers, Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NECBatt’.
Publisher:
NEC Personal Computers, Ltd.  (signed and verified)

Product:
NEC Battery Refresh Utility

Description:
バッテリ・リフレッシュ&診断ツール - スケジューラ

Version:
2, 2, 9, 16

MD5:
a0c9c08054995b76345daf660411b097

SHA-1:
9e55a4d72762bdf9184f4895fb12f33b513638bd

SHA-256:
f09c8e31c0fc7f0bbf28e948774f1ec6e6d188a4f027950cb29c1fd51d4cc489

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 11:34:57 PM UTC  (a few moments ago)

File size:
374.6 KB (383,576 bytes)

Product version:
2, 2, 9, 16

Copyright:
© 2007 NEC Personal Computers, Ltd. All rights reserved.

Original file name:
nbSched.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\necbatt\nbsched.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/3/2016 9:00:00 AM

Valid to:
6/14/2016 8:59:59 AM

Subject:
CN="NEC Personal Computers, Ltd.", OU=PDD5, O="NEC Personal Computers, Ltd.", L=Chiyoda-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
52C5A4580C03B9F2AC7D61D02D7A65B4

File PE Metadata
Compilation timestamp:
3/24/2016 6:26:12 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:P/1EJzGEQZFxGojFP94xmKzoccqUwTKb1OHXrxHtuafK2f/miQfNLO4b9PMO6tb:P9EJzGEQhPN9ypcqUwTKb1OXrxNvbf/b

Entry address:
0x899C

Entry point:
48, 83, EC, 28, E8, DF, 49, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 60, 4D, 8B, D9, 4D, 8B, D0, 48, 8B, D9, 4D, 85, C0, 75, 28, E8, BF, 13, 00, 00, 48, 83, 64, 24, 20, 00, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, C7, 00, 16, 00, 00, 00, E8, 34, F9, FF, FF, 83, C8, FF, E9, 9E, 00, 00, 00, 48, 85, D2, 74, 05, 48, 85, C9, 74, CE, C7, 44, 24, 48, 42, 00, 00, 00, 48, 89, 4C, 24, 40, 48, 89, 4C, 24, 30, 48, 81, FA, FF, FF, FF, 3F, 76, 0A, C7, 44, 24, 38, FF, FF, FF...
 
[+]

Entropy:
6.4836

Code size:
179 KB (183,296 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NECBatt

Command:
C:\Program Files\necbatt\nbsched.exe