NEJPQLUZ.EXE

Launcher

Fuji Xerox Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NEJPQLU’.
Publisher:
Fuji Xerox Co., Ltd.  (signed and verified)

Product:
Launcher

Description:
Launcher for x64

Version:
1,000,907,16

MD5:
59b51a1c3b488be4a7ddd4fcd174be9f

SHA-1:
ce3ae522102eeb60b934c88b1e6ea45d52e69cfd

SHA-256:
d63ebcbc4961b35ac7c947f844761f20879cc2f5bdc265612eb68513c1694682

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:03:28 AM UTC  (today)

File size:
1.1 MB (1,194,912 bytes)

Product version:
1,000,000,00

Copyright:
(C) Fuji Xerox Co., Ltd. 2008-2009

Original file name:
NEJPQLUZ.EXE

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\nec printers\printer software\nejpqluz.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/23/2009 9:00:00 AM

Valid to:
7/24/2010 8:59:59 AM

Subject:
CN="Fuji Xerox Co., Ltd.", OU=Controller Development Group Controller Platform Development III, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Fuji Xerox Co., Ltd.", L="Akasaka 9-7-3, Minato-ku", S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A8749C432E17D75B36F559E0043058A

File PE Metadata
Compilation timestamp:
7/16/2009 3:46:04 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:8RvXdylT33vyGJLmVVYHBiiQ/4thqwt+a3GkBz80PdRNeNJ:8RlJ0BZQ/4tQwt3GkBz80LSJ

Entry address:
0x34C80

Entry point:
48, 83, EC, 28, E8, 17, 61, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 3B, 0D, D9, 52, 03, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, A1, 61, 00, 00, CC, 48, 83, EC, 68, 48, 85, C9, 75, 2B, E8, 22, 31, 00, 00, 45, 33, C9, 45, 33, C0, C7, 00, 16, 00, 00, 00, 33, C0, 33, D2, 33, C9, 48, 89, 44, 24, 20, E8, E6, 16, 00, 00, B8, FF, FF, FF, FF, 48...
 
[+]

Entropy:
5.7370

Code size:
311 KB (318,464 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NEJPQLU

Command:
"C:\Program Files\nec printers\printer software\nejpqluz.exe" \s