TaskProxy.exe

TaskProxy Application

NEC Personal Computers, Ltd.

It runs as a scheduled task under the Windows Task Scheduler named NECCapsLock triggered to execute each time a user logs in.
Publisher:
NEC Personal Computers, Ltd.   (signed by NEC Personal Computers, Ltd.)

Product:
TaskProxy Application

Version:
1, 0, 1, 6

MD5:
972442f4eec31d1e95e4754abab44328

SHA-1:
687c21f2ab2c359d56f5261c3ab6a196712a77b4

SHA-256:
a8b72fc0e37ad614eca59b73ace11f26a4de0a5ed9cc69e9ff1b092696ca8f99

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/30/2024 3:19:00 PM UTC  (today)

File size:
71.3 KB (73,056 bytes)

Product version:
1, 0, 1, 6

Copyright:
© 2016 NEC Personal Computers, Ltd. All rights reserved.

Original file name:
TaskProxy.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\keyboardlockstateosd\taskproxy.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/7/2016 9:00:00 AM

Valid to:
6/15/2017 8:59:59 AM

Subject:
CN="NEC Personal Computers, Ltd.", OU=PDD6, O="NEC Personal Computers, Ltd.", L=Chiyoda-ku, S=Tokyo, C=JP

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3240C1FDF3522AD8FBCFF562DAA9846E

File PE Metadata
Compilation timestamp:
7/26/2016 7:33:35 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x24A0

Entry point:
48, 83, EC, 28, E8, 77, 03, 00, 00, 48, 83, C4, 28, E9, BE, FC, FF, FF, FF, 25, 18, 0D, 00, 00, FF, 25, 0A, 0D, 00, 00, FF, 25, 4C, 0D, 00, 00, FF, 25, EE, 0C, 00, 00, FF, 25, D0, 0C, 00, 00, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, 1D, 2C, 00, 00, FF, 15, C7, 0B, 00, 00, 48, 8B, 05, 08, 2D, 00, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, E1, 03, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44...
 
[+]

Entropy:
5.2312

Code size:
7 KB (7,168 bytes)

Scheduled Task
Task name:
NECCapsLock

Trigger:
Logon (Runs on logon)