Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

15.0.29.0 0.52%
15.0.17.0 0.52%
4.2.6.100 4.19%
4.2.3.100 14.66%
4.2.3.100 19.90%
4.0.1.102 5.76%
3, 5, 4, 0 1.57%
3, 5, 3, 0 6.81%
3, 5, 2, 0 0.52%
3, 5, 1, 0 6.28%
3, 2, 3, 0 1.57%
3, 1, 0, 0 0.52%
3, 1, 0, 0 5.24%
3, 0, 3, 0 4.71%
2, 10, 6, 4 2.09%
2, 10, 6, 1 1.05%
2, 10, 5, 1 1.05%
2, 10, 3, 2 7.85%
2, 9, 1, 0 4.71%
2, 7, 3, 2 1.05%
2, 7, 3, 2 1.05%
2, 7, 3, 1 3.66%
2, 7, 3, 0 0.52%
2, 7, 2, 0 3.14%
2, 6, 6, 0 1.05%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, FreeSid, LsaRemoveAccountRights, LsaAddAccountRights, LsaNtStatusToWinError, LsaOpenPolicy, RegCreateKeyW, GetFileSecurityW, GetSecurityDescriptorDacl, GetAclInformation, InitializeAcl, GetAce, AddAce, SetEntriesInAclW, SetSecurityDescriptorDacl, SetFileSecurityW, LookupAccountNameW, LogonUserW, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, ControlService, DeleteService, CreateServiceW, ChangeServiceConfig2W, OpenThreadToken, OpenProcessToken, RegEnumKeyExW, OpenSCManagerW, OpenServiceW, CloseServiceHandle, QueryServiceConfigW, QueryServiceStatus, SetServiceStatus, RegisterEventSourceW, ReportEventW, CloseEncryptedFileRaw, WriteEncryptedFileRaw, ReadEncryptedFileRaw, OpenEncryptedFileRawW, EncryptFileW, GetUserNameW, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, LsaClose, RegSetValueExW, RegQueryInfoKeyW, CopySid, GetLengthSid, IsValidSid, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, DeregisterEventSource, RegOpenKeyW, RegEnumValueW, LookupPrivilegeValueW, AdjustTokenPrivileges, LsaQueryInformationPolicy, LsaFreeMemory
dbghelp.dll
GetTimestampForLoadedLibrary
kernel32.dll
GetProcessHeap, HeapAlloc, HeapFree, GetCommandLineW, GetModuleHandleW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, GetCurrentThreadId, GetCurrentThread, GetCurrentProcess, CloseHandle, LocalAlloc, LocalFree, lstrcmpiW, GetLastError, RaiseException, lstrlenW, GetModuleFileNameW, FreeLibrary, LoadLibraryW, GetProcAddress, FindFirstChangeNotificationW, WaitForMultipleObjects, FindCloseChangeNotification, FindNextChangeNotification, WaitForSingleObject, InterlockedDecrement, InterlockedIncrement, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, InterlockedCompareExchange, Sleep, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, CreateSemaphoreW, ReleaseSemaphore, BackupSeek, BackupWrite, BackupRead, SetEndOfFile, DeviceIoControl, SetFilePointer, FindFirstFileW, FindClose, SetLastError, FindNextFileW, GetCompressedFileSizeW, GetLocalTime, SystemTimeToFileTime, FileTimeToSystemTime, LocalFileTimeToFileTime, FileTimeToLocalFileTime, GetVolumeInformationW, GetWindowsDirectoryW, GetSystemDirectoryW, GetShortPathNameW, GetTempFileNameW, DeleteFileW, GetTempPathW, GetLogicalDriveStringsW, CopyFileW, ExpandEnvironmentStringsW, GetVersionExW, MoveFileW, GetComputerNameW, GetFileAttributesW, CompareStringW, GetDriveTypeW, GetDiskFreeSpaceW, CreateThread, CreateEventW, SetEvent, ResetEvent, TerminateThread, ResumeThread, SuspendThread, SetThreadPriority, GetThreadPriority, ExitThread, FormatMessageW, IsBadStringPtrA, IsBadStringPtrW, IsBadReadPtr, IsBadWritePtr, WideCharToMultiByte, CreateFileW, ReadFile, WriteFile, CreateDirectoryW, RemoveDirectoryW, SetFileAttributesW, SetFileTime, GetFileSize, GetGeoInfoW, GetUserGeoID, GetModuleHandleExW
msvcp80.dll
DllMain
msvcr80.dll
DllMain
netapi32.dll
NetWkstaUserGetInfo, NetApiBufferFree, NetWkstaGetInfo
ole32.dll
CoRevokeClassObject, CoRegisterClassObject, CoTaskMemFree, CoCreateInstance, CoTaskMemRealloc, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoInitialize, StringFromGUID2, CoTaskMemAlloc, StringFromCLSID, CoCreateGuid, CoUnmarshalInterface, CoMarshalInterface
shell32.dll
SHGetPathFromIDListW, SHGetFileInfoW, ShellExecuteW, SHGetMalloc, SHGetDesktopFolder, SHGetSpecialFolderLocation
shlwapi.dll
SHDeleteValueW, SHDeleteKeyW
user32.dll
GetMessageW, CharNextW, LoadStringW, PostThreadMessageW, DispatchMessageW, FindWindowW, UnregisterClassA
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
winmm.dll
PlaySoundW

NBService.exe

Nero BackItUp by Nero AG (Signed)

Remove NBService.exe
Version:   4.2.3.100
MD5:   7d2633295eb6ff2b938185874884059d
SHA1:   1f3a0c977c4ecbab8c025770aa29ab454ca548a1
SHA256:   b3a4e52abcb2e2720d8adb0b68c222d4ab98e838d40b6a731d15eb1d6c9dea15

What is NBService.exe?

Nero BackItUp is a Windows backup software application that provides both local and network based file backups. With Nero BackItUp & Burn you can create backup copies on demand by manually selecting the files and folders you want to include in them or set the program to do it automatically without user intervention.

Overview

nbservice.exe runs as a service under the name NBService (Nero BackItUp Scheduler 3) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Nero AG which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:nbservice.exe
Publisher:Nero AG
Product name:Nero BackItUp
Typical file path:C:\Program Files\common files\nero\nero backitup 4\nbservice.exe
File version:4.2.3.100
Size:913.29 KB (935,208 bytes)
Certificate
Issued to:Nero AG
Authority (CA):VeriSign
Effective date:Sunday, May 10, 2009
Expiration date:Thursday, June 21, 2012
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Nero BackItUp Scheduler 3'
  • 'NBService'
  • 'Nero BackItUp Scheduler 4.0'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00033074%
0.028634%
Kernel CPU:0.00015694%
0.013761%
User CPU:0.00017380%
0.014873%
Kernel CPU time:552 ms/min
100,923,805ms/min
CPU cycles:5,237/sec
17,470,203/sec
Memory
Private memory:4.72 MB
21.59 MB
Private (maximum):8.18 MB
Private (minimum):3.81 MB
Non-paged memory:4.72 MB
21.59 MB
Virtual memory:53.02 MB
140.96 MB
Virtual memory (peak):56.02 MB
169.69 MB
Working set:3.96 MB
18.61 MB
Working set (peak):8.21 MB
37.95 MB
Page faults:3,526/min
2,039/min
I/O
I/O read transfer:63 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:17 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:4
12
Handles:131
600
GUI GDI count:4
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • "C:\Program Files\common files\nero\nero backitup 4\nbservice.exe"
  • "C:\program\delade filer\nero\nero backitup 4\nbservice.exe"
Owner:SYSTEM
Windows Service
Service name:Nero BackItUp Scheduler 3
Display name:NBService
Description:“Nero BackItUp Scheduler 3 is responsible to control all jobs created using Nero BackItUp 3. These jobs can create backups of selected files/folders/partitions or complete hard disk to hard disk, network drive, disc or FTP.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 26.01%
Microsoft Windows XP 24.86%
Windows 7 Home Premium 21.97%
Windows Vista Home Premium 6.36%
Windows 7 Professional 6.36%
Windows 7 Home Basic 2.89%
Windows 8 Pro 2.31%
Windows 8.1 1.73%
Windows 8 Single Language 1.16%
Windows Seven Black Edition 1.16%
Windows Vista Home Basic 1.16%
Windows Vista Ultimate 1.16%
Windows 8 Pro with Media Center 1.16%
Windows 8 0.58%
Windows 8 Enterprise 0.58%
Windows 8 Release Preview 0.58%

Distribution by countryDistribution by country

United States installs about 19.19% of Nero BackItUp.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 20.98%
ASUS 18.18%
Acer 14.69%
Hewlett-Packard 13.99%
Toshiba 9.79%
GIGABYTE 6.99%
American Megatrends 4.20%
Intel 4.20%
Sony 2.80%
Medion 1.40%
Compaq 1.40%
Packard Bell 1.40%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE