Versions
3, 5, 3, 0 29.41%
3, 5, 1, 0 17.65%
3, 2, 3, 0 5.88%
3, 1, 0, 0 23.53%
3, 0, 3, 0 17.65%


Import table
QueryServiceConfigW, RegSetValueExW, RegDeleteValueW, RegCloseKey, InitializeSecurityDescriptor, RegCreateKeyW, LsaOpenPolicy, LsaNtStatusToWinError, LsaAddAccountRights, LsaRemoveAccountRights, LsaClose, LookupAccountNameW, RegOpenKeyW, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegOpenCurrentUser, RegQueryValueW, RegCreateKeyExW, RegQueryValueExW, AllocateAndInitializeSid, GetLengthSid, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, FreeSid, CloseServiceHandle, OpenServiceW, OpenSCManagerW, QueryServiceStatus, GetUserNameW, EncryptFileW, OpenEncryptedFileRawW, ReadEncryptedFileRaw, WriteEncryptedFileRaw, CloseEncryptedFileRaw, RegOpenKeyExW
SetTextJustification, TextOutW, GetTextFaceW, CreateFontW, CreateDIBSection, SetDIBitsToDevice, GetStockObject, SelectPalette, CreateDIBitmap, GetTextExtentPointW, GetTextExtentPoint32W, ExtTextOutW, StretchBlt, BitBlt, RealizePalette, CreateCompatibleDC, CreateCompatibleBitmap, GetObjectW, CreateFontIndirectW, CreatePalette, SelectObject
GdipCloneImage, GdipDrawImageRectRectI, GdiplusShutdown, GdiplusStartup, GdipBitmapSetPixel, GdipDrawImageRectI, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromStream, GdipDeleteGraphics, GdipGetImageWidth, GdipFree, GdipDisposeImage, GdipBitmapUnlockBits, GdipAlloc, GdipCreateFromHDC, GdipBitmapGetPixel, GdipGetImageHeight
FormatMessageW, GetUserDefaultLangID, GetFileAttributesW, WinExec, lstrcatW, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetEnvironmentVariableW, IsBadReadPtr, LocalFree, GetModuleFileNameA, lstrcmpiW, lstrcpyW, GetLocaleInfoW, GetSystemDefaultLangID, FreeResource, IsBadWritePtr, IsBadStringPtrW, IsBadStringPtrA, CompareStringW, GetDiskFreeSpaceW, GetDriveTypeW, GetComputerNameW, LocalAlloc, MoveFileW, ExpandEnvironmentStringsW, UnmapViewOfFile, GetLogicalDriveStringsW, GetTempPathW, DeleteFileW, GetTempFileNameW, GetShortPathNameW, GetSystemDirectoryW, GetVolumeInformationW, ReadFile, WriteFile, CreateDirectoryW, SetLastError, RemoveDirectoryW, GetWindowsDirectoryW, SetFileTime, GetFileSize, SetFilePointer, SetEndOfFile, BackupRead, BackupWrite, BackupSeek, ResetEvent, WaitForMultipleObjects, GetCompressedFileSizeW, FindNextFileW, FindClose, FindFirstFileW, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, SystemTimeToFileTime, GetLocalTime, InterlockedExchange, InterlockedCompareExchange, GetStartupInfoW, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, IsDebuggerPresent, ResumeThread, SetEvent, ReleaseSemaphore, WaitForSingleObject, CreateSemaphoreW, GetVersionExW, HeapFree, HeapAlloc, GetProcessHeap, MapViewOfFile, CreateFileMappingW, FreeLibrary, GetExitCodeProcess, CreateEventW, SizeofResource, lstrlenA, MultiByteToWideChar, GetLongPathNameW, lstrlenW, FindResourceW, LoadResource, LockResource, GlobalAlloc, GlobalLock, GetProcAddress, GetLastError, LoadLibraryW, GetModuleFileNameW, WideCharToMultiByte, SetCurrentDirectoryW, GetCurrentDirectoryW, GetVersion, GetModuleHandleW, SetFileAttributesW, CloseHandle, GetTickCount, DeviceIoControl, Sleep, CreateFileW, GetPrivateProfileStringW, GlobalFree, GetACP, GetLocaleInfoA, GetThreadLocale, GetVersionExA, CopyFileW, GlobalUnlock
NetWkstaUserGetInfo, NetApiBufferFree
CoUninitialize, CoCreateInstanceEx, CoInitialize, CoCreateInstance, CoInitializeEx, CreateStreamOnHGlobal, CoTaskMemFree, StringFromCLSID, CoCreateGuid
SHGetPathFromIDListW, Shell_NotifyIconW, ShellExecuteExW, ShellExecuteW, SHGetFileInfoW, SHGetMalloc, SHGetDesktopFolder, SHGetSpecialFolderLocation
SHDeleteKeyW, PathFileExistsW
IsChild, SetWindowLongW, ModifyMenuW, WinHelpW, GetWindowTextW, IsDialogMessageW, SetTimer, KillTimer, PostMessageW, RegisterWindowMessageA, MessageBoxW, CreatePopupMenu, AppendMenuW, IsWindowEnabled, GetDlgCtrlID, SetWindowTextW, LoadStringW, FindWindowW, GetFocus, GetMenuItemID, GetMenuItemCount, WaitForInputIdle, GetDesktopWindow, SystemParametersInfoW, AdjustWindowRect, GetSystemMetrics, IsWindowVisible, GetSysColorBrush, DestroyWindow, SetRect, IsMenu, GetWindowLongW, GetMenu, GetWindow, GetCapture, OffsetRect, MessageBeep, CopyIcon, SetCursor, ReleaseCapture, DestroyCursor, SetCapture, RedrawWindow, InflateRect, SetRectEmpty, PtInRect, GetSysColor, DrawFocusRect, GetKeyState, ScreenToClient, SetWindowPos, MapDialogRect, GetParent, InvalidateRect, UpdateWindow, ReleaseDC, GetDC, GetClientRect, GetWindowRect, IsRectEmpty, IsWindow, UnregisterClassW, EnumWindows, GetClassNameW, SendMessageW, RegisterWindowMessageW, EnableWindow, GetCursorPos, TrackPopupMenu, LoadImageW, DefWindowProcW, DestroyIcon, LoadCursorW, SetForegroundWindow, LoadMenuW, GetSubMenu, SetMenuDefaultItem
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW


Nero BackItUp by Nero AG (Signed)

Remove NBKEYSCAN.exe
Version:   3, 2, 3, 0
MD5:   d18bd766746b7be0abefa20dc36fd1c8
SHA1:   84a1e94a947c87017d856a7f6ad44387be2a4138
SHA256:   47eed4ae02a439074b6bdd3b1726de2154928b6861d2423c51f483a49399a472

What is NBKEYSCAN.exe?

Nero BackItUp is a Windows backup software application that provides both local and network based file backups. With Nero BackItUp & Burn you can create backup copies on demand by manually selecting the files and folders you want to include in them or set the program to do it automatically without user intervention.


nbkeyscan.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including Nero 8 published by Nero AG, Nero 8 from Nero AG and Nero 8 by Nero AG. The file is digitally signed by Nero AG which was issued by the VeriSign certificate authority (CA).


File name:nbkeyscan.exe
Publisher:Nero AG
Product name:Nero BackItUp
Typical file path:C:\Program Files\nero\nero8\nero backitup\nbkeyscan.exe
File version:3, 2, 3, 0
Size:2.11 MB (2,213,160 bytes)
Issued to:Nero AG
Authority (CA):VeriSign
Effective date:Thursday, April 20, 2006
Expiration date:Tuesday, June 23, 2009
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
More details


Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'NBKeyScan' → "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 29.41%
Microsoft Windows XP 17.65%
Windows 7 Home Premium 11.76%
Windows Vista Home Premium 11.76%
Windows 8 Single Language 5.88%
Windows 8 Pro 5.88%
Windows 8 Release Preview 5.88%
Windows Vista Ultimate 5.88%
Windows 7 Professional 5.88%

Distribution by countryDistribution by country

United States installs about 23.53% of Nero BackItUp.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 37.50%
ASUS 25.00%
Toshiba 12.50%
Hewlett-Packard 12.50%
