cblsx64.exe

Norplex AS

It runs as a separate (within the context of its own process) windows Service named “Ahsay A-Click Backup Services”.
Publisher:
Norplex AS  (signed and verified)

MD5:
c67121deb8a1d56c8b0347fdb6b0bc43

SHA-1:
79cf2d0d52c0e732dabe3f4dd84c3b159dd628c4

SHA-256:
e102d0ddec666b2dca65023b96c9c6ddde853d63393ed1629b9ac2be1aad5401

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/7/2024 4:36:00 PM UTC  (today)

File size:
291.4 KB (298,384 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\app\bin\cblsx64.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
10/31/2015 11:41:02 PM

Valid to:
10/31/2017 4:50:46 PM

Subject:
E=firma@swiboda.com, CN=Norplex AS, O=Norplex AS, L=Heggenes, S=Oppland, C=NO

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
13720DB7141FCA

File PE Metadata
Compilation timestamp:
9/26/2016 2:46:04 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

Entry address:
0x1A8B0

Entry point:
48, 83, EC, 28, E8, 07, A1, 00, 00, 48, 83, C4, 28, E9, 4E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 18, 57, 48, 83, EC, 20, 48, 85, C9, 48, 8B, DA, 48, 8B, F9, 75, 12, 48, 8B, CA, 48, 8B, 5C, 24, 40, 48, 83, C4, 20, 5F, E9, D9, E8, FF, FF, 48, 85, D2, 75, 12, E8, 9F, E9, FF, FF, 33, C0, 48, 8B, 5C, 24, 40, 48, 83, C4, 20, 5F, C3, 48, 83, FA, E0, 48, 89, 6C, 24, 30, 48, 89, 74, 24, 38, 77, 43, BD, 01, 00, 00, 00, 48, 8B, 0D, BE, C7, 02, 00, 48, 85, DB, 4C, 8B, C7...
 
[+]

Code size:
191.5 KB (196,096 bytes)

Service
Display name:
Ahsay A-Click Backup Services

Service name:
OBAScheduler

Description:
Continuous Backup and Scheduler Services for Ahsay A-Click Backup

Type:
Win32OwnProcess


Scan cblsx64.exe - Powered by Reason Core Security