OnlineBackup.exe

@Backup Online Backup

SwapDrive Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘@BackupScheduler’. This is installed with Online Backup.
Publisher:
SwapDrive, Inc.  (signed by SwapDrive Inc.)

Product:
@Backup Online Backup

Description:
@Backup Scheduler

Version:
2.00.131

MD5:
e23935a472009bf88330492f85749425

SHA-1:
51b53f0cd08cd611e1223b8759ad71b02d790fb5

SHA-256:
83e426b0a540a71c3054baeb366cec199352f23d5868ec8bdf927cce58282211

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:13:21 AM UTC  (today)

File size:
597.4 KB (611,768 bytes)

Product version:
2.00.294

Copyright:
Copyright © 1996-2006 SwapDrive Inc., All Rights Reserved

Trademarks:
@Backup, SkyDesk, SwapDrive

Original file name:
OnlineBackup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\online backup\onlinebackup.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
10/12/2005 2:30:27 PM

Valid to:
10/12/2006 2:30:27 PM

Subject:
CN=SwapDrive Inc., OU=Security Department, O=SwapDrive Inc., L=Washington, S=District of Columbia, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
400CAD

File PE Metadata
Compilation timestamp:
6/30/2006 7:03:29 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:hl3q56ADt1FrDG3H0gA26g52HqBVXqQHw7PD:G56ADJn7c60JBZq2wbD

Entry address:
0x15ACA

Entry point:
E8, 4B, 86, 00, 00, E9, 16, FE, FF, FF, 6A, 0C, 68, 68, B9, 42, 00, E8, 60, 3F, 00, 00, 6A, 0E, E8, 28, 34, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 90, 05, 43, 00, BA, 8C, 05, 43, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 76, C9, FF, FF, 59, FF, 76, 04, E8, 6D, C9, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 4F, 3F, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, F5, 32, 00, 00, 59, C3, 8B, 4C, 24, 04, 53, 33...
 
[+]

Entropy:
5.8616

Code size:
148 KB (151,552 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
@BackupScheduler

Command:
C:\Program Files\online backup\onlinebackup.exe


The file OnlineBackup.exe has been discovered within the following program.

Online Backup  by SwapDrive, Inc.
www.backup.com/aboutus.html
About 9% of users remove it
 
Powered by Should I Remove It?

Scan OnlineBackup.exe - Powered by Reason Core Security