ws_rep.exe

CA ARCserve RHA Engine

CA

It runs as a separate (within the context of its own process) windows Service named “CA ARCserve RHA Engine”.
Publisher:
CA  (signed and verified)

Product:
CA ARCserve RHA Engine

Version:
16.5.4.4050

MD5:
37ee45572600b7ac51c52c9dd632e57e

SHA-1:
459e850a4fcefe490881964145af1809706cfed0

SHA-256:
df0cc5355e5327742f3b5bedc90939bff4d184a94e88536a6c1fcb892a114293

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:56:33 PM UTC  (today)

File size:
10.7 MB (11,261,952 bytes)

Product version:
16.5

Copyright:
Copyright (C) 2014 CA, Inc.

Original file name:
ws_rep.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ca\arcserve rha\engine\ws_rep.exe

Digital Signature
Signed by:

Authority:
CA

Valid from:
9/16/2010 3:29:50 PM

Valid to:
7/17/1974 9:01:34 AM

Subject:
E=support@ca.com, CN=www.ca.com, OU=www.ca.com, O=CA, L=New York City, S=New York State, C=US

Issuer:
E=support@ca.com, CN=www.ca.com, OU=www.ca.com, O=CA, L=New York City, S=New York State, C=US

Serial number:
00A2E2ACF320B6F80E

File PE Metadata
Compilation timestamp:
8/20/2014 12:50:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
196608:WeIdy/HTOCzA81YlCbrTeftBUoYIX+kV7Oo8QKDHvGEIb2v2z:WeIdy/zOCzUlC3TeftGP2+kJQQKDHvGt

Entry address:
0x677D06

Entry point:
E8, AF, 06, 00, 00, E9, 6C, FD, FF, FF, FF, 25, 80, 1C, B9, 00, FF, 25, 7C, 1C, B9, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, E8, AB, FB, FF, FF, 59, 5D, C3, 6A, 08, B8, 6B, BE, AB, 00, E8, 50, 07, 00, 00, FF, 75, 08, 83, 65, FC, 00, E8, 48, 00, 00, 00, 59, 89, 45, EC, 8B, 45, EC, E8, DD, 07, 00, 00, C3, 83, 65, EC, 00, B8, 48, 7D, A7, 00, C3, CC, FF, 25, 78, 1C, B9, 00, FF, 25, 74, 1C, B9, 00, FF, 25, 70, 1C, B9, 00, FF, 25, 6C, 1C, B9, 00, FF, 25, E8, 19, B9, 00, FF, 25, EC, 19, B9, 00, FF, 25, F0, 19, B9, 00...
 
[+]

Entropy:
6.6567

Code size:
7.6 MB (7,926,272 bytes)

Service
Display name:
CA ARCserve RHA Engine

Service name:
CAARCserveRHAEngine

Description:
Provides real-time replication and protection against data corruption for files and databases

Type:
Win32OwnProcess

Depends on:
rpcss


Scan ws_rep.exe - Powered by Reason Core Security