ws_rep.exe

CA

It runs as a separate (within the context of its own process) windows Service named “CA ARCserve RHA Engine”.
Publisher:
CA  (signed and verified)

Version:
16.1

MD5:
10a5ecbecc11541d9bf4276f88202fe1

SHA-1:
da154fe0cf792618ad6954f5fca20ae4a823e553

SHA-256:
3b3925d88b7832487b58a2385b863241a2806b1a841cc849a8f9fa13de6f0b9e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:32:56 PM UTC  (today)

File size:
20.3 MB (21,243,392 bytes)

Product version:
16.1

Copyright:
Copyright (C) 2011 CA Inc.

Original file name:
ws_rep.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ca\arcserve rha\engine\ws_rep.exe

Digital Signature
Signed by:

Authority:
CA

Valid from:
9/16/2010 11:59:50 AM

Valid to:
7/17/1974 5:31:34 AM

Subject:
E=support@ca.com, CN=www.ca.com, OU=www.ca.com, O=CA, L=New York City, S=New York State, C=US

Issuer:
E=support@ca.com, CN=www.ca.com, OU=www.ca.com, O=CA, L=New York City, S=New York State, C=US

Serial number:
00A2E2ACF320B6F80E

File PE Metadata
Compilation timestamp:
8/25/2011 8:17:14 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
98304:QxUTRlu8+QtUguKu1MmInyervajyQVdCkG4kA6vZMPGdOpHFQIXHWRKiA1m0iarq:TPtUe0riGuoBPcZdIX00MMw

Entry address:
0xDEE600

Entry point:
48, 83, EC, 28, E8, 57, 0B, 00, 00, 48, 83, C4, 28, E9, DE, FC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, 48, 8B, 0D, D0, A6, 54, 00, FF, 15, BA, E0, 00, 00, 48, 89, 44, 24, 38, 48, 83, F8, FF, 75, 0B, 48, 8B, CB, FF, 15, AE, E0, 00, 00, EB, 7E, B9, 08, 00, 00, 00, E8, D2, 0B, 00, 00, 90, 48, 8B, 0D, A2, A6, 54, 00, FF, 15, 8C, E0, 00, 00, 48, 89, 44, 24, 38, 48, 8B, 0D, 88, A6, 54, 00, FF, 15, 7A, E0, 00, 00, 48, 89, 44, 24, 40, 48, 8B, CB, FF, 15...
 
[+]

Entropy:
6.1627

Code size:
14 MB (14,653,440 bytes)

Service
Display name:
CA ARCserve RHA Engine

Service name:
CAARCserveRHAEngine

Description:
Provides real-time replication and protection against data corruption for files and databases

Type:
Win32OwnProcess

Depends on:
rpcss


Scan ws_rep.exe - Powered by Reason Core Security