RCallAttendant.exe

WinDeveloper Recall Message

WinDeveloper Software Ltd.

It runs as a separate (within the context of its own process) windows Service named “Message Recall Attendant”.
Publisher:
WinDeveloper Software Ltd.  (signed and verified)

Product:
WinDeveloper Recall Message

Description:
Recall Message Attendant Service

Version:
1, 0, 0, 2

MD5:
7cc7de480e3f88fa8808d60f7634e674

SHA-1:
f642896078bf67118799e6d9461234ed97ee11db

SHA-256:
3cbb0b8993d37e413aa3d245cf170e3ee899bb0d5ff5672a0ac9a63c21849ce3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 2:42:12 AM UTC  (today)

File size:
246.2 KB (252,120 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (c) 2011 WinDeveloper Software Ltd. All rights reserved.

Original file name:
RCallAttendant.exe

File type:
Executable application (Win64 EXE)

Language:
English (United Kingdom)

Common path:
C:\Program Files\windeveloper message recall\rcallattendant.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/10/2011 8:00:00 PM

Valid to:
8/10/2016 7:59:59 PM

Subject:
CN=WinDeveloper Software Ltd., O=WinDeveloper Software Ltd., STREET="64/5, Triq Madre Tereza", L=Mosta, S=Mosta, PostalCode=MST2410, C=MT

Issuer:
CN=COMODO Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E79F8B0E851D6C1EA27663B3B36167FF

File PE Metadata
Compilation timestamp:
10/4/2012 2:35:36 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:mWVNQhgtVLE1RgigQiYUW5fmh/5T+J+egLR6lAye6uZwv2gZStue9m:mWVWhQLwRgi9HUYOh/5T+J+dLR6lFuOp

Entry address:
0x19770

Entry point:
48, 83, EC, 28, E8, 27, 62, 00, 00, 48, 83, C4, 28, E9, 12, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 6C, 24, 18, 48, 89, 74, 24, 20, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 20, 49, 63, 78, 0C, 4C, 8B, F9, 49, 8B, C8, 49, 8B, E9, 4D, 8B, E8, 4C, 8B, F2, E8, 28, 63, 00, 00, 4D, 8B, 17, 4C, 89, 55, 00, 44, 8B, E0, 85, FF, 0F, 84, 85, 00, 00, 00, 48, 8D, 0C, BF, 48, 8D, 34, 8D, EC, FF, FF, FF, 49, 63, 5D, 10, 49, 03, 5E, 08, 48, 03, DE, 44, 3B, 63, 04, 7E, 49, 44, 3B, 63, 08, 7F, 43, 49, 8B, 0E...
 
[+]

Entropy:
6.4154

Code size:
161.5 KB (165,376 bytes)

Service
Display name:
Message Recall Attendant

Service name:
RCallAttendant

Description:
Performs Message Recall system maintenance and background processing.

Type:
Win32OwnProcess

Depends on:
RPCSS


Scan RCallAttendant.exe - Powered by Reason Core Security