wpservice.exe

Ark Information Systems inc.

It runs as a windows Service named “WinProtector Service”.
Publisher:
Ark Information Systems inc.  (signed and verified)

MD5:
4933cf5c98082a846ccfaa2b9037b6af

SHA-1:
bab0362cfbac76d2cc5b1b98313398c3a8c20920

SHA-256:
bbaaddaf2cca03aa94394035a7760de87debbb1a1d3c6bfe51173a32569f0c61

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:20:46 PM UTC  (today)

File size:
1.5 MB (1,608,312 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\wpservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/5/2011 9:00:00 AM

Valid to:
7/5/2012 8:59:59 AM

Subject:
CN=Ark Information Systems inc., OU=KH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ark Information Systems inc., L=Chiyoda-Ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12C38454C4550880A009D55657B5A022

File PE Metadata
Compilation timestamp:
4/9/2012 3:06:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
49152:UAIur7r+yid7UMimEOhlgbdkDt6856CBXd3PAYrvqRWlAQ6VwJfM:8uL+yiJUMKOhlgbdkDt685N5dVvqROAJ

Entry address:
0xF48B5

Entry point:
E8, AC, B0, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 40, 5B, 56, 00, 00, 75, 18, E8, D9, A9, 00, 00, 6A, 1E, E8, 23, A8, 00, 00, 68, FF, 00, 00, 00, E8, 52, 2B, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 40, 5B, 56, 00, FF, 15, 78, 82, 51, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 48, 5B, 56, 00, 74, 0D, 53, E8, EF, B0, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 1D, 03, 00, 00, 89, 30, E8, 16, 03, 00, 00, 89...
 
[+]

Entropy:
6.4071

Code size:
1.1 MB (1,142,784 bytes)

Service
Display name:
WinProtector Service

Type:
Win32OwnProcess, InteractiveProcess


Scan wpservice.exe - Powered by Reason Core Security