WRSA.exe
Webroot SecureAnywhere by Webroot Inc. (Signed)
Version: | 8.0.4.84 |
MD5: | 4158b19a9bf089a7a655106a8c1be508 |
SHA1: | 91459e342e2586ea1471b2c9f4266273bb7b4477 |
About WRSA.exe (from Webroot Inc.)
“You need the best protection against viruses, spyware and malware. That's why we've improved the protection found in Spy Sweeper and created Webroot® SecureAnywhere™ AntiVirus, giving you online prote”
Overview
wrsa.exe runs as a service under the name WRSVC with extensive SYSTEM privileges (full administrator access). It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including Webroot SecureAnywhere published by Webroot and Webroot SecureAnywhere published by Webroot. The file is digitally signed by Webroot Inc. which was issued by the VeriSign certificate authority (CA).
Details
File name: | wrsa.exe |
Publisher: | Webroot |
Product name: | Webroot SecureAnywhere |
Typical file path: | C:\Program Files\webroot\wrsa.exe |
File version: | 8.0.4.84 |
Size: | 746.12 KB (764,024 bytes) |
Build date: | 6/11/2014 6:06 PM |
Certificate |
Issued to: | Webroot Inc. |
Authority (CA): | VeriSign |
Expiration date: | Thursday, January 9, 2014 |
Digital DNA |
File packed: | Yes |
.NET CLR: | No |
More details
Programs
The following programs will install this file
“Webroot SecureAnywhere uses a radically new cloud-based approach to online security that protects you against the latest threats as soon as they emerge. And it does so at blazing fast speeds, typically taking two minutes or less after the initial scan of your PC. It also backs up your files and blocks dangerous web links. Plus, with Webroot’s first-of-its-kind security portal, you can access all your passwords and manage the protection ...”
Behaviors
Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'WRSVC' → "C:\Program Files\Webroot\WRSA.exe" -ul
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00032596% | |
Kernel CPU: | 0.00015024% | |
User CPU: | 0.00017572% | |
Kernel CPU time: | 74,202 ms/min | |
CPU cycles: | 8,049,358/sec | |
Context switches: | 20/sec | |
Memory |
Private memory: | 49.14 MB | |
Private (maximum): | 32 MB | |
Private (minimum): | 844 KB | |
Non-paged memory: | 49.14 MB | |
Virtual memory: | 144.49 MB | |
Virtual memory (peak): | 290.75 MB | |
Working set: | 2.53 MB | |
Working set (peak): | 77.81 MB | |
Page faults: | 8,490,517/min | |
I/O |
I/O read transfer: | 797.18 KB/sec | |
I/O read operations: | 30/sec | |
I/O write transfer: | 32.37 KB/sec | |
I/O write operations: | 17/sec | |
I/O other transfer: | 587.62 KB/sec | |
I/O other operations: | 1,124/sec | |
Resource allocations |
Threads: | 21 | |
Handles: | 366 | |
GUI GDI count: | 282 | |
GUI GDI peak: | 318 | |
GUI USER count: | 28 | |
GUI USER peak: | 52 | |
Process properties
Integrety level: | System |
Platform: | 64-bit |
Command lines: |
- "C:\Program Files\webroot\wrsa.exe" -service
- "C:\Program Files\webroot\wrsa.exe"
|
Owner: | SYSTEM |
Windows Service |
Service name: | WRSVC |
Description: | “Webroot SecureAnywhere Antivirus v8.0.2.118” |
Type: | Win32OwnProcess |
Parent processes: |
|
Threads
Averages
WRSA.exe (main module) |
Total CPU: | 0.00703154% | |
Kernel CPU: | 0.00489749% | |
User CPU: | 0.00213406% | |
CPU cycles: | 376,439/sec | |
Context switches: | 4/sec | |
Memory: | 2.1 MB | |
wow64cpu.dll |
Total CPU: | 0.00123355% | |
Kernel CPU: | 0.00087432% | |
User CPU: | 0.00035923% | |
CPU cycles: | 78,982/sec | |
Memory: | 32 KB | |
wow64.dll |
Total CPU: | 0.00029481% | |
Kernel CPU: | 0.00005896% | |
User CPU: | 0.00023585% | |
CPU cycles: | 20,447/sec | |
Memory: | 252 KB | |
ntdll.dll |
Total CPU: | 0.00012502% | |
Kernel CPU: | 0.00006001% | |
User CPU: | 0.00006501% | |
CPU cycles: | 41,264/sec | |
Memory: | 1.67 MB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
28.57% |
|
Windows Seven Black Edition |
19.05% |
|
Windows 8 |
19.05% |
|
Windows 8.1 |
9.52% |
|
Windows Vista Ultimate |
4.76% |
|
Windows 8 Pro with Media Center |
4.76% |
|
Windows Vista Home Premium |
4.76% |
|
Windows 7 Ultimate N |
4.76% |
|
Windows 7 Ultimate |
4.76% |
|
Distribution by country
United States installs about 95.24% of Webroot SecureAnywhere.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
52.94% |
|
Acer |
11.76% |
|
Dell |
11.76% |
|
Lenovo |
11.76% |
|
ASUS |
11.76% |
|