oasrv.exe

Online Armor Personal Firewall

Tall Emu

It runs as a separate (within the context of its own process) windows Service named “Online Armor”.
Publisher:
Tall Emu  (signed and verified)

Product:
Online Armor Personal Firewall

Version:
3.0.0.190

MD5:
5fb449583de38ff307eecf85055702ee

SHA-1:
7be776518bb259fe8be21b3b3795a4f1445d3bae

SHA-256:
d1c70b4c68d6e09b8aa620e7e5b670d125d72e79ccce143c02a2a6df15958232

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 4:19:47 AM UTC  (today)

File size:
3.2 MB (3,321,032 bytes)

Product version:
3.0.0.0

Copyright:
Tall Emu 2004-2008

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\Program Files\tall emu\online armor\oasrv.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/25/2008 11:55:39 AM

Valid to:
2/25/2010 11:55:39 AM

Subject:
E=support@tallemu.com, CN=Tall Emu, O=Tall Emu, C=AU

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001185185634A

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:4Mc//////Z3pyiQBtxoUnMBIOys9tWc8ZWhI3vU/f4CuS:3iSt3Kks9tWc8ZWHf4CuS

Entry address:
0x220BD4

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 57, 33, C0, 89, 45, EC, B8, 64, FC, 61, 00, E8, E4, 64, DE, FF, 33, C0, 55, 68, D9, 0D, 62, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, B9, 0D, 62, 00, 64, FF, 30, 64, 89, 20, 68, 00, 00, 80, 00, 68, 00, 00, 40, 00, E8, CD, 69, DE, FF, 50, E8, 6F, 6D, DE, FF, A1, DC, 6F, 63, 00, 8B, 00, E8, 97, 1D, DE, FF, E8, 56, 1D, DE, FF, 68, A8, E2, 63, 00, 68, A4, E2, 63, 00, E8, A7, 69, DE, FF, 50, E8, 81, 6A, DE, FF, E8, B0, 31, ED, FF, 84, C0, 0F, 84, 32, 01, 00, 00, A1, BC, 6B, 63...
 
[+]

Entropy:
6.5980

Developed / compiled with:
Microsoft Visual C++

Code size:
2.1 MB (2,228,224 bytes)

Service
Display name:
Online Armor

Service name:
SvcOnlineArmor

Type:
Win32OwnProcess

Group:
NetBIOSGroup

Depends on:
RPCSS


Scan oasrv.exe - Powered by Reason Core Security