ealsp.dll

ifslsp Dynamic Link Library

Mcgruff Safeguard

It is installed as a Winsock Layered Service Provider (LSP) named “eaLSP over [MSAFD Tcpip [TCP/IP]]” as a layered chain entry.
Publisher:
Mcgruff Safeguard  (signed and verified)

Product:
ifslsp Dynamic Link Library

Version:
9.6.12.134

MD5:
5f7756d285c8ddc9ba301ece58df6529

SHA-1:
59422e6842e00bf427c7bcdaa160b1bf5a85d2b1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 6:56:25 AM UTC  (today)

File size:
41.3 KB (42,272 bytes)

Product version:
9.6.12.134

Copyright:
Copyright (C) 2009

Original file name:
ifslsp.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\event agent\bin\ealsp.dll

Digital Signature
Authority:
The USERTRUST Network

Valid from:
4/8/2009 8:00:00 PM

Valid to:
4/9/2011 7:59:59 PM

Subject:
CN=Mcgruff Safeguard, O=Mcgruff Safeguard, STREET=5900 Collins, L=Miami Beach, S=FL, PostalCode=33140, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0409B5BA142089722CF05EA8561A2C5A

File PE Metadata
Compilation timestamp:
12/2/2009 1:17:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:rnatCIjgBO2CO5mt1bZSUPiebMVEdK+yjGOzredyqItLE:D4CIjgBOcW1sVeb4E8+yj0dyqIt4

Entry address:
0x11E0

Entry point:
55, 8B, EC, 83, E4, F8, 8B, 45, 0C, 81, EC, 14, 03, 00, 00, 53, 33, DB, 2B, C3, 56, 57, 0F, 84, 79, 08, 00, 00, 83, E8, 01, 0F, 85, 34, 08, 00, 00, E8, D6, 39, 00, 00, 83, 3D, 3C, A7, 00, 10, 06, B8, 64, 00, 00, 00, C7, 05, 44, A0, 00, 10, 01, 00, 00, 00, 89, 5C, 24, 10, 89, 5C, 24, 14, 89, 44, 24, 18, 89, 44, 24, 1C, 72, 30, 50, 8D, 84, 24, AC, 00, 00, 00, 50, 68, 04, 72, 00, 10, FF, 15, 5C, 70, 00, 10, 3B, C3, 75, 07, 68, 14, 72, 00, 10, EB, 16, 8D, 8C, 24, A8, 00, 00, 00, 88, 9C, 04, A8, 00, 00, 00, 51...
 
[+]

Entropy:
6.5272

Developed / compiled with:
Microsoft Visual C++

Code size:
21 KB (21,504 bytes)

Winsock2 LSP
Name:
eaLSP over [MSAFD Tcpip [TCP/IP]]

Type:
Layered Chain Entry

Provider ID:
{F9D68488-49A4-4E7E-9DD3-E2A9D4FCDD80}


Scan ealsp.dll - Powered by Reason Core Security