oasrv.exe

Online Armor Firewall

Tall Emu

It runs as a separate (within the context of its own process) windows Service named “Online Armor”.
Publisher:
Tall Emu  (signed and verified)

Product:
Online Armor Firewall

Description:
Online Armor Component

Version:
3.5.0.14

MD5:
a915530a43debefe5c3056f9eec1ba76

SHA-1:
e1a6a4006cfbadab2b2d5185c406d0f589ed87f5

SHA-256:
ae1f3c23958c2ca84414984971f57441680a0ec662a08375e1bbad594f42251d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 2:51:45 PM UTC  (today)

File size:
2.9 MB (3,052,744 bytes)

Product version:
3.5.0.14

Copyright:
Tall Emu 2004-2009

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\Program Files\online armor\oasrv.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/25/2008 5:55:39 PM

Valid to:
2/25/2010 5:55:39 PM

Subject:
E=support@tallemu.com, CN=Tall Emu, O=Tall Emu, C=AU

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001185185634A

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:nlfwDqjhwoKMg1gvlzYbc//////oVSaK247a6DOrPPy0nvZzyOn/TMWa/msk:nlf+q1Z2+mc//////oVSaMDOrPPy0gON

Entry address:
0x20F544

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 14, E6, 60, 00, E8, 3D, 7D, DF, FF, E8, C8, 3B, E9, FF, 33, C0, 55, 68, 76, F7, 60, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, 59, F7, 60, 00, 64, FF, 30, 64, 89, 20, 68, 00, 00, 80, 00, 68, 00, 00, 40, 00, E8, 29, 82, DF, FF, 50, E8, C3, 85, DF, FF, A1, C4, 5F, 62, 00, 8B, 00, E8, 2B, 37, DF, FF, E8, EA, 36, DF, FF, 68, 3C, DF, 62, 00, 68, 38, DF, 62, 00, E8, 03, 82, DF, FF, 50, E8, DD, 82, DF, FF, E8, 10, 1D, E9, FF, 84, C0, 0F, 84, 62, 01, 00, 00, A1, 7C, 5B, 62...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.1 MB (2,157,056 bytes)

Service
Display name:
Online Armor

Service name:
SvcOnlineArmor

Type:
Win32OwnProcess

Group:
NetBIOSGroup

Depends on:
RPCSS


Scan oasrv.exe - Powered by Reason Core Security