rnlsp.dll

VRADD.com Multiplatform Application Framework

It is installed as a Winsock Layered Service Provider (LSP) named “ActiveTracker LSP over [MSAFD Tcpip [TCP/IP]]” as a layered chain entry.
Publisher:

MD5:
8a478a3c4063dcf5e30ce5dce55264ec

SHA-1:
3ba31c1e7e9e87a29e7152aecd4bfdf6ce196b1a

SHA-256:
c71b2dd5e37511cd78eaacf125ed8e855a2f0323f667e1258d056c3709373db2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 10:40:37 PM UTC  (today)

File size:
121.8 KB (124,728 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Windows\System32\rnlsp.dll

Digital Signature
Authority:
The USERTRUST Network

Valid from:
12/27/2009 6:00:00 PM

Valid to:
12/28/2010 5:59:59 PM

Subject:
CN=VRADD.com Multiplatform Application Framework, O=VRADD.com Multiplatform Application Framework, STREET=PO Box 988, L=Noosa Heads, S=QLD, PostalCode=4567, C=AU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
311AB50B91A43F3A6D7937E0C3D4F9F8

File PE Metadata
Compilation timestamp:
10/15/2010 1:39:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:OvirWvyaTEmygSDb0R0DcHKT5K7PPzUS5dym3OHtPcDcbnZgiD230ZB6O0bOA9:+iuyahZsb5wHKlK7P7byj2DB1EZV0J

Entry address:
0x6549

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, DA, 2C, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, C1, 8B, 4D, 08, C7, 00, B0, 84, 01, 10, 8B, 09, 89, 48, 04, C6, 40, 08, 00, 5D, C2, 08, 00, 8B, 41, 04, 85, C0, 75, 05, B8, B8, 84, 01, 10, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 57, 8B, F9, 74, 2D, 56, FF, 75, 08, E8, 83, 2D, 00, 00, 8D, 70, 01, 56, E8, 62, 1A, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 11, FF, 75, 08, 56, 50, E8, 05, 2D, 00, 00...
 
[+]

Entropy:
6.4771

Code size:
87.5 KB (89,600 bytes)

Winsock2 LSP
Name:
ActiveTracker LSP over [MSAFD Tcpip [TCP/IP]]

Type:
Layered Chain Entry

Provider ID:
{009F9A73-770F-46BB-BB83-4E4146EFA3E1}

Service flags:
0x20066


Scan rnlsp.dll - Powered by Reason Core Security