AdRemNetFlowServer.exe

AdRem NetCrunch

AdRem Software sp. z o.o.

It runs as a separate (within the context of its own process) windows Service named “AdRem NetCrunch Flow Collector”.
Publisher:
AdRem Software, Inc.  (signed by AdRem Software sp. z o.o.)

Product:
AdRem NetCrunch

Description:
NetCrunch NetFlow Server

Version:
9.3.0.3879

MD5:
2abe2bf9695d3842c1fe1a275a841d79

SHA-1:
23a571cd1cb6e351f2d7edab12647ebd07f42d0e

SHA-256:
250365ebadd16ba4de404a92e3258b89e05f8ad0a8ec61d239b27b9e8f61e1c3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/3/2026 5:59:31 AM UTC  (today)

File size:
13.5 MB (14,184,360 bytes)

Product version:
9.3.0.0

Copyright:
2015 (c) AdRem Software Inc., all rights reserved

Original file name:
AdRemNetFlowServer.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\adrem\netcrunch\server\9.0\adremnetflowserver.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/16/2016 1:00:00 AM

Valid to:
12/20/2016 12:59:59 AM

Subject:
CN=AdRem Software sp. z o.o., O=AdRem Software sp. z o.o., L=Krakow, S=malopolska, C=PL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6940ADB9C819ED30D090F4E561439531

File PE Metadata
Compilation timestamp:
10/24/2016 5:37:20 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x9E9F50

Entry point:
55, 57, 53, 48, 83, EC, 40, 48, 8B, EC, 48, C7, 45, 38, 00, 00, 00, 00, 90, 48, 8D, 0D, 36, 01, 00, 00, E8, 31, 22, 63, FF, 90, 48, 8D, 4D, 38, E8, 07, 71, B6, FF, 48, 8B, 05, 60, B0, 11, 00, 48, 8B, 08, 48, 8B, 55, 38, E8, F4, 5A, A5, FF, 48, 8B, 05, 4D, B0, 11, 00, 48, 8B, 08, B2, 01, E8, 13, 61, A5, FF, 48, 8B, 05, 3C, B0, 11, 00, 48, 8B, 00, C6, 40, 30, 04, 48, 8B, 05, 2E, B0, 11, 00, 48, 8B, 08, C7, C2, 20, A1, 07, 00, E8, 60, 5F, A5, FF, 48, 8B, 05, F9, B5, 11, 00, 48, 8B, 00, 80, 78, 78, 00, 74, 13...
 
[+]

Code size:
10.1 MB (10,574,336 bytes)

Service
Display name:
AdRem NetCrunch Flow Collector

Service name:
AdRemNetFlowServerSvc

Description:
Collects and analyzes NetFlow and sFlow data

Type:
Win32OwnProcess


Scan AdRemNetFlowServer.exe - Powered by Reason Core Security