messerv.exe

Mobility

NetMotion Wireless Inc.

It runs as a separate (within the context of its own process) windows Service named “NetMotion Client”.
Publisher:
NetMotion Wireless, Inc.  (signed by NetMotion Wireless Inc.)

Product:
Mobility

Description:
NetMotion Network Provider Shell

Version:
10.11.21343

MD5:
340803f2e67c9427648336de142e6ef6

SHA-1:
42e329b6af4a5635e97399b7dc39b9644254ec49

SHA-256:
24bd32ac46704590dd455992190760b1a2d70ea73e5c5ac88d62424db9269f5b

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 10:35:33 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

File size:
1.3 MB (1,339,944 bytes)

Product version:
10.11.21343

Copyright:
Copyright © 1999-2013 NetMotion Wireless, Inc.

Trademarks:
NetMotion is a registered trademark of NetMotion Wireless, Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\netmotion client\messerv.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/11/2012 8:00:00 PM

Valid to:
5/9/2014 7:59:59 PM

Subject:
CN=NetMotion Wireless Inc., OU=DEVELOPMENT SERVICES, O=NetMotion Wireless Inc., L=Seattle, S=Washington, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3BAC12C0A5101692AC8428F0D51BC993

File PE Metadata
Compilation timestamp:
3/13/2014 8:08:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:XAbXAYupo3iTyc0NMWa6xVIO86S0l+idPbE/ydD/0bnJyykKN0pneJ8ZN+8FGCx:wwY5aVvGZnz70dyC0pne++8FGCx

Entry address:
0xE7ED8

Entry point:
E8, FD, 07, 00, 00, E9, 6C, FD, FF, FF, FF, 25, 40, B5, 4E, 00, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 44, B5, 4E, 00, FF, 25, 48, B5, 4E, 00, FF, 25, 4C, B5, 4E, 00, FF, 25, 50, B5, 4E, 00, FF, 25, 54, B5, 4E, 00, FF, 25, 58, B5, 4E, 00, FF, 25, 5C, B5, 4E, 00, FF, 25, 60, B5, 4E, 00, FF, 25, 64, B5, 4E, 00, FF, 25, 68, B5, 4E, 00, FF, 25, 6C, B5, 4E, 00, FF, 25, 70, B5, 4E, 00, FF, 25, 74, B5, 4E, 00, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, DA, F9, FF, FF, 51, 8D...
 
[+]

Entropy:
6.6673

Code size:
933 KB (955,392 bytes)

Service
Display name:
NetMotion Client

Service name:
MESSERV

Description:
Provides secure, continuous remote access to network resources and applications from mobile devices.

Type:
Win32OwnProcess

Group:
PNP_TDI

Depends on:
NMutilnt fsclm NMDRV


Scan messerv.exe - Powered by Reason Core Security