momclnt.EXE

Anwendung momclnt

NT-ware Systemprogrammierung GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MOMCLIENT’. This is installed with uniFLOW Client.
Publisher:
NT-ware Systemprogrammierung GmbH  (signed and verified)

Product:
Anwendung momclnt

Description:
uniFLOW OM Client

Version:
5,0,5,510

MD5:
af47b34f5d5a8234b0bac7c149b9e10b

SHA-1:
01c3a5fc0eb9c8f4986dc1bc6c2d8777d2fea615

SHA-256:
cda00fd0dbed7b773020af8a26527399fd5c342cbb176229beff1442927a2a0f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 12:51:22 PM UTC  (today)

File size:
1.4 MB (1,516,392 bytes)

Product version:
5,0,5,510

Copyright:
Copyright (C) 1999-2011 NT-ware GmbH

Original file name:
momclnt.EXE

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\uniflow_client\momclnt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/18/2009 2:00:00 AM

Valid to:
6/28/2012 1:59:59 AM

Subject:
CN=NT-ware Systemprogrammierung GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NT-ware Systemprogrammierung GmbH, L=Bad Iburg, S=Niedersachsen, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
049076675A2D7B658A640FE70C1D568C

File PE Metadata
Compilation timestamp:
3/29/2011 1:58:00 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:Fbksb/Dz3smzlsfpB4/q69gHSHwGDQSrekzMIY6Py9LWMWJE:V/ftzlTeSHFQAeaDP4WbJE

Entry address:
0xC3174

Entry point:
E8, AE, D9, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, C0, 6F, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, CE, 6B, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 88, 14, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 87, 00, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, 71, 6F, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Entropy:
6.1763

Code size:
1 MB (1,073,152 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MOMCLIENT

Command:
C:\Program Files\uniflow_client\momclnt.exe


The file momclnt.EXE has been discovered within the following program.

uniFLOW Client  by NT-ware
About 1% of users remove it
 
Powered by Should I Remove It?

Scan momclnt.EXE - Powered by Reason Core Security