nmroam.sys

Mobility

NetMotion Wireless Inc.

It runs as a Windows kernel mode device driver named “NetMotion Roaming Detection Daemon”.
Publisher:
NetMotion Wireless, Inc.  (signed by NetMotion Wireless Inc.)

Product:
Mobility

Description:
NetMotion OID Based Roaming Detection

Version:
10.10.17840

MD5:
2e076634b765ae97655cd13202c8110d

SHA-1:
7a56c81110e09b300efab42c0fddfda6dd39ae45

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 11:11:13 AM UTC  (today)

File size:
26 KB (26,664 bytes)

Product version:
10.10.17840

Copyright:
Copyright © 1999-2013 NetMotion Wireless, Inc.

Trademarks:
NetMotion is a registered trademark of NetMotion Wireless, Inc.

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\nmroam.sys

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/11/2012 8:00:00 PM

Valid to:
5/9/2014 7:59:59 PM

Subject:
CN=NetMotion Wireless Inc., OU=DEVELOPMENT SERVICES, O=NetMotion Wireless Inc., L=Seattle, S=Washington, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3BAC12C0A5101692AC8428F0D51BC993

File PE Metadata
Compilation timestamp:
12/9/2013 5:17:34 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x703E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 06, C0, FF, FF, CC, CC, B4, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 71, 00, 00, 00, 10, 00, 00, 14, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8A, 73, 00, 00, 60, 10, 00, 00, C4, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, 74, 00, 00, 10, 10, 00, 00, 0C, 71, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 14, 75, 00, 00, 58, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 71, 00, 00, A0, 71, 00, 00, 78, 71...
 
[+]

Entropy:
6.3884

Code size:
16 KB (16,384 bytes)

Driver
Display name:
NetMotion Roaming Detection Daemon

Service name:
NMRoam

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Scan nmroam.sys - Powered by Reason Core Security