ctxidhlp.exe

Citrix Presentation Server

Citrix Systems, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Citrix Session Helper’.
Publisher:
Citrix Systems, Inc.  (signed and verified)

Product:
Citrix Presentation Server

Description:
Citrix Session Helper

Version:
4.5.4052

MD5:
9d50794c98d10b8383197353b67bd528

SHA-1:
9c94013f01107f352c97c99335c8dd420a66d016

SHA-256:
7153a8cb69a07be73c4567af31579ac4e9e58b144ebd36db0d80264295a7eeb5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 11:16:43 PM UTC  (a few moments ago)

File size:
74.4 KB (76,176 bytes)

Product version:
4.5

Copyright:
Copyright 1990-2009 Citrix Systems, Inc.

Original file name:
ctxidhlp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\citrix\virtual desktop agent\ctxidhlp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/9/2012 1:00:00 AM

Valid to:
4/1/2014 1:59:59 AM

Subject:
CN="Citrix Systems, Inc.", OU=XenApp Engineering (Server), OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Citrix Systems, Inc.", L=Fort Lauderdale, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
614060318E0F1AF1C5E0F34675F62930

File PE Metadata
Compilation timestamp:
11/9/2012 7:53:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
1536:qIAC/hnUIrd7n6YOyHQ52PYlcVL2RwkdlwuUM1n:zv/FUmd7xI2gZC+lwuUM1n

Entry address:
0x20EB

Entry point:
6A, 60, 68, E8, C4, 40, 00, E8, 51, 14, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 9D, 15, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 34, C0, 40, 00, 8B, 4E, 10, 89, 0D, 7C, F9, 40, 00, 8B, 46, 04, A3, 88, F9, 40, 00, 8B, 56, 08, 89, 15, 8C, F9, 40, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 80, F9, 40, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 80, F9, 40, 00, C1, E0, 08, 03, C2, A3, 84, F9, 40, 00, 33, F6, 56, 8B, 3D, 2C, C0, 40, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
44 KB (45,056 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Citrix Session Helper

Command:
C:\Program Files\citrix\virtual desktop agent\ctxidhlp.exe