scsifilt.sys

Citrix Windows PV drivers

XenSource(TEST)

It runs as a Windows kernel mode device driver named “scsifilt”.
Publisher:
Citrix Systems, Inc.  (signed by XenSource(TEST))

Product:
Citrix Windows PV drivers

Description:
Xen disk filter driver

Version:
6.0.6001.18000 built by: CitrixSystems,Inc.

MD5:
bee626c0dbac7d716c78dd5e46e58f0f

SHA-1:
285d4e541f6700c5af54b3168c20bcd0c021fd86

SHA-256:
12a50be24d72d1e0efe61e374e30ff9df7bff36763ff635bf1c5af5aa61bea82

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/27/2024 12:47:44 AM UTC  (today)

Scan engine
Detection
Engine version

nProtect
Trojan/W32.Agent.40608.C
13.08.22.03

File size:
39.7 KB (40,608 bytes)

Product version:
6.0.6001.18000

Copyright:
Copyright (C) Citrix Systems, Inc., 2009

Original file name:
scsifilt.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\scsifilt.sys

Digital Signature
Signed by:

Authority:
XenSource(TEST)

Valid from:
8/9/2007 4:04:45 AM

Valid to:
1/1/2040 8:59:59 AM

Subject:
CN=XenSource(TEST)

Issuer:
CN=XenSource(TEST)

Serial number:
55104EFE4E0704AE437EDF51B9873685

File PE Metadata
Compilation timestamp:
4/30/2010 10:56:51 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:EAYubN5ELak+Ul6tMQ4P1RY+qKv0mqDyE7jvnlSpdYPLG:EAYub8B+Ul5QC3Yy0mqOE7jviSy

Entry address:
0xB005

Entry point:
8B, FF, 55, 8B, EC, A1, 08, 90, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, CC, 80, 01, 00, 8B, 00, 35, 08, 90, 01, 00, A3, 08, 90, 01, 00, 75, 07, 8B, C1, A3, 08, 90, 01, 00, F7, D0, A3, 0C, 90, 01, 00, 5D, E9, ED, 77, FF, FF, CC, 50, B1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, B6, 00, 00, BC, 80, 00, 00, 94, B0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BA, B6, 00, 00, 00, 80, 00, 00, AC, B0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 56, BA, 00, 00, 18, 80, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5439

Code size:
31 KB (31,744 bytes)

Driver
Display name:
scsifilt

Type:
Kernel device driver (KernelDriver)

Group:
Primary Disk


Scan scsifilt.sys - Powered by Reason Core Security