xenvbd.sys

Citrix Windows PV drivers

XenSource(TEST)

It runs as a Windows kernel mode device driver named “xenvbd”.
Publisher:
Citrix  (signed by XenSource(TEST))

Product:
Citrix Windows PV drivers

Description:
XenSource xenvbd SCSI miniport

Version:
5.5.0.23143p built by: CitrixSystems,Inc.

MD5:
aba2ad29c48186279c8a6d38b66b47d0

SHA-1:
241b64c2c2b15ace6fbde6b4875c294b3f4f014f

SHA-256:
badd55f3f8a29054c4d9ef4a995d44825bfe34d552e0822fbda714ef42533841

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 2:08:49 PM UTC  (today)

File size:
123.2 KB (126,112 bytes)

Product version:
5.5.0.23143p

Copyright:
Copyright (C) Citrix Systems, Inc., 2009

Original file name:
xenvbd.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\xenvbd.sys

Digital Signature
Signed by:

Authority:
XenSource(TEST)

Valid from:
8/8/2007 2:04:45 PM

Valid to:
12/31/2039 5:59:59 PM

Subject:
CN=XenSource(TEST)

Issuer:
CN=XenSource(TEST)

Serial number:
55104EFE4E0704AE437EDF51B9873685

File PE Metadata
Compilation timestamp:
11/9/2009 4:35:01 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:VP7uW1KG2WCzjGazMEDN8DDZC6GhhidvGILG:VP7H1qWCeazMZRba

Entry address:
0x1F005

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 80, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 80, 70, 01, 00, B8, 00, 80, 01, 00, C1, E8, 08, 33, 02, A3, 00, 80, 01, 00, 75, 07, 8B, C1, A3, 00, 80, 01, 00, F7, D0, A3, 04, 80, 01, 00, 5D, E9, 2B, 32, FE, FF, CC, 40, F1, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, F3, 01, 00, 80, 70, 00, 00, C0, F0, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 70, F4, 01, 00, 00, 70, 00, 00, E0, F0, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, F6, F4, 01, 00, 20, 70, 00, 00, 98...
 
[+]

Entropy:
2.4305

Code size:
26.5 KB (27,136 bytes)

Driver
Display name:
xenvbd

Type:
Kernel device driver (KernelDriver)

Group:
Scsi Miniport

Depends on:
xenevtchn


Scan xenvbd.sys - Powered by Reason Core Security