vmstorfl.sys

Windows Main Build Lab Account

It runs as a Windows kernel mode device driver named “Disk Virtual Machine Bus Acceleration Filter Driver”.
Publisher:
Windows Main Build Lab Account  (signed and verified)

MD5:
2e9903ac0e8d2ae1c70cc5ed73e7e706

SHA-1:
e2a8fa96596478aed78192a75961151d5858dd7c

SHA-256:
10265f1be2957ac6b27a883fdf0a06db396da977b7c024401f0ac7a9be1fe696

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 7:53:45 AM UTC  (today)

File size:
37 KB (37,856 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\vmstorfl.sys

Digital Signature
Authority:
MSIT Test CodeSign CA 2

Valid from:
3/13/2009 1:39:14 AM

Valid to:
3/13/2010 12:39:14 AM

Subject:
CN=Windows Main Build Lab Account

Issuer:
CN=MSIT Test CodeSign CA 2, DC=redmond, DC=corp, DC=microsoft, DC=com

Serial number:
29C9F976000100003536

File PE Metadata
Compilation timestamp:
4/8/2009 7:45:43 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:9Oxqi63nLeT8fBCYpmFn32VsWecInltxd5MdV9b5rbWQhT:9o67eQVKn32VidnZd5MTh5rb3T

Entry address:
0x1E1A

Entry point:
8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 85, DB, 75, 0E, FF, 75, 0C, 53, E8, D2, 53, 00, 00, E9, BE, 00, 00, 00, 66, 83, 25, E8, 49, 01, 00, 00, 56, FF, 75, 0C, BE, E8, 49, 01, 00, 56, 89, 1D, FC, 49, 01, 00, 66, C7, 05, EA, 49, 01, 00, 08, 02, C7, 05, EC, 49, 01, 00, 00, 4A, 01, 00, FF, 15, 0C, 40, 01, 00, 68, F8, 49, 01, 00, 68, 4C, 43, 01, 00, 56, 53, E8, B1, 10, 00, 00, 85, C0, 7C, 77, 57, 8B, 3D, 08, 4C, 01, 00, EB, 0E, 56, 53, FF, 57, 08, 85, C0, 89, 45, 08, 7C, 1B, 8B, 3F, 85, FF, 75, EE, E8, 62, 00, 00...
 
[+]

Entropy:
6.3481

Code size:
25.5 KB (26,112 bytes)

Driver
Display name:
Disk Virtual Machine Bus Acceleration Filter Driver

Service name:
storflt

Type:
Kernel device driver (KernelDriver)

Group:
Extended Base


Scan vmstorfl.sys - Powered by Reason Core Security