BitLockerWizard.exe
- File Path:
C:\Windows\system32\BitLockerWizard.exe
- Description: BitLocker Drive Encryption Wizard
Hashes
Type | Hash |
---|---|
MD5 | A9C78F189E2111734F7E961EBE38188A |
SHA1 | F4C13F46048B4B536083D4627A1C0E2C22753385 |
SHA256 | 13302146579B36397D4B5E602F98B8474A65BDCC125E499FD0FF2EEFD811C44B |
SHA384 | 9D54C7149FCC8E3FA00752419C78B6D1F5DF988907D5549DA2BEAB8B823DE19E2587F67F6DA999BE4D41BDDDA007CF81 |
SHA512 | 7389E29B83E6ECFD061C7668A1B4841D0359E40DF34460E8FAA2A616A6F3F46B2F1405630E32F6ABB311FF2C527966DAB13ADD386F6F685FE9FDE7C8C3864F90 |
SSDEEP | 3072:NZoyKwnVS570M9kdatGCO+xmBc+hMPhPsx:ceVs7nyatGt+SYF |
IMP | 1438673C4B1B5696C777658AD76B5D13 |
PESHA1 | D4F285E06AE87D808F75688D470822451E9B3C42 |
PE256 | 8B8002DC5034BED43A7814A1BEB3B7AED27BC2014D7B879C62F686825C308335 |
Runtime Data
Usage (stderr):
Bitlocker Wizard Launcher
Usage: BitlockerWizard X: <P|R|S|T>
P is mapped to FVEUI_AFTER_TPM_PPI_NO_REBOOT
R is mapped to FVEUI_AFTER_TPM_PPI_REBOOT
S is mapped to FVEUI_MODE_CREATE_NO_REBOOT
T is mapped to FVEUI_MODE_CREATE_AFTER_REBOOT
U is mapped to FVEUI_MODE_DUPLICATEKEY
V is mapped to FVEUI_MODE_RESUME
W is mapped to FVEUI_AFTER_REPARTITION
X is mapped to FVEUI_PARAM_AFTER_REPARTITION_TPM_PPI
Y is mapped to FVEUI_PARAM_SAVE_RECOVERY
Z is mapped to FVEUI_PARAM_PASSPHRASE
K is mapped to FVEUI_PARAM_STARTUPKEY
J is mapped to FVEUI_PARAM_CHANGE_PIN
I is mapped to FVEUI_PARAM_STARTUP_UNLOCK
Loaded Modules:
Path |
---|
C:\Windows\System32\ADVAPI32.dll |
C:\Windows\System32\bcrypt.dll |
C:\Windows\system32\BDEUI.dll |
C:\Windows\system32\BitLockerWizard.exe |
C:\Windows\System32\combase.dll |
C:\Windows\System32\COMDLG32.dll |
C:\Windows\system32\FVEWIZ.dll |
C:\Windows\System32\GDI32.dll |
C:\Windows\System32\gdi32full.dll |
C:\Windows\System32\KERNEL32.DLL |
C:\Windows\System32\KERNELBASE.dll |
C:\Windows\System32\msvcp_win.dll |
C:\Windows\System32\msvcrt.dll |
C:\Windows\SYSTEM32\ntdll.dll |
C:\Windows\System32\ole32.dll |
C:\Windows\System32\OLEAUT32.dll |
C:\Windows\System32\RPCRT4.dll |
C:\Windows\System32\sechost.dll |
C:\Windows\System32\SHELL32.dll |
C:\Windows\System32\ucrtbase.dll |
C:\Windows\System32\USER32.dll |
C:\Windows\System32\win32u.dll |
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: BitLockerWizard.exe.mui
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.19041.1 (WinBuild.160101.0800)
- Product Version: 10.0.19041.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/74
- VirusTotal Link: https://www.virustotal.com/gui/file/13302146579b36397d4b5e602f98b8474a65bdcc125e499fd0ff2eefd811c44b/detection
File Similarity (ssdeep match)
MIT License. Copyright (c) 2020-2021 Strontic.