BitLockerWizard.exe

  • File Path: C:\Windows\system32\BitLockerWizard.exe
  • Description: BitLocker Drive Encryption Wizard

Hashes

Type Hash
MD5 A9C78F189E2111734F7E961EBE38188A
SHA1 F4C13F46048B4B536083D4627A1C0E2C22753385
SHA256 13302146579B36397D4B5E602F98B8474A65BDCC125E499FD0FF2EEFD811C44B
SHA384 9D54C7149FCC8E3FA00752419C78B6D1F5DF988907D5549DA2BEAB8B823DE19E2587F67F6DA999BE4D41BDDDA007CF81
SHA512 7389E29B83E6ECFD061C7668A1B4841D0359E40DF34460E8FAA2A616A6F3F46B2F1405630E32F6ABB311FF2C527966DAB13ADD386F6F685FE9FDE7C8C3864F90
SSDEEP 3072:NZoyKwnVS570M9kdatGCO+xmBc+hMPhPsx:ceVs7nyatGt+SYF
IMP 1438673C4B1B5696C777658AD76B5D13
PESHA1 D4F285E06AE87D808F75688D470822451E9B3C42
PE256 8B8002DC5034BED43A7814A1BEB3B7AED27BC2014D7B879C62F686825C308335

Runtime Data

Usage (stderr):

Bitlocker Wizard Launcher
    	Usage: BitlockerWizard X: <P|R|S|T>
    	    P is mapped to  FVEUI_AFTER_TPM_PPI_NO_REBOOT
    	    R is mapped to  FVEUI_AFTER_TPM_PPI_REBOOT
    	    S is mapped to  FVEUI_MODE_CREATE_NO_REBOOT
    	    T is mapped to  FVEUI_MODE_CREATE_AFTER_REBOOT
    	    U is mapped to  FVEUI_MODE_DUPLICATEKEY
    	    V is mapped to  FVEUI_MODE_RESUME
    	    W is mapped to  FVEUI_AFTER_REPARTITION
    	    X is mapped to  FVEUI_PARAM_AFTER_REPARTITION_TPM_PPI
    	    Y is mapped to  FVEUI_PARAM_SAVE_RECOVERY
    	    Z is mapped to  FVEUI_PARAM_PASSPHRASE
    	    K is mapped to  FVEUI_PARAM_STARTUPKEY
    	    J is mapped to  FVEUI_PARAM_CHANGE_PIN
    	    I is mapped to  FVEUI_PARAM_STARTUP_UNLOCK


Loaded Modules:

Path
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\bcrypt.dll
C:\Windows\system32\BDEUI.dll
C:\Windows\system32\BitLockerWizard.exe
C:\Windows\System32\combase.dll
C:\Windows\System32\COMDLG32.dll
C:\Windows\system32\FVEWIZ.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\ole32.dll
C:\Windows\System32\OLEAUT32.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\SHELL32.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: BitLockerWizard.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/13302146579b36397d4b5e602f98b8474a65bdcc125e499fd0ff2eefd811c44b/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\baaupdate.exe 86
C:\WINDOWS\system32\baaupdate.exe 82
C:\windows\system32\baaupdate.exe 83
C:\Windows\system32\baaupdate.exe 91
C:\Windows\system32\BdeHdCfg.exe 74
C:\WINDOWS\system32\BdeHdCfg.exe 74
C:\Windows\system32\BdeHdCfg.exe 77
C:\windows\system32\BdeHdCfg.exe 79
C:\Windows\system32\bdeunlock.exe 43
C:\Windows\system32\bdeunlock.exe 44
C:\WINDOWS\system32\bdeunlock.exe 40
C:\windows\system32\bdeunlock.exe 49
C:\Windows\system32\BitLockerWizard.exe 88
C:\windows\system32\BitLockerWizard.exe 88
C:\WINDOWS\system32\BitLockerWizard.exe 88
C:\Windows\system32\BitLockerWizardElev.exe 86
C:\Windows\system32\BitLockerWizardElev.exe 88
C:\WINDOWS\system32\BitLockerWizardElev.exe 90
C:\windows\system32\BitLockerWizardElev.exe 91
C:\Windows\system32\fvecpl.dll 44
C:\Windows\system32\fvenotify.exe 72
C:\windows\system32\fvenotify.exe 72
C:\WINDOWS\system32\fvenotify.exe 72
C:\Windows\system32\fvenotify.exe 65
C:\WINDOWS\system32\fveprompt.exe 72
C:\Windows\system32\fveprompt.exe 74
C:\Windows\system32\fveprompt.exe 68
C:\windows\system32\fveprompt.exe 71
C:\Windows\system32\fveui.dll 49
C:\WINDOWS\system32\manage-bde.exe 52
C:\Windows\system32\manage-bde.exe 50
C:\Windows\system32\manage-bde.exe 54
C:\windows\system32\manage-bde.exe 55
C:\Windows\system32\repair-bde.exe 79
C:\WINDOWS\system32\repair-bde.exe 80
C:\windows\system32\repair-bde.exe 75
C:\Windows\system32\repair-bde.exe 71

MIT License. Copyright (c) 2020-2021 Strontic.