bfsvc.exe

  • File Path: C:\Windows\bfsvc.exe
  • Description: Boot File Servicing Utility

Hashes

Type Hash
MD5 0726E07524335D86FC9C6BB2EBAB71F7
SHA1 C0B8221A063D133014C2B29197ACD70FE0A7C0FF
SHA256 1B17747065AA027A0995460A2E5C9C4C2FE255918892AF16C3545B925687F5DF
SHA384 A7E28EEBBDF82879D50693E58247D6063039005F74B9E363D0295A37A148FAA94521BB96356307A69326AF22BFA44721
SHA512 9B41C6BA32FC7F8FB058006DA64D2699888BC4856351569E813C49598148F109A8C898060FF323E2B5979F1AE2E3D1974598B056B8F8E219F5E5DA4ABE01DE9D
SSDEEP 1536:zKPEy6iopQUevUYr33JZHOvBfwn6NXI9M6eynTDuae10jguBybF:E8Q++ZHOvBfw6N4CAeWjc
IMP 0036D0ED215BD5342506902CA36E0BD3
PESHA1 EBC8680FCF5CAEDCFB706C58094DE4C9FA0EE8C9
PE256 270F3CF361AF1D3915F70B0EE833DAE98D4DA6FC116BB0E1183572508B94B33B

Runtime Data

Usage (stderr):

BFSVC Error: Failed to get partition name. Status = 0xc0000452
BFSVC Error: Failed to get system partition! Last Error = 0x3bc3
BFSVC Error: ServicingBootFiles failed. Error = 0x3bc3

Loaded Modules:

Path
C:\Windows\bfsvc.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: bfsvc.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/75
  • VirusTotal Link: https://www.virustotal.com/gui/file/1b17747065aa027a0995460a2e5c9c4c2fe255918892af16c3545b925687f5df/detection

MIT License. Copyright (c) 2020-2021 Strontic.