feclient.dll

  • File Path: C:\Windows\system32\feclient.dll
  • Description: Windows NT File Encryption Client Interfaces

Hashes

Type Hash
MD5 4401F4795005B5DC4BB1BAF1A87B1342
SHA1 4061A34907C7B7240A2D0F70CEC1AB7F9C73A358
SHA256 A5BD0D33940328C60D50F05F387E8CEF277F596F2D96935471568D820F807727
SHA384 5FEDD5149CDCBEF1C79887ABBE877D8B4C61E115894A5EDC0DFA3BF0CC3E6F62BD117AA4A999B40594BC9E0657C5FF00
SHA512 2AF537DD94358C24966A43286A8DB8970BECF2200BBADE0CA35ED39B0D0BC9622F6B507254E31DC90B634EA24BBCE78ED612B0D1C706086F8578154481C48D8F
SSDEEP 3072:n8oP0YhYA0+oA1PswL4qPcWoDaASgIEVn0MHjOk8+MgSBL/ynOxcrvkFTd6b5+B0:n8GZhYGplPrCaAzIu0MHipjyOUfb8OP
IMP 92D0B17F3FBF8F96B5AFA7076C7D717B
PESHA1 DD99ECB0E218DBD33FC45E6AD1F8873407B3F967
PE256 611B0510AE441644587C1220F4D30C87AD2EAEED761008E94255358CA449D76E

DLL Exports:

Function Name Ordinal Type
EfsClientFreeProtectorList 37 Exported Function
EfsClientFreeKeyInfo 36 Exported Function
EfsClientFileEncryptionStatus 35 Exported Function
EfsClientOpenFileRaw 40 Exported Function
EfsClientGetKeyInfo 39 Exported Function
EfsClientGetEncryptedFileVersion 38 Exported Function
EfsClientEncryptFileEx 34 Exported Function
EfsClientCloseFileRaw 30 Exported Function
EdpWriteLogSiteLearningEvents 29 Exported Function
EdpUnprotectFile 28 Exported Function
EfsClientDuplicateEncryptionInfo 33 Exported Function
EfsClientDecryptFile 32 Exported Function
EfsClientCopyFileRaw 31 Exported Function
EfsClientQueryProtectors 41 Exported Function
FeClQueryInfo 50 Exported Function
FeClientInitialize 51 Exported Function
FeClClearCaches 49 Exported Function
OefsCheckSupport 54 Exported Function
GetLockSessionWrappedKey 53 Exported Function
GetLockSessionUnwrappedKey 52 Exported Function
EfsValidateUserForConsumer 48 Exported Function
EfsClientWriteFileWithHeaderRaw 44 Exported Function
EfsClientWriteFileRaw 43 Exported Function
EfsClientReadFileRaw 42 Exported Function
EfsValidateTokenForConsumer 47 Exported Function
EfsUtilGetCurrentKey 46 Exported Function
EfsReprotectFile 45 Exported Function
EdpDplPolicyEnabledForUser 10 Exported Function
EdpDecontainerizeFile 9 Exported Function
EdpCredentialQuery 8 Exported Function
EdpDplUpgradeVerifyUser 13 Exported Function
EdpDplUpgradePinInfo 12 Exported Function
EdpDplStartCredServiceIfDplEnabledForUser 11 Exported Function
EdpCredentialExists 7 Exported Function
EdpAllowFileAccessForProcess 3 Exported Function
DpQueryUserProtectorDescriptorInfo 2 Exported Function
DpQueryUserProtectorDescriptor 1 Exported Function
EdpCredentialDelete 6 Exported Function
EdpCredentialCreate 5 Exported Function
EdpContainerizeFile 4 Exported Function
EdpDplUserCredentialsSet 14 Exported Function
EdpQueryDplEnforcedPolicyOwnerIds 24 Exported Function
EdpQueryCredServiceInfo 23 Exported Function
EdpPurgeAppLearningEvents 22 Exported Function
EdpSetCredServiceInfo 27 Exported Function
EdpRmsClearKeys 26 Exported Function
EdpQueryRevokedPolicyOwnerIds 25 Exported Function
EdpIsConsumerDataProtectionSupported 21 Exported Function
EdpFree 17 Exported Function
EdpDplUserUnlockStart 16 Exported Function
EdpDplUserUnlockComplete 15 Exported Function
EdpIsConsumerDataProtectionEnforced 20 Exported Function
EdpGetCredServiceState 19 Exported Function
EdpGetContainerIdentity 18 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: FECLIENT.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/a5bd0d33940328c60d50f05f387e8cef277f596f2d96935471568d820f807727/detection/

MIT License. Copyright (c) 2020-2021 Strontic.