feclient.dll

  • File Path: C:\Windows\SysWOW64\feclient.dll
  • Description: Windows NT File Encryption Client Interfaces

Hashes

Type Hash
MD5 BA0F46D00C347F38044852703510E329
SHA1 2081F9A8B876F1BFD322FAFCC944411B20240950
SHA256 CB68D51F285F5EE3C29BD81E5D058840D11F2A3F2092D618AE50B649ACAD1FC3
SHA384 AF5338FB74A5770C2A91A1C0CDA327969201949AEB5022905F1CE8DBFDF9758B97936FFAB7C59BAECA65B590052965FC
SHA512 2619A498DD358DBF5195A6501466D1C305CFC163AFE384F5EDD4944838F2DD07F88264FDE1A3E77E6F19599BD7D37185DFDC419FC0525C4478F7EAA8BC6E81B2
SSDEEP 3072:0a+SbvkBo7fXrUgUUxKRVTyGV6QzMZLaIZyLZyLRicyL/6feeHuO3hKhUg6pVjXE:lJ3r7UUCclaIZyLZyLUcyLSfnhKhB6pU
IMP BE81CAAFBD94620974731B5CB2722E06
PESHA1 B5681F24646E4DB82E2DE1E836EC1AEFE11BEAD8
PE256 78D0EEBB97514B8F95C2BE1E3445391E3253F02F4134E41321E88DDD56138849

DLL Exports:

Function Name Ordinal Type
EfsClientFreeProtectorList 38 Exported Function
EfsClientFreeKeyInfo 37 Exported Function
EfsClientFileEncryptionStatus 36 Exported Function
EfsClientOpenFileRaw 41 Exported Function
EfsClientGetKeyInfo 40 Exported Function
EfsClientGetEncryptedFileVersion 39 Exported Function
EfsClientEncryptFileEx 35 Exported Function
EfsClientCloseFileRaw 31 Exported Function
EdpWriteLogSiteLearningEvents 30 Exported Function
EdpUnprotectFile 29 Exported Function
EfsClientDuplicateEncryptionInfo 34 Exported Function
EfsClientDecryptFile 33 Exported Function
EfsClientCopyFileRaw 32 Exported Function
EfsClientQueryProtectors 42 Exported Function
FeClQueryInfo 50 Exported Function
FeClientInitialize 51 Exported Function
FeClClearCaches 49 Exported Function
OefsCheckSupport 54 Exported Function
GetLockSessionWrappedKey 53 Exported Function
GetLockSessionUnwrappedKey 52 Exported Function
EfsValidateUserForConsumer 48 Exported Function
EfsClientWriteFileWithHeaderRaw 45 Exported Function
EfsClientWriteFileRaw 44 Exported Function
EfsClientReadFileRaw 43 Exported Function
EfsValidateTokenForConsumer 47 Exported Function
EfsUtilGetCurrentKey 1 Exported Function
EfsReprotectFile 46 Exported Function
EdpDplPolicyEnabledForUser 11 Exported Function
EdpDecontainerizeFile 10 Exported Function
EdpCredentialQuery 9 Exported Function
EdpDplUpgradeVerifyUser 14 Exported Function
EdpDplUpgradePinInfo 13 Exported Function
EdpDplStartCredServiceIfDplEnabledForUser 12 Exported Function
EdpCredentialExists 8 Exported Function
EdpAllowFileAccessForProcess 4 Exported Function
DpQueryUserProtectorDescriptorInfo 3 Exported Function
DpQueryUserProtectorDescriptor 2 Exported Function
EdpCredentialDelete 7 Exported Function
EdpCredentialCreate 6 Exported Function
EdpContainerizeFile 5 Exported Function
EdpDplUserCredentialsSet 15 Exported Function
EdpQueryDplEnforcedPolicyOwnerIds 25 Exported Function
EdpQueryCredServiceInfo 24 Exported Function
EdpPurgeAppLearningEvents 23 Exported Function
EdpSetCredServiceInfo 28 Exported Function
EdpRmsClearKeys 27 Exported Function
EdpQueryRevokedPolicyOwnerIds 26 Exported Function
EdpIsConsumerDataProtectionSupported 22 Exported Function
EdpFree 18 Exported Function
EdpDplUserUnlockStart 17 Exported Function
EdpDplUserUnlockComplete 16 Exported Function
EdpIsConsumerDataProtectionEnforced 21 Exported Function
EdpGetCredServiceState 20 Exported Function
EdpGetContainerIdentity 19 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: FECLIENT.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/cb68d51f285f5ee3c29bd81e5d058840d11f2a3f2092d618ae50b649acad1fc3/detection/

MIT License. Copyright (c) 2020-2021 Strontic.