fvecpl.dll

  • File Path: C:\Windows\system32\fvecpl.dll
  • Description: BitLocker Drive Encryption control panel

Hashes

Type Hash
MD5 7809069116F870A3555AE330B0AD66F3
SHA1 272E126C5CA7B289E258320857E58870D89DD2A7
SHA256 BD28232A913200428CD81D0FF9143B99555360DEDC6899F07AA623B7D5C931A8
SHA384 9D5FBE1F8666E50E646A3A91FA29A34EDA4710D4694B7244BFBF4B84F57AF36C200F7CBABEC0460D957BDC273C66E7DF
SHA512 7EF50F924E49BA08746771F9434FBD1D9350FE04CA348009D245B2CBABCC262D768BB17F86F35FE6003067DCAA000C0C3EB46BBC7F45E7B50C9D7FC54FB6976A
SSDEEP 6144:KnJgyKworQz8f5ac44i3RFGn9uz7Dvle222gBLBUZdTVs7nyatGt+SYF:6Kmz8P44URFGYz7Dde2vDH+S+
IMP EA9FF07D6F588D404D9DD8FE97B523DE
PESHA1 2ABE8F9DED002B2D47FDF6D29DCA72AB5D145237
PE256 D18536FDB48DCEB2C394CA1BF74772E11ABE0EFA366557729153BD176E9AFDF8

DLL Exports:

Function Name Ordinal Type
VolumeFveStatus::IsPartiallyConverted 32 Exported Function
VolumeFveStatus::IsOsVolume 31 Exported Function
VolumeFveStatus::IsPaused 33 Exported Function
VolumeFveStatus::IsRoamingDevice 35 Exported Function
VolumeFveStatus::IsPreProvisioned 34 Exported Function
VolumeFveStatus::IsOsCriticalVolume 30 Exported Function
VolumeFveStatus::IsEncrypted 26 Exported Function
VolumeFveStatus::IsEDriveVolume 25 Exported Function
VolumeFveStatus::IsEncrypting 27 Exported Function
VolumeFveStatus::IsOn 29 Exported Function
VolumeFveStatus::IsLocked 28 Exported Function
VolumeFveStatus::GetLastConvertStatus 8 Exported Function
VolumeFveStatus::operator 5 Exported Function
BuiVolume::NO_DRIVE_LETTER 39 Exported Function
VolumeFveStatus::GetStatusFlags 9 Exported Function
VolumeFveStatus::GetExtendedFlags 7 Exported Function
VolumeFveStatus::operator 4 Exported Function
VolumeFveStatus::IsUnknownFveVersion 37 Exported Function
VolumeFveStatus::IsSecure 36 Exported Function
VolumeFveStatus::IsWiping 38 Exported Function
BuiVolume::operator 3 Exported Function
VolumeFveStatus::NeedsRestart 40 Exported Function
VolumeFveStatus::HasExternalKey 10 Exported Function
VolumeFveStatus::FailedDryRun 6 Exported Function
VolumeFveStatus::HasPassphraseProtector 12 Exported Function
VolumeFveStatus::HasPinProtector 13 Exported Function
VolumeFveStatus::HasPBKDF2RecoveryPassword 11 Exported Function
VolumeFveStatus::VolumeFveStatus 2 Exported Function
DllGetClassObject 42 Exported Function
DllCanUnloadNow 41 Exported Function
DllRegisterServer 43 Exported Function
VolumeFveStatus::VolumeFveStatus 1 Exported Function
DllUnregisterServer 44 Exported Function
VolumeFveStatus::IsDEAutoProvisioned 21 Exported Function
VolumeFveStatus::IsCsvMetadataVolume 20 Exported Function
VolumeFveStatus::IsDecrypted 22 Exported Function
VolumeFveStatus::IsDisabled 24 Exported Function
VolumeFveStatus::IsDecrypting 23 Exported Function
VolumeFveStatus::IsConverting 19 Exported Function
VolumeFveStatus::HasRecoveryPassword 15 Exported Function
VolumeFveStatus::HasRecoveryData 14 Exported Function
VolumeFveStatus::HasSmartCardProtector 16 Exported Function
VolumeFveStatus::HasTpmProtector 18 Exported Function
VolumeFveStatus::HasStartupKeyProtector 17 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: FVECPL.DLL.MUI
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/67
  • VirusTotal Link: https://www.virustotal.com/gui/file/bd28232a913200428cd81d0ff9143b99555360dedc6899f07aa623b7d5c931a8/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\baaupdate.exe 40
C:\WINDOWS\system32\baaupdate.exe 44
C:\windows\system32\baaupdate.exe 40
C:\WINDOWS\system32\baaupdate.exe 40
C:\Windows\system32\baaupdate.exe 40
C:\WINDOWS\system32\BdeHdCfg.exe 40
C:\Windows\system32\BdeHdCfg.exe 44
C:\WINDOWS\system32\BdeHdCfg.exe 43
C:\Windows\system32\BdeHdCfg.exe 40
C:\windows\system32\BdeHdCfg.exe 41
C:\Windows\system32\bdeunlock.exe 36
C:\Windows\system32\bdeunlock.exe 41
C:\WINDOWS\system32\bdeunlock.exe 36
C:\WINDOWS\system32\bdeunlock.exe 38
C:\windows\system32\bdeunlock.exe 35
C:\Windows\system32\bdeunlock.exe 40
C:\WINDOWS\system32\BitLockerWizard.exe 44
C:\Windows\system32\BitLockerWizard.exe 38
C:\windows\system32\BitLockerWizard.exe 41
C:\WINDOWS\system32\BitLockerWizard.exe 44
C:\Windows\system32\BitLockerWizard.exe 41
C:\Windows\system32\BitLockerWizard.exe 44
C:\Windows\system32\BitLockerWizardElev.exe 40
C:\Windows\system32\BitLockerWizardElev.exe 43
C:\WINDOWS\system32\BitLockerWizardElev.exe 43
C:\Windows\system32\BitLockerWizardElev.exe 43
C:\windows\system32\BitLockerWizardElev.exe 41
C:\WINDOWS\system32\BitLockerWizardElev.exe 40
C:\Windows\system32\fvenotify.exe 41
C:\WINDOWS\system32\fvenotify.exe 43
C:\windows\system32\fvenotify.exe 36
C:\WINDOWS\system32\fvenotify.exe 41
C:\Windows\system32\fvenotify.exe 40
C:\WINDOWS\system32\fveprompt.exe 43
C:\Windows\system32\fveprompt.exe 40
C:\Windows\system32\fveprompt.exe 41
C:\WINDOWS\system32\fveprompt.exe 41
C:\windows\system32\fveprompt.exe 40
C:\Windows\system32\fveui.dll 40
C:\WINDOWS\system32\manage-bde.exe 41
C:\Windows\system32\manage-bde.exe 38
C:\Windows\system32\manage-bde.exe 36
C:\WINDOWS\system32\manage-bde.exe 38
C:\windows\system32\manage-bde.exe 40
C:\Windows\system32\repair-bde.exe 46
C:\WINDOWS\system32\repair-bde.exe 40
C:\WINDOWS\system32\repair-bde.exe 44
C:\windows\system32\repair-bde.exe 41
C:\Windows\system32\repair-bde.exe 40

MIT License. Copyright (c) 2020-2021 Strontic.