bcfmgr.exe

BestCrypt Volume Encryption

Jetico Inc. Oy

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BestCrypt Volume Encryption’.
Publisher:
Jetico Inc. Oy  (signed and verified)

Product:
BestCrypt Volume Encryption

Description:
BestCrypt Volume Encryption Manager

Version:
3.72.01

MD5:
619ae7c5eb578c8b4ef827315795118b

SHA-1:
03f847908623ad87da9625d5a0fe068df799c4e6

SHA-256:
523fb3848f42449fd36d7b12e437c5400b573cf2dc7fc603e0ec7c525c2b32b7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 11:54:43 AM UTC  (today)

File size:
2.6 MB (2,770,840 bytes)

Product version:
3.72.01

Copyright:
Copyright (C) 2005 - 2016

Trademarks:
BestCrypt is a trademark of Jetico Inc. Oy

Original file name:
bcfmgr.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\jetico\bestcrypt\bc_ve\bcfmgr.exe

Digital Signature
Signed by:

Authority:
Jetico Inc. Oy

Valid from:
10/17/2016 7:42:23 PM

Valid to:
12/31/2039 11:59:59 PM

Subject:
CN=Jetico Inc. Oy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Jetico Inc. Oy, L=Espoo, S=Uusimaa, C=FI

Issuer:
CN=Jetico Inc. Oy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Jetico Inc. Oy, L=Espoo, S=Uusimaa, C=FI

Serial number:
86C9D6864F49B384416332414197383A

File PE Metadata
Compilation timestamp:
9/14/2016 10:20:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:Sdxrl8x2QdaB7UVO12h+FL4Rz5FN1JCOQcOU84MlHyMMYguH:exex2hB7UVOscL45RkcOb4MlHyMMYguH

Entry address:
0x137141

Entry point:
E8, E5, BD, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 0C, 75, 1D, E8, C4, 66, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 91, 4A, 00, 00, 83, C4, 14, 83, C8, FF, EB, 69, 8B, 45, 08, 3B, C3, 74, DC, 56, FF, 75, 14, 89, 45, E8, FF, 75, 10, 89, 45, E0, FF, 75, 0C, 8D, 45, E0, 50, C7, 45, EC, 42, 00, 00, 00, C7, 45, E4, FF, FF, FF, 7F, E8, 27, C0, 00, 00, 83, C4, 10, FF, 4D, E4, 8B, F0, 78, 0A, 8B, 45, E0, 88, 18, FF, 45, E0, EB, 0C, 8D, 45, E0, 50, 53, E8, FD...
 
[+]

Entropy:
6.3172

Code size:
1.4 MB (1,448,448 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BestCrypt Volume Encryption

Command:
"C:\Program Files\jetico\bestcrypt\bc_ve\bcfmgr.exe" mountatlogon


Scan bcfmgr.exe - Powered by Reason Core Security