bcfmgr.exe

BestCrypt Volume Encryption

Jetico Inc. Oy

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BestCrypt Volume Encryption’.
Publisher:
Jetico, Inc. Oy  (signed by Jetico Inc. Oy)

Product:
BestCrypt Volume Encryption

Description:
BestCrypt Volume Encryption Manager

Version:
3.60.14

MD5:
cb18bf24ef1906bee4b1935a194aa7d7

SHA-1:
ed4ebc2c51e8ac3c57b6be0791bf4fb51490ea0e

SHA-256:
a91998aa7da83b4fcc670e7339870bc62ea524c9c5249bc73e8e7779a9637418

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 2:21:16 AM UTC  (today)

File size:
2.5 MB (2,657,568 bytes)

Product version:
3.60.14

Copyright:
Copyright (C) 2005 - 2013

Trademarks:
BestCrypt is a trademark of Jetico, Inc. Oy

Original file name:
bcfmgr.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\jetico\bestcrypt volume encryption\bcfmgr.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/6/2012 6:00:00 PM

Valid to:
9/8/2015 5:59:59 PM

Subject:
CN=Jetico Inc. Oy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Jetico Inc. Oy, L=Espoo, S=Uusimaa, C=FI

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
31C10146F5E05334B854758765316025

File PE Metadata
Compilation timestamp:
8/1/2013 11:59:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:oERIn2HU49J4eUOMpc9dL879jl4LUOQcOU84MlHyMMYguHx:lOnH49J+O3XLOlU2cOb4MlHyMMYguHx

Entry address:
0x1246D9

Entry point:
E8, 79, BA, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 0C, 75, 1D, E8, 0C, 63, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 6E, C9, 00, 00, 83, C4, 14, 83, C8, FF, EB, 69, 8B, 45, 08, 3B, C3, 74, DC, 56, FF, 75, 14, 89, 45, E8, FF, 75, 10, 89, 45, E0, FF, 75, 0C, 8D, 45, E0, 50, C7, 45, EC, 42, 00, 00, 00, C7, 45, E4, FF, FF, FF, 7F, E8, 69, BC, 00, 00, 83, C4, 10, FF, 4D, E4, 8B, F0, 78, 0A, 8B, 45, E0, 88, 18, FF, 45, E0, EB, 0C, 8D, 45, E0, 50, 53, E8, 91...
 
[+]

Entropy:
6.3225

Code size:
1.3 MB (1,361,408 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BestCrypt Volume Encryption

Command:
"C:\Program Files\jetico\bestcrypt volume encryption\bcfmgr.exe" mountatlogon


Scan bcfmgr.exe - Powered by Reason Core Security