dumpfve.sys

Bitlocker Drive Encryption Crashdump Filter

Microsoft Corporation

Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
Bitlocker Drive Encryption Crashdump Filter

Version:
6.2.9200.16384 (win8_rtm.120725-1247)

MD5:
a93715b61401ca75ed6c9062a4593fbb

SHA-1:
29187d385447af9fc82ac0fe915dd1d76f976f6d

SHA-256:
e65bfa2cd2759713b56d3e8668e5d599c35f959ab594a728d8e64f149c4ff35f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/26/2024 1:34:06 PM UTC  (today)

File size:
61 KB (62,496 bytes)

Product version:
6.2.9200.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
dumpfve.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Digital Signature
Authority:
Microsoft Corporation

Valid from:
4/9/2012 10:55:50 PM

Valid to:
7/9/2013 10:55:50 PM

Subject:
CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
610BBBD8000000000005

File PE Metadata
Compilation timestamp:
7/26/2012 4:28:53 AM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
10.10

CTPH (ssdeep):
768:9eucG93cNiaDNai5q5IIUE67CdyMlMqWNU+K74FV2BRpWbSDHCHFAHgPeNCMAw18:Pn9qD2XdyMlMqqU+NV2/S2woPJi

Entry address:
0x445C

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 97, CB, 00, 00, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, F2, D3, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 59, 8C, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, 08, 00, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, B9, 02, 00, 00, 00, CD, 29, CC, CC, CC, CC, CC, CC, CC, FF, 25, 64, 3B, 00, 00...
 
[+]

Entropy:
6.9077

Code size:
29 KB (29,696 bytes)