¿Para qué sirve la dll feclient.dll?

Windows NT File Encryption Client Interfaces

Dependencias de la dll feclient.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\feclient.dll

File Type: DLL

  Image has the following dependencies:

    msvcrt.dll
    api-ms-win-core-localization-l1-2-0.dll
    api-ms-win-core-processthreads-l1-1-0.dll
    api-ms-win-core-heap-l1-1-0.dll
    api-ms-win-core-libraryloader-l1-2-0.dll
    api-ms-win-core-debug-l1-1-0.dll
    api-ms-win-core-errorhandling-l1-1-0.dll
    api-ms-win-core-winrt-l1-1-0.dll
    api-ms-win-core-handle-l1-1-0.dll
    api-ms-win-core-synch-l1-1-0.dll
    api-ms-win-core-winrt-string-l1-1-0.dll
    api-ms-win-core-threadpool-l1-2-0.dll
    api-ms-win-eventing-provider-l1-1-0.dll
    api-ms-win-core-registry-l1-1-0.dll
    api-ms-win-core-file-l1-1-0.dll
    api-ms-win-security-base-l1-1-0.dll
    api-ms-win-security-sddl-l1-1-0.dll
    api-ms-win-core-heap-l2-1-0.dll
    api-ms-win-core-sysinfo-l1-1-0.dll
    api-ms-win-core-synch-l1-2-1.dll
    api-ms-win-core-string-l1-1-0.dll
    bcrypt.dll
    api-ms-win-core-synch-l1-2-0.dll
    api-ms-win-core-rtlsupport-l1-1-0.dll
    api-ms-win-core-profile-l1-1-0.dll
    RPCRT4.dll
    OLEAUT32.dll
    api-ms-win-core-com-l1-1-0.dll
    api-ms-win-core-memory-l1-1-1.dll
    api-ms-win-core-memory-l1-1-0.dll
    api-ms-win-core-privateprofile-l1-1-0.dll
    api-ms-win-stateseparation-helpers-l1-1-0.dll
    ntdll.dll
    iertutil.dll
    api-ms-win-core-processthreads-l1-1-1.dll
    api-ms-win-core-delayload-l1-1-1.dll
    api-ms-win-core-delayload-l1-1-0.dll
    api-ms-win-core-kernel32-legacy-l1-1-0.dll

  Image has the following delay load dependencies:

    EFSCORE.dll
    VAULTCLI.dll
    CRYPT32.dll
    USERENV.dll
    CRYPTBASE.dll
    ext-ms-win-session-usermgr-l1-1-0.dll
    api-ms-win-core-psm-app-l1-1-0.dll
    EFSUTIL.dll
    MPR.dll
    ext-ms-win-devmgmt-policy-l1-1-0.dll
    api-ms-win-service-management-l2-1-0.dll
    api-ms-win-service-management-l1-1-0.dll

  Summary

        2000 .data
        1000 .didat
        2000 .pdata
       10000 .rdata
        1000 .reloc
        1000 .rsrc
       2B000 .text

Funciones que tiene la dll feclient.dll


1    0 000133A0 DpQueryUserProtectorDescriptor
2    1 000135E0 DpQueryUserProtectorDescriptorInfo
3    2 00012DA0 EdpAllowFileAccessForProcess
4    3 00012D30 EdpContainerizeFile
5    4 00011E30 EdpCredentialCreate
6    5 000121F0 EdpCredentialDelete
7    6 000120D0 EdpCredentialExists
8    7 00011F80 EdpCredentialQuery
9    8 00012D80 EdpDecontainerizeFile
10    9 000127A0 EdpDplPolicyEnabledForUser
11    A 000127B0 EdpDplStartCredServiceIfDplEnabledForUser
12    B 00012700 EdpDplUpgradePinInfo
13    C 00012730 EdpDplUpgradeVerifyUser
14    D 00012760 EdpDplUserCredentialsSet
15    E 00012790 EdpDplUserUnlockComplete
16    F 00012790 EdpDplUserUnlockStart
17   10 00012260 EdpFree
18   11 00012D60 EdpGetContainerIdentity
19   12 00012690 EdpGetCredServiceState
20   13 00012EE0 EdpIsConsumerDataProtectionEnforced
21   14 00012ED0 EdpIsConsumerDataProtectionSupported
22   15 00012DE0 EdpPurgeAppLearningEvents
23   16 00012830 EdpQueryCredServiceInfo
24   17 00012240 EdpQueryDplEnforcedPolicyOwnerIds
25   18 00012220 EdpQueryRevokedPolicyOwnerIds
26   19 00012D20 EdpRmsClearKeys
27   1A 00012A70 EdpSetCredServiceInfo
28   1B 00012DC0 EdpUnprotectFile
29   1C 00012DF0 EdpWriteLogSiteLearningEvents
30   1D 00010C40 EfsClientCloseFileRaw
31   1E 00012E00 EfsClientCopyFileRaw
32   1F 000108F0 EfsClientDecryptFile
33   20 00011320 EfsClientDuplicateEncryptionInfo
34   21 000107D0 EfsClientEncryptFileEx
35   22 000109C0 EfsClientFileEncryptionStatus
36   23 000116C0 EfsClientFreeKeyInfo
37   24 00011240 EfsClientFreeProtectorList
38   25 00011720 EfsClientGetEncryptedFileVersion
39   26 000115F0 EfsClientGetKeyInfo
40   27 00010A50 EfsClientOpenFileRaw
41   28 00010FE0 EfsClientQueryProtectors
42   29 00010B90 EfsClientReadFileRaw
43   2A 00010BB0 EfsClientWriteFileRaw
44   2B 00010BF0 EfsClientWriteFileWithHeaderRaw
45   2C 00012E30 EfsReprotectFile
46   2D          EfsUtilGetCurrentKey (forwarded to efsutil._EfsUtilGetCurrentKey_Deprecated@16)
47   2E 000130D0 EfsValidateTokenForConsumer
48   2F 00012F10 EfsValidateUserForConsumer
49   30 00012D00 FeClClearCaches
50   31 00012C70 FeClQueryInfo
51   32 00010710 FeClientInitialize
52   33 00012540 GetLockSessionUnwrappedKey
53   34 000123E0 GetLockSessionWrappedKey
54   35 00012E10 OefsCheckSupport

Información avanzada sobre funciones que tiene la dll feclient.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\feclient.dll

File Type: DLL

  Section contains the following exports for FeClient.dll

    00000000 characteristics
    C27ED45B time date stamp
        0.00 version
           1 ordinal base
          54 number of functions
          54 number of names

    ordinal hint RVA      name

          1    0 000133A0 DpQueryUserProtectorDescriptor
          2    1 000135E0 DpQueryUserProtectorDescriptorInfo
          3    2 00012DA0 EdpAllowFileAccessForProcess
          4    3 00012D30 EdpContainerizeFile
          5    4 00011E30 EdpCredentialCreate
          6    5 000121F0 EdpCredentialDelete
          7    6 000120D0 EdpCredentialExists
          8    7 00011F80 EdpCredentialQuery
          9    8 00012D80 EdpDecontainerizeFile
         10    9 000127A0 EdpDplPolicyEnabledForUser
         11    A 000127B0 EdpDplStartCredServiceIfDplEnabledForUser
         12    B 00012700 EdpDplUpgradePinInfo
         13    C 00012730 EdpDplUpgradeVerifyUser
         14    D 00012760 EdpDplUserCredentialsSet
         15    E 00012790 EdpDplUserUnlockComplete
         16    F 00012790 EdpDplUserUnlockStart
         17   10 00012260 EdpFree
         18   11 00012D60 EdpGetContainerIdentity
         19   12 00012690 EdpGetCredServiceState
         20   13 00012EE0 EdpIsConsumerDataProtectionEnforced
         21   14 00012ED0 EdpIsConsumerDataProtectionSupported
         22   15 00012DE0 EdpPurgeAppLearningEvents
         23   16 00012830 EdpQueryCredServiceInfo
         24   17 00012240 EdpQueryDplEnforcedPolicyOwnerIds
         25   18 00012220 EdpQueryRevokedPolicyOwnerIds
         26   19 00012D20 EdpRmsClearKeys
         27   1A 00012A70 EdpSetCredServiceInfo
         28   1B 00012DC0 EdpUnprotectFile
         29   1C 00012DF0 EdpWriteLogSiteLearningEvents
         30   1D 00010C40 EfsClientCloseFileRaw
         31   1E 00012E00 EfsClientCopyFileRaw
         32   1F 000108F0 EfsClientDecryptFile
         33   20 00011320 EfsClientDuplicateEncryptionInfo
         34   21 000107D0 EfsClientEncryptFileEx
         35   22 000109C0 EfsClientFileEncryptionStatus
         36   23 000116C0 EfsClientFreeKeyInfo
         37   24 00011240 EfsClientFreeProtectorList
         38   25 00011720 EfsClientGetEncryptedFileVersion
         39   26 000115F0 EfsClientGetKeyInfo
         40   27 00010A50 EfsClientOpenFileRaw
         41   28 00010FE0 EfsClientQueryProtectors
         42   29 00010B90 EfsClientReadFileRaw
         43   2A 00010BB0 EfsClientWriteFileRaw
         44   2B 00010BF0 EfsClientWriteFileWithHeaderRaw
         45   2C 00012E30 EfsReprotectFile
         46   2D          EfsUtilGetCurrentKey (forwarded to efsutil._EfsUtilGetCurrentKey_Deprecated@16)
         47   2E 000130D0 EfsValidateTokenForConsumer
         48   2F 00012F10 EfsValidateUserForConsumer
         49   30 00012D00 FeClClearCaches
         50   31 00012C70 FeClQueryInfo
         51   32 00010710 FeClientInitialize
         52   33 00012540 GetLockSessionUnwrappedKey
         53   34 000123E0 GetLockSessionWrappedKey
         54   35 00012E10 OefsCheckSupport

  Summary

        2000 .data
        1000 .didat
        2000 .pdata
       10000 .rdata
        1000 .reloc
        1000 .rsrc
       2B000 .text

Integridad de la dll feclient.dll



Algorithm       Hash                                                                   Path                                         
---------       ----                                                                   ----                                         
SHA256          A5BD0D33940328C60D50F05F387E8CEF277F596F2D96935471568D820F807727       C:\Windows\System32\feclient.dll             


Detalles sobre el fichero dll feclient.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\feclient.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : feclient.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\feclient.dll
                    InternalName:     FECLIENT.DLL
                    OriginalFilename: FECLIENT.DLL
                    FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
                    FileDescription:  Windows NT File Encryption Client Interfaces
                    Product:          Microsoft® Windows® Operating System
                    ProductVersion:   10.0.19041.1
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Inglés (Estados Unidos)
                    
BaseName          : feclient
Target            : {C:\Windows\WinSxS\amd64_microsoft-windows-feclient_31bf3856ad364e35_10.0.19041.1_none_74cb1eaef6f25b5b\feclient
                    .dll}
LinkType          : HardLink
Name              : feclient.dll
Length            : 252416
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\feclient.dll
Extension         : .dll
CreationTime      : 07/12/2019 10:08:52
CreationTimeUtc   : 07/12/2019 9:08:52
LastAccessTime    : 03/12/2020 10:41:59
LastAccessTimeUtc : 03/12/2020 9:41:59
LastWriteTime     : 07/12/2019 10:08:52
LastWriteTimeUtc  : 07/12/2019 9:08:52
Attributes        : Archive



Procesos que utilizan la dll feclient.dll


svchost