Arnold Butler - 1 day ago

Hello, I currently use VeraCrypt full disk encryption for Windows. I have experimented with using an encrypted volume within the C: on top of this in the past (although I currently do not have a volume set up - just basic full disk encryption).

Using sysinternals Sigcheck, I see that I have two VeraCrypt.exe root certificates installed on my computer. They are both signed. They both have the same name, the same signing date and time, the same publisher (IDRIX SARL), the same product/file version, and the same size. Neither of them are returning any warnings with VirusTotal.

The only difference is that one of them is located in C:\Program Files\VeraCrypt\VeraCrypt.exe and the other is located in C:\WINDOWS\system32\VeraCrypt.exe

Some questions:
1. Is it normal or expected to have duplicate Veracrypt certificates in these separate folders?
2. If not, what could have caused this, and what potential threat (if any) does this pose?
3. If not, what should I do? Should I delete one of them (if so, which one and how)?

Thank you for this amazing software and all your work on it!

 

Last edit: Arnold Butler 1 day ago