tapiipc.exe

Sigbert Engelhardt

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SI-Local-Server’.
Publisher:
SECS  (signed by Sigbert Engelhardt)

Version:
1.0.0.0

MD5:
3ef788aa3425cbb7c18443c7602f0c00

SHA-1:
80a110e153f854afff16ebe764f7cd509a57e94b

SHA-256:
cfeebc82fb8bfa04cee39a80bc359f4fe5ad0fbb458c106d494dd4415a216847

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 7:22:59 AM UTC  (today)

File size:
1.7 MB (1,752,712 bytes)

Product version:
1.0.0.0

Copyright:
Sigbert Engelhardt

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\si-local-server\tapiipc.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
8/31/2012 4:13:27 AM

Valid to:
9/1/2014 4:27:36 AM

Subject:
E=md5@se-cs.de, CN=Sigbert Engelhardt, L=Hundeshagen, S=Thuringen, C=DE, Description=Mna075a8AtfPcZyh

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0721

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x13F280

Entry point:
55, 8B, EC, 83, C4, F4, 53, B8, 60, EB, 53, 00, E8, 9F, 84, EC, FF, 68, FC, F2, 53, 00, 6A, FF, 6A, 00, E8, 8D, 85, EC, FF, 8B, D8, 85, DB, 74, 4E, E8, C2, 86, EC, FF, 85, C0, 75, 45, A1, 70, 6C, 54, 00, 8B, 00, E8, CE, B6, F0, FF, A1, 70, 6C, 54, 00, 8B, 00, C6, 40, 43, 00, 8B, 0D, 44, 68, 54, 00, A1, 70, 6C, 54, 00, 8B, 00, 8B, 15, 1C, E7, 53, 00, E8, C3, B6, F0, FF, A1, 70, 6C, 54, 00, 8B, 00, E8, 37, B7, F0, FF, 85, DB, 74, 06, 53, E8, F9, 84, EC, FF, 5B, E8, 37, 49, EC, FF, 00, 00, 00, 7B, 35, 32, 45...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,303,552 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SI-Local-Server

Command:
"C:\Program Files\si-local-server\tapiipc.exe"


Scan tapiipc.exe - Powered by Reason Core Security