tapinstall.exe

Windows Setup API

Optimal Software s.r.o.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application tapinstall.exe, “Windows Setup API” by Optimal Software s.r.o has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Optimal Software s.r.o.)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.1.7600.16385 (win7_wdk.100208-1538)

MD5:
285a92f169a4505f6b7fa85988b3eefb

SHA-1:
2f15ea0c4830ab346c107932aaf1218f18a4c173

SHA-256:
bf5089cece7dc654d1d1d7ab0c41b2eaef42b5a8d1dc4bacf81db879d6e6995b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 5:45:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Speedchecker.OptimalS.Installer.Meta (L)
16.6.10.12

File size:
83 KB (85,024 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wifi protector\openvpn\bin\tapinstall.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/29/2014 3:00:00 AM

Valid to:
10/30/2015 2:59:59 AM

Subject:
CN=Optimal Software s.r.o., O=Optimal Software s.r.o., STREET=Jablunkovska 2014/40a, L=Cesky Tesin, S=Cesky Tesin, PostalCode=73701, C=CZ

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
50C21E22FC95CC7EFFB6E44F30CE0384

File PE Metadata
Compilation timestamp:
2/9/2010 6:31:47 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
768:3PrhT5+KybRpnE8K74kca7NerB8iXpYmRRXvdi82BSOe9oKSJ2SLD0BEZWkAmhZ+:L+KY04RMmSCYmBiF4O7WTmho

Entry address:
0x6454

Entry point:
E8, 28, 06, 00, 00, E9, C3, FD, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 84, 11, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, E0, 11, 00, 01, CC, CC, CC, CC, CC, 3B, 0D, B0, 81, 00, 01, 75, 03, C2, 00, 00, E9, 8C, 06, 00, 00, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, CC, CC, CC, CC, FF, 25, 88, 11, 00, 01, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
5.3236

Code size:
27 KB (27,648 bytes)

Remove tapinstall.exe - Powered by Reason Core Security