tapinstall.exe

Windows Setup API

Optimal Software s.r.o.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application tapinstall.exe, “Windows Setup API” by Optimal Software s.r.o has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Optimal Software s.r.o.)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.1.7600.16385 (win7_wdk.100208-1538)

MD5:
e7b3caaae5c40a9c08471f547d3678de

SHA-1:
9ac4e77d474db9d1e34855f0b908f5aef58eab5e

SHA-256:
7b03b7735ebef72202e6dde6a633503bbaca7b683dbca21ad88839cf61dcece5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 2:46:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Speedchecker.OptimalS.Installer.Meta (L)
16.6.10.12

File size:
84.7 KB (86,720 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wifi protector\openvpn\bin\tapinstall.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/31/2012 3:00:00 AM

Valid to:
11/5/2014 3:00:00 PM

Subject:
CN=Optimal Software s.r.o., O=Optimal Software s.r.o., L=Český Těšín, C=CZ

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09DA6E35288E3A0431B971129CCF387A

File PE Metadata
Compilation timestamp:
2/9/2010 6:31:47 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
768:3+rhT5+KybRpnE8K74kca7NerB8iXpYmRRXvdi82BSOe9oKSJ2SLD0BEZWkArj:A+KY04RMmSCYmBiF4O7WTH

Entry address:
0x6454

Entry point:
E8, 28, 06, 00, 00, E9, C3, FD, FF, FF, CC, CC, CC, CC, CC, CC, FF, 25, 84, 11, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, E0, 11, 00, 01, CC, CC, CC, CC, CC, 3B, 0D, B0, 81, 00, 01, 75, 03, C2, 00, 00, E9, 8C, 06, 00, 00, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, CC, CC, CC, CC, FF, 25, 88, 11, 00, 01, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
5.3429

Code size:
27 KB (27,648 bytes)

Remove tapinstall.exe - Powered by Reason Core Security