tapELDI.sys

TAP-Windows Virtual Network Driver

ByELDI Certificate

The file tapELDI.sys by ByELDI Certificate has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “KMS-Windows ELDI”.
Publisher:
The OpenVPN Project  (signed by ByELDI Certificate)

Product:
TAP-Windows Virtual Network Driver

Version:
9.9.2 9/9 built by: WinDDK

MD5:
8d9feee4d86de1b6d52dcf08c15f529f

SHA-1:
39f8a7d73ebe13433a9c6f79f8735e587c758b4c

SHA-256:
093a641e1accf893a786f9d8a152b733565aa6ca2d8ac14c02c0451dd4980a18

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 5:22:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ByELDICertificate.K
14.4.20.5

File size:
31.5 KB (32,272 bytes)

Product version:
9.9.2 9/9

Copyright:
OpenVPN Technologies, Inc.

Original file name:
tapELDI.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\tapeldi.sys

Digital Signature
Authority:
ByELDI Certificate

Valid from:
11/18/2013 5:55:17 AM

Valid to:
1/1/2040 6:59:59 AM

Subject:
CN=ByELDI Certificate

Issuer:
CN=ByELDI Certificate

Serial number:
4455572E3FD4538F44AC413F951D0311

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:JIOPCr6ghD8JTbbdDChKCfl4FUFqa0XFC1bRbq0FlCbBBhFuxHc:acCr6gYTbRDoRfi60a0XFC1UPvhFuxHc

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, C2, FD, FF, FF, CC, CC, 20, A3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 60, A5, 00, 00, 90, 70, 00, 00, 90, A2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 22, A7, 00, 00, 00, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 86, A5, 00, 00, 00, 00, 00, 00, 06, A7, 00, 00, 00, 00, 00, 00, EE, A6, 00, 00, 00, 00, 00, 00, D6, A6, 00, 00, 00, 00, 00, 00...
 
[+]

Driver
Display name:
KMS-Windows ELDI

Service name:
tapELDI

Type:
Kernel device driver (KernelDriver)


Remove tapELDI.sys - Powered by Reason Core Security