wpsapi.dll

Optimal Software s.r.o.

The module wpsapi.dll by Optimal Software s.r.o has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Optimal Software s.r.o.  (signed and verified)

MD5:
6053d86bd61e00989f060a165fa0e15e

SHA-1:
2e250304d7675d05251ba8ba6f543c4bc3f302e0

SHA-256:
38b108bb3b3be9b1a717ba7ac0327661e11c06ad7c544716cd00275b16bbe149

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 4:24:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Speedchecker.OptimalS.Meta (L)
16.6.10.12

File size:
1.2 MB (1,224,936 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\pc speed up\wpsapi.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/11/2015 2:00:00 AM

Valid to:
5/11/2016 1:59:59 AM

Subject:
CN=Optimal Software s.r.o., OU=Optimal Software s.r.o., O=Optimal Software s.r.o., STREET=Jablunkovksá 2014/40a, L=Český Těšín, S=MS, PostalCode=73701, C=CZ

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DE52000CC87F2CDEAE54899FBF253D03

File PE Metadata
Compilation timestamp:
3/6/2014 11:10:33 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:cOXEZnhEd/cY4t3cqg9A/QS+IMTQPe49yZMSC:cOungcY4hcV9A/QSPjy+

Entry address:
0xA8838

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 27, 7C, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 4C, 8B, DC, 4D, 89, 43, 18, 4D, 89, 4B, 20, 48, 83, EC, 38, 49, 8D, 43, 20, 45, 33, C9, 49, 89, 43, E8, E8, 4D, 8E, 00, 00, 48, 83, C4, 38, C3, 33, D2, 44, 8D, 42, 0A, E9, A1, 90, 00, 00, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 83, CF, FF, 48, 8B, D9...
 
[+]

Code size:
827.5 KB (847,360 bytes)

Remove wpsapi.dll - Powered by Reason Core Security