ravcpl64.exe

Диспетчер Realtek HD

Realtek Semiconductor Corp

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RtHDVCpl’.
Publisher:
Realtek Semiconductor  (signed by Realtek Semiconductor Corp)

Product:
Диспетчер Realtek HD

Version:
1, 0, 0, 990

MD5:
e082712606fb6d2bc8d5525a133a305d

SHA-1:
1f37df385d6ec85f7dd59f99d3be257ee031563e

SHA-256:
c47809cd399ce2714b0103f62482d67b481aeb03063fa4129afea0b6786aa8bf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 5:50:10 AM UTC  (today)

File size:
15.7 MB (16,418,560 bytes)

Product version:
1, 0, 0, 990

Copyright:
2013 (c) Realtek Semiconductor. All rights reserved.

Original file name:
RtHDVCpl.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\realtek\audio\hda\ravcpl64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2013 3:00:00 AM

Valid to:
7/12/2016 2:59:59 AM

Subject:
CN=Realtek Semiconductor Corp, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Realtek Semiconductor Corp, L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
13222A5DCCF716DF5AF9C87084412DD9

File PE Metadata
Compilation timestamp:
1/12/2016 10:21:11 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:3n4LHRyeFT3Ymt2yOZTHaxRWcUC9QSRnb4aS:I79FTomtIuRWcUCySRE

Entry address:
0x227210

Entry point:
48, 83, EC, 28, E8, 27, 74, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8D, 05, 8F, 2F, 04, 00, 8B, DA, 48, 8B, F9, 48, 89, 01, E8, B2, 74, 00, 00, F6, C3, 01, 74, 08, 48, 8B, CF, E8, 65, 4B, FC, FF, 48, 8B, C7, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, C3, CC, CC, CC, CC, CC, CC, CC, 4C, 8D, 41, 11, 48, 83, C2, 11, 4C, 2B, C2, 66, 90, 66, 66, 90, 0F, B6, 0A, 42, 0F, B6, 04, 02, 2B, C8, 75, 08, 48, 83, C2, 01...
 
[+]

Code size:
2.4 MB (2,476,544 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RtHDVCpl

Command:
C:\Program Files\realtek\audio\hda\ravcpl64.exe -s


Scan ravcpl64.exe - Powered by Reason Core Security