ravcpl64.exe

Диспетчер Realtek HD

Realtek Semiconductor Corp

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RtHDVCpl’.
Publisher:
Realtek Semiconductor  (signed by Realtek Semiconductor Corp)

Product:
Диспетчер Realtek HD

Version:
1, 0, 0, 537

MD5:
111b311cff5fa8fc48c32fbec2a8783a

SHA-1:
9c67f41d7d48a4b789360aa05e6e9b399e025c2a

SHA-256:
f06830359f11515ba1ca5ec061f5b254e5a4676fbec8afac23b56bb413b7e63f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 9:27:34 AM UTC  (today)

File size:
10.4 MB (10,920,552 bytes)

Product version:
1, 0, 0, 537

Copyright:
2010 (c) Realtek Semiconductor. All rights reserved.

Original file name:
RtHDVCpl.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\realtek\audio\hda\ravcpl64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2010 2:00:00 AM

Valid to:
6/11/2013 2:59:59 AM

Subject:
CN=Realtek Semiconductor Corp, OU=RTCN, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Realtek Semiconductor Corp, L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
60E1245038BCDCB76283B7D22BCBCA92

File PE Metadata
Compilation timestamp:
6/22/2010 11:54:12 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:pX0rtfV39BdZeGHVxYeVA8LsKv2ZwmIRrimtslQnOMCToaLGJxB0CaaRGSOF:sfrBdZYeFT3Ymt2SOHTHaxNa/

Entry address:
0x2388B0

Entry point:
48, 83, EC, 28, E8, 77, B6, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 3B, 0D, C9, 58, 0F, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, F1, B6, 00, 00, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8D, 05, 17, B8, 03, 00, 8B, DA, 48, 8B, F9, 48, 89, 01, E8, 22, B8, 00, 00, F6, C3, 01, 74, 08, 48, 8B, CF, E8, 65, 59, FC, FF, 48, 8B, C7, 48, 8B...
 
[+]

Code size:
2.4 MB (2,519,040 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RtHDVCpl

Command:
C:\Program Files\realtek\audio\hda\ravcpl64.exe -s


Scan ravcpl64.exe - Powered by Reason Core Security