RTHDCPL.EXE

Realtek HD Audio Sound Effect Manager

Realtek Semiconductor Corp

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RTHDCPL’.
Publisher:
Realtek Semiconductor Corp.  (signed by Realtek Semiconductor Corp)

Product:
Realtek HD Audio Sound Effect Manager

Description:
Realtek HD Audio Control Panel

Version:
2.3.4.9

MD5:
4a39132bc9d69eec076b92fbd20522cc

SHA-1:
d5e3e114bf84a91cc97c3e1ed5e2b8287b39e8ce

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:19:48 AM UTC  (today)

File size:
18.6 MB (19,523,616 bytes)

Product version:
2.3.4.9

Copyright:
Copyright (c) 2010 Realtek Semiconductor Corp.

Original file name:
RTHDCPL.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\rthdcpl.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/15/2007 5:30:00 AM

Valid to:
6/12/2010 5:29:59 AM

Subject:
CN=Realtek Semiconductor Corp, OU=RTCN, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Realtek Semiconductor Corp, L=Hsinchu, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E6DDC87375082845814F442D1D82A25

File PE Metadata
Compilation timestamp:
4/20/2010 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

Entry address:
0x1A7C

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 98, F0, 64, 00, A1, 8B, F0, 64, 00, C1, E0, 02, A3, 8F, F0, 64, 00, 52, 6A, 00, E8, AD, C3, 24, 00, 8B, D0, E8, 46, 57, 1D, 00, 5A, E8, A4, 56, 1D, 00, E8, 7B, 57, 1D, 00, 6A, 00, E8, 00, 6D, 1D, 00, 59, 68, 34, F0, 64, 00, 6A, 00, E8, 87, C3, 24, 00, A3, 93, F0, 64, 00, 6A, 00, E9, 7F, D7, 1D, 00, E9, 2E, 6D, 1D, 00, 33, C0, A0, 7D, F0, 64, 00, C3, A1, 93, F0, 64, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, B4, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
7.3369

Code size:
2.3 MB (2,416,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RTHDCPL

Command:
rthdcpl.exe


Scan RTHDCPL.EXE - Powered by Reason Core Security