rthdvbg.exe

HD Audio Background Process

Realtek Semiconductor

The executable rthdvbg.exe has been detected as malware by 34 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
Realtek Semiconductor

Product:
HD Audio Background Process

Version:
1, 0, 0, 180

MD5:
2cab8c1acb4b6e81e4cf33182ebc4e59

SHA-1:
ddb48c89d4bd78ee23c76d5c3bc4b22d6cff9758

SHA-256:
c3058be017500a15a82c70fe515c357693b9190e4acbc458d3786a763c6865df

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 10:06:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
838

Agnitum Outpost
Win32.Sality.FA.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.10.20

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:Sality
141003-0

AVG
Win32/Sality
2014.0.4040

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.141019

Bitdefender
Win32.Sality.3
1.0.20.1460

Bkav FE
W32.Sality.PE
1.3.0.4959

Dr.Web
Win32.Sector.22
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
14.10.19

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
11.2014-19-10_1

G Data
Win32.Sality
14.10.24

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.7.8.0

K7 AntiVirus
Virus
13.184.13727

Kaspersky
Virus.Win32.Sality
15.0.0.494

McAfee
W32/Sality.gen.z
5600.6972

Microsoft Security Essentials
Threat.Undefined
1.185.3705.0

MicroWorld eScan
Win32.Sality.3
15.0.0.876

NANO AntiVirus
Virus.Win32.Sality.yusp
0.28.2.62671

Norman
Sality.ZHB
11.20141019

nProtect
Win32.Sality.3
14.10.19.01

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.U
10.14.14.00

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.11237

Trend Micro House Call
PE_SALITY.ER
7.2.292

Trend Micro
PE_SALITY.ER
10.465.19

Vba32 AntiVirus
Virus.Win32.Sality.bakb
3.12.26.3

VIPRE Antivirus
Threat.4734158
33706

ViRobot
Win32.Sality.N
2011.4.7.4223

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.1960

File size:
1 MB (1,087,344 bytes)

Product version:
1, 0, 0, 180

Copyright:
2013 (c) Realtek Semiconductor. All rights reserved.

Original file name:
RtHDVBgProc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\dp_sounds_realtek_14025\drp\forced\ntx86\7177\rthdvbg.exe

File PE Metadata
Compilation timestamp:
2/11/2014 10:34:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:MXd8OHJQ9woqfx/NeXFZ8+sOkk3EPDNG+TW0n/T+QNWmgrRw2y8:MXd8OHJQuleXFZ8+BVCA+p8

Entry address:
0x49C2F

Entry point:
0F, AF, EE, 68, C2, 9A, 08, 00, 55, 80, FA, 68, B3, 41, 1A, C8, C7, C7, 68, A6, 6B, 38, 8B, EF, 00, CB, 46, 55, F6, C2, 89, 58, 85, EF, 81, FA, D3, A0, 00, 00, 70, 05, BF, BE, 02, 7C, 51, 03, D0, 0F, CF, 87, FA, 72, 04, FF, CD, F7, D0, 3B, F7, 72, 02, 86, CD, 45, E8, 00, 00, 00, 00, 5A, 0F, 6E, D2, 03, C8, 81, F9, 56, 61, 00, 00, 73, 06, F7, D5, FF, CA, 86, E2, 81, FF, 32, CF, 00, 00, 74, 02, FF, C8, 84, D8, 8D, 0D, 74, E2, EC, F1, 84, D4, 51, 42, 5A, 52, 85, EE, 59, F6, C0, 8D, 4A, 51, 0F, AF, C1, 58, 50...
 
[+]

Entropy:
5.6273

Code size:
424 KB (434,176 bytes)

Remove rthdvbg.exe - Powered by Reason Core Security