RtHDVCpl.exe

Realtek HD Audio Manager

Realtek Semiconductor Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RTHDVCPL’.
Publisher:
Realtek Semiconductor  (signed by Realtek Semiconductor Corp.)

Product:
Realtek HD Audio Manager

Version:
1, 0, 0, 1028

MD5:
db3d671c418f824365532a2f3a29ab15

SHA-1:
3a4bcc16d77db82e24b8c5112c80e4ce5d58fc00

SHA-256:
703ddce12770c453da2848b70c48e35384d7953df641fa3c054954b8a580ce4a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 2:31:14 PM UTC  (today)

File size:
14.3 MB (14,951,976 bytes)

Product version:
1, 0, 0, 1028

Copyright:
2016 (c) Realtek Semiconductor. All rights reserved.

Original file name:
RtHDVCpl.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\realtek\audio\hda\rthdvcpl.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/20/2016 6:00:00 PM

Valid to:
1/24/2019 6:00:00 AM

Subject:
CN=Realtek Semiconductor Corp., O=Realtek Semiconductor Corp., L=Hsinchu, S=Taiwan, C=TW, PostalCode=300, STREET="No. 2, Innovation Road II, Hsinchu Science Park", SERIALNUMBER=22671299, OID.1.3.6.1.4.1.311.60.2.1.3=TW, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A9997ACCB4B384C80E313DD2854407B

File PE Metadata
Compilation timestamp:
10/3/2016 3:56:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x1296A6

Entry point:
E8, 70, 65, 00, 00, E9, 17, FE, FF, FF, FF, 35, 60, 17, 5C, 00, E8, 35, 5F, 00, 00, 85, C0, 59, 74, 02, FF, D0, 6A, 19, E8, 6E, 53, 00, 00, 6A, 01, 6A, 00, E8, D0, 66, 00, 00, 83, C4, 0C, E9, D5, 65, 00, 00, 3B, 0D, 20, 67, 5B, 00, 75, 02, F3, C3, E9, E1, 66, 00, 00, 51, C7, 01, 74, 6D, 56, 00, E8, D9, 67, 00, 00, 59, C3, 56, 8B, F1, E8, EA, FF, FF, FF, F6, 44, 24, 08, 01, 74, 07, 56, E8, 73, 99, FD, FF, 59, 8B, C6, 5E, C2, 04, 00, 8B, 44, 24, 04, 83, C1, 09, 51, 83, C0, 09, 50, E8, 1C, 68, 00, 00, F7, D8...
 
[+]

Entropy:
7.2272

Code size:
1.4 MB (1,441,792 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RTHDVCPL

Command:
"C:\Program Files\realtek\audio\hda\rthdvcpl.exe" -s


Scan RtHDVCpl.exe - Powered by Reason Core Security