RtkAudioService.exe

Realtek Audio Service

Realtek Semiconductor

The executable RtkAudioService.exe has been detected as malware by 29 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
Publisher:
Realtek Semiconductor

Product:
Realtek Audio Service

Version:
1, 0, 0, 19

MD5:
e16f2fb6c4a61f42b973d254dcd89af5

SHA-1:
55c6dce2cee2e25179843e58b51a672dd4f3da9d

SHA-256:
e35e0433298b09ec8ea90f137f7e7b9629bcb2efdb795a2b539271a049db85e3

Scanner detections:
29 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/16/2024 11:50:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
928

Agnitum Outpost
Win32.Sality.AP.Gen
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.07.22

Avira AntiVirus
W32/Sality.AG
7.11.30.172

avast!
Win32:Kukacka
140617-1

AVG
Win32/Sality
2014.0.3986

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.14722

Bitdefender
Win32.Sality.3
1.0.20.1015

Comodo Security
Virus.Win32.Sality.Gen
18930

Dr.Web
Win32.Sector.21
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
8.14.07.22.01

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

G Data
Win32.Sality
14.7.24

IKARUS anti.virus
Virus.Win32.Heur
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.181.12795

Kaspersky
Virus.Win32.Sality
15.0.0.494

Microsoft Security Essentials
Threat.Undefined
1.179.723.0

MicroWorld eScan
Win32.Sality.3
15.0.0.609

NANO AntiVirus
Virus.Win32.Sality.yusp
0.28.2.60990

Norman
Sality.ZHB
11.20140722

nProtect
Virus/W32.Sality.D
14.07.21.01

Panda Antivirus
W32/Sality.AA
14.07.22.01

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.U
7.14.14.00

Total Defense
Win32/Sality.AA
37.0.11073

Trend Micro House Call
PE_SALITY.RL
7.2.203

Trend Micro
PE_SALITY.RL
10.465.22

VIPRE Antivirus
Threat.4721115
31208

File size:
194.6 KB (199,272 bytes)

Product version:
1, 0, 0, 19

Copyright:
2009 (c) Realtek Semiconductor. All rights reserved.

Original file name:
RtkAudioService.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Taiwanese)

Common path:
C:\Program Files\realtek\audio\drivers\wdm\rtkaudioservice.exe

File PE Metadata
Compilation timestamp:
3/17/2009 7:07:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
3072:Rzwun1AbCdoJcBkmUWBMjM5ZX8bME87vhJHAMUxvWoHLLdeit:5wS+bbcBaWBLDnwVoqdXt

Entry address:
0x88B1

Entry point:
60, 12, DC, 31, DE, 69, F7, 13, 88, A5, 7D, 81, D7, 83, C8, 2C, 5B, 38, F0, 81, E7, 58, 63, F5, D4, 8A, DE, F7, C5, 62, 17, B2, DD, 81, C2, FE, A4, 00, 00, 80, D5, 7D, 8A, E7, 10, DF, 81, EA, 3D, 1D, 00, 00, 8B, EF, 57, 8B, F0, C6, C7, EB, 85, CD, 1A, F8, 53, 0F, B7, F1, 69, CE, D9, 97, 73, D7, E8, 5E, 00, 00, 00, 0F, AF, D0, 81, F9, 5F, 95, 00, 00, 78, 02, 84, F3, 0F, AF, F8, 88, EF, 0F, B7, C5, 43, 68, 5D, 4C, 00, 00, 4E, 5F, 0F, BE, C3, F2, C7, C3, 1A, 2F, FA, 03, 81, EF, F3, 0E, 00, 00, 01, F0, 8D, 2F...
 
[+]

Code size:
88 KB (90,112 bytes)

Remove RtkAudioService.exe - Powered by Reason Core Security