Author Topic: Virus disguised as Realtek HD Audio - This might interest you!  (Read 23931 times)

0 Members and 1 Guest are viewing this topic.

Offline MegaTeam

  • Newbie
  • *
  • Posts: 8
Greetings to you dear Avast Community  :) as been said in the title, this topic might interest some of you.
Whats the story? since few days I have been facing constant lag on my windows 7, videos did not play smoothly, very annoying few days to be honest. I noticed a process called rthdcpl.exe (Realtek HD Audio) that was consuming 25% of my CPU "see attachment 1" if I end the process the lag goes away in an instant. But it always comes back after I believe the problem was solved.

So i thought I need to update the Realtek Audio driver from my motherboard site but it didn't help. The weird thing is the location of this rthdcpl.exe file which is not where the drivers get installed, the location is ( C:\Users\username\AppData\Local\Apple Computer\Realtek HD\rthdcpl.exe ) "see attachment 2". I noticed the installation date and time was very recent, on July 11th 10:15pm which is the same date and time I installed Zona the Russian torrent software and downloaded a game from it. I tried to open the rthdcpl.exe but nothing appears then I checked the config.xml from the same folder and found a short script that triggers an action after 4 days of the installation to execute the rthdcpl.exe file. In "attachment 3" you can see the script. So I deleted the xml file only and the rthdcpl.exe process didn't appear again.

P.S I ran Avast & Malwarebytes Anti-Malware and everything was clear.
Now I am worried what was the purpose of this file? In the few days it ran did it affect my PC? Do anyone know about this or faced this before? Can you explain the config.xml file script?
I am no expert by any means and your thoughts about the matter will be appreciated.
Thank you in advance  ;)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Virus disguised as Realtek HD Audio - This might interest you!
« Reply #1 on: July 19, 2016, 01:24:12 PM »
You can upload and check suspicious file(s) at > www.virustotal.com / www.metadefender.com / www.jotti.org
If scanned before, always click rescan for a fresh result

You may post link to scan result here



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Virus disguised as Realtek HD Audio - This might interest you!
« Reply #2 on: July 19, 2016, 01:25:20 PM »
If you need assistance, follow instructions here and attach requested logs > https://forum.avast.com/index.php?topic=53253.0



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699

Offline MegaTeam

  • Newbie
  • *
  • Posts: 8
Re: Virus disguised as Realtek HD Audio - This might interest you!
« Reply #5 on: July 19, 2016, 07:44:00 PM »
Already sent Avast the files, whats the next step? should I delete the files normally?