realsched.exe
RealPlayer (32-bit) by RealNetworks (Signed)
Warning 27 antivirus scanners has detected malware in various versions of realsched.exe.
Overview
There are 18 versions of realsched.exe in the wild, the latest version being 16.0.3.51. realsched.exe is run as a standard windows process with the logged in user's account privileges. During installation, a run registry key for all users is added that will cause the program to run each time any user logs on to Windows. The average file size is about 253.63 KB. The file is a digitally signed and issued to RealNetworks by Thawte. Some variations of the file have been seen to be installed with the program RealPlayer from RealNetworks, Inc.. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 2.22 MB. Addionally, typically read and write I/O disk operations is about 5.24 KB per minute for reads and 36 Bytes per minute for writes.
What is realsched.exe?
RealNetworks Scheduler
RealUpgrade Launcher is part of RealPlayer, by RealNetworks, a cross-platform software product primarily used for the playing of recorded media. The media player is compatible with numerous formats within the multimedia realm, including MP3, MPEG-4, QuickTime, Windows Media, and multiple proprietary versions of RealAudio and RealVideo formats.
About realsched.exe (from RealNetworks)
“Real brings you RealPlayer, the only solution you’ll need for managing all your music and videos. It’s the best free media player around for enjoying all types of entertainment! You can also transfer ”
Details |
File name: | realsched.exe |
Publisher: | RealNetworks, Inc. |
Product name: | RealPlayer (32-bit) |
Description: | RealNetworks Scheduler |
Typical file path: | C:\Program Files\real\realplayer\update\realsched.exe |
Certificate |
Issued to: | RealNetworks |
Authority (CA): | Thawte |
Effective date: | Sunday, August 15, 2010 |
Expiration date: | Tuesday, August 16, 2011 |
Programs installed in
(Note, the programs listed below are for all versions of RealPlayer (32-bit) .)
RealPlayer is a cross-platform software product primarily used for the playing of recorded media. The media player is compatible with numerous formats within the multimedia realm, including MP3, MPEG-...
Behaviors
(Note, the behaviors below are for all versions of realsched.exe, select a unique version for details.)
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'TkBellExe' → "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
- Handler name 'RPPlayMediaOnArrival'
- Handler name 'RPPlayDVDMovieOnArrival'
- Handler name 'RPPlayCDAudioOnArrival'
- Handler name 'RPDVDBurningOnArrival'
- Handler name 'RPDeviceOnArrival'
Scheduled tasks
- The job 'RealCreateProcessScheduledTask7880094S-1-5-21-2355705715-2703073010-2366679147-1000' runs on registration in the path '\RealCreateProcessScheduledTask7880094S-1-5-21-2355705715-2703073010-2366679147-1000'
- The job 'RealCreateProcessScheduledTask90546427S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask90546427S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask8247866S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask8247866S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask7205342S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask7205342S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask56948664S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask56948664S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask425531072S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask425531072S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask41220690S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask41220690S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask408135057S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask408135057S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask3919119S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask3919119S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask361147400S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask361147400S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask343337421S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask343337421S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask341536093S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask341536093S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask336132281S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask336132281S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask333730708S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask333730708S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask310249453S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask310249453S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask303935063S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask303935063S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask291419212S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask291419212S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask28162922S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask28162922S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask2718301S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask2718301S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask2637462S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask2637462S-1-5-21-1484444706-205473755-680422138-1000'
- The task 'RealCreateProcessScheduledTask261177731S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask261177731S-1-5-21-1484444706-205473755-680422138-1000'
- The job 'RealCreateProcessScheduledTask208385667S-1-5-21-1484444706-205473755-680422138-1000' runs on registration in the path '\RealCreateProcessScheduledTask208385667S-1-5-21-1484444706-205473755-680422138-1000'
Malware detections
Based on 40+ industry antivirus scanners, 27 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
Avira AntiVir |
7.11.64.68 |
TR/Dropper.Gen |
0.1.1.868 |
avast! |
6.0.1289.0 |
Win32:Malware-gen |
0.1.1.868 |
AVG |
2014.0.3629 |
Dropper.Generic7.CCPG |
0.1.1.868 |
BitDefender |
7.2 |
Gen:Variant.Barys.290 |
0.1.1.868 |
Comodo Internet Security |
15850 |
Heur.Suspicious |
16.0.0.282 |
Comodo Internet Security |
17682 |
Heur.Suspicious |
16.0.1.18 |
Comodo Internet Security |
15518 |
UnclassifiedMalware |
0.1.1.868 |
Emsisoft Anti-Malware |
3.0.0.569 |
Gen:Variant.Barys.290 (B) |
0.1.1.868 |
ESET NOD32 |
7.8099 |
a variant of MSIL/Injector.AFM |
0.1.1.868 |
Fortinet |
5.0.43.0 |
MSIL/Kryptik.GVV!tr |
0.1.1.868 |
F-Secure |
11.0.19020.35 |
Gen:Variant.Barys.290 |
0.1.1.868 |
G Data |
13.10.22 |
Gen:Variant.Barys.290 |
0.1.1.868 |
Ikarus |
T3.1.4.0.0 |
VirTool.MSIL |
0.1.1.868 |
Jiangmin |
16.0.100 |
Trojan/Generic.aiocv |
0.1.1.868 |
Kaspersky |
9.0.0.837 |
HEUR:Trojan.Win32.Generic |
0.1.1.868 |
Kingsoft |
2013.1.8.219 |
Win32.Troj.Undef.(kcloud) |
0.1.1.868 |
McAfee |
5.400.1158 |
Suspicious Resource!msil |
0.1.1.868 |
McAfee Gateway Anti-Malware |
v2012.1-dat |
Artemis!79BFEE40D13A |
0.1.1.868 |
Microsoft Security Essentials |
1.9203.0 |
VirTool:MSIL/Injector.CT |
0.1.1.868 |
eScan by MicroWorld |
12.0.250.0 |
Gen:Variant.Barys.290 |
0.1.1.868 |
Norman |
7.00.22 |
Troj_Generic.IHISF |
0.1.1.868 |
Panda Antivirus |
10.0.3.5 |
Trj/CI.A |
0.1.1.868 |
PC Tools |
9.0.0.2 |
HeurEngine.ZeroDayThreat |
0.1.1.868 |
Rising Antivirus |
24.52.04.01 |
Trojan.Win32.Generic.142A2C74 |
0.1.1.868 |
Sophos |
4.86.0 |
Mal/Generic-S |
0.1.1.868 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.R47H1C8 |
0.1.1.868 |
VIPRE Antivirus |
15956 |
Trojan.Win32.Generic!BT |
0.1.1.868 |
All file variations of realsched.exe
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
25.10% |
|
Windows 7 Home Premium |
19.77% |
|
Microsoft Windows XP |
14.07% |
|
Windows 7 Home Basic |
12.17% |
|
Windows Vista Home Premium |
6.46% |
|
Windows 7 Professional |
6.08% |
|
Windows 7 Ultimate N |
3.80% |
|
Windows XP Professional |
3.42% |
|
Windows 8 |
3.04% |
|
Windows 8 Pro |
2.28% |
|
Windows Vista Home Basic |
1.52% |
|
Windows 8 Enterprise |
0.76% |
|
Windows 8 Single Language |
0.76% |
|
Windows Vista Ultimate |
0.38% |
|
Windows 8 Pro with Media Center |
0.38% |
|
Distribution by country
United States installs about 33.33% of RealPlayer (32-bit) .
Distribution by PC manufacturer
PC Manufacturer | distribution |
Toshiba |
36.44% |
|
Dell |
16.00% |
|
Hewlett-Packard |
11.11% |
|
Acer |
11.11% |
|
Sony |
10.67% |
|
ASUS |
3.56% |
|
Intel |
3.56% |
|
Lenovo |
2.67% |
|
GIGABYTE |
2.22% |
|
Samsung |
1.33% |
|
Compaq |
0.89% |
|
American Megatrends |
0.44% |
|