rnupgagent.exe
RealNetworks Installer (32-bit) by RealNetworks (Signed)
Warning 4 antivirus scanners has detected malware in various versions of rnupgagent.exe.
Overview
rnupgagent.exe has 15 known versions, the most recent one is 10.6.0.33. rnupgagent.exe is run as a standard windows process with the logged in user's account privileges. The process utilizes the Windows Task Scheduler to automatically launch the file as a process when a user logs into Windows. The average file size is about 431.21 KB. It is an authenticode code-signed executable issued to RealNetworks by the certification authority Thawte. During the process's lifecycle, the typical CPU resource utilization is less than 0.01% with the maximum memory reaching around 11.43 MB.
What is rnupgagent.exe?
RealNetworks Installer is part of RealPlayer, by RealNetworks, a cross-platform software product primarily used for the playing of recorded media. The media player is compatible with numerous formats within the multimedia realm, including MP3, MPEG-4, QuickTime, Windows Media, and multiple proprietary versions of RealAudio and RealVideo formats.
Details |
File name: | rnupgagent.exe |
Publisher: | RealNetworks, Inc. |
Product name: | RealNetworks Installer (32-bit) |
Description: | RealNetworks Installer |
Typical file path: | C:\users\user\appdata\roaming\real\update\upgradehelper\realplayer\10.20\agent\rnupgagent.exe |
Original name: | rnsetup.EXE |
Certificate |
Issued to: | RealNetworks |
Authority (CA): | Thawte |
Effective date: | Tuesday, March 8, 2011 |
Behaviors
(Note, the behaviors below are for all versions of rnupgagent.exe, select a unique version for details.)
Scheduled tasks
- The task 'ReclaimerUpdateFiles_harlyson' runs daily in the path '\ReclaimerUpdateFiles_harlyson'
- The task 'RNUpgradeHelperResumePrompt_Pluto' in the path '\RNUpgradeHelperResumePrompt_Pluto'
- The task 'RNUpgradeHelperResumePrompt_WIZARD' in the path '\RNUpgradeHelperResumePrompt_WIZARD'
- The job 'RNUpgradeHelperLogonPrompt_WIZARD' runs on logon in the path '\RNUpgradeHelperLogonPrompt_WIZARD'
- The task 'ReclaimerUpdateXML_WIZARD' runs daily in the path '\ReclaimerUpdateXML_WIZARD'
- The job 'ReclaimerUpdateFiles_WIZARD' runs daily in the path '\ReclaimerUpdateFiles_WIZARD'
- The job 'RNUpgradeHelperResumePrompt_Owner' in the path '\RNUpgradeHelperResumePrompt_Owner'
- The task 'RNUpgradeHelperLogonPrompt_Owner' runs on logon in the path '\RNUpgradeHelperLogonPrompt_Owner'
- The job 'ReclaimerUpdateFiles_Robert' runs daily in the path '\ReclaimerUpdateFiles_Robert'
- The job 'ReclaimerUpdateFiles_owner' runs daily in the path '\ReclaimerUpdateFiles_owner'
- The job 'ReclaimerResumeInstall_stacey jackson' runs in the path 'C:\WINDOWS\Tasks\ReclaimerResumeInstall_stacey jackson.job'
- The task 'ReclaimerResumeInstall_HP_Administrator' runs in the path 'C:\WINDOWS\Tasks\ReclaimerResumeInstall_HP_Administrator.job'
- The job 'ReclaimerUpdateXML_Owner' runs daily in the path '\ReclaimerUpdateXML_Owner'
- The job 'RNUpgradeHelperResumePrompt_THE KING' in the path '\RNUpgradeHelperResumePrompt_THE KING'
- The task 'RNUpgradeHelperLogonPrompt_THE KING' runs on logon in the path '\RNUpgradeHelperLogonPrompt_THE KING'
- The job 'ReclaimerUpdateXML_THE KING' runs daily in the path '\ReclaimerUpdateXML_THE KING'
- The task 'ReclaimerUpdateFiles_THE KING' runs daily in the path '\ReclaimerUpdateFiles_THE KING'
- The task 'RNUpgradeHelperResumePrompt_Toshiba' in the path '\RNUpgradeHelperResumePrompt_Toshiba'
- The job 'RNUpgradeHelperLogonPrompt_Toshiba' runs on logon in the path '\RNUpgradeHelperLogonPrompt_Toshiba'
- The task 'ReclaimerUpdateXML_Toshiba' runs daily in the path '\ReclaimerUpdateXML_Toshiba'
- The job 'ReclaimerUpdateFiles_Toshiba' runs daily in the path '\ReclaimerUpdateFiles_Toshiba'
- The task 'ReclaimerUpdateFiles_Central Command' runs daily in the path '\ReclaimerUpdateFiles_Central Command'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
- Login entry path '\RNUpgradeHelperLogonPrompt_WIZARD'
- Login entry path '\RNUpgradeHelperLogonPrompt_Owner'
- Login entry path '\RNUpgradeHelperLogonPrompt_THE KING'
- Login entry path '\RNUpgradeHelperLogonPrompt_Toshiba'
- Login entry path '\RNUpgradeHelperLogonPrompt_lakay'
- Login entry path '\RNUpgradeHelperLogonPrompt_DELL'
- Login entry path '\RNUpgradeHelperLogonPrompt_Fujitsu'
- Login entry path '\RNUpgradeHelperLogonPrompt_G'
- Login entry path '\RNUpgradeHelperLogonPrompt_Terry'
- Login entry path '\RNUpgradeHelperLogonPrompt_allan'
- Login entry path 'C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_XXXX.job'
- Login entry path '\RNUpgradeHelperLogonPrompt_Bev'
- Login entry path '\RNUpgradeHelperLogonPrompt_Azzoza'
- Login entry path '\RNUpgradeHelperLogonPrompt_Michael'
- Login entry path 'C:\WINDOWS\Tasks\ReclaimerResumeInstallLogin_Administrator.job'
- Login entry path '\RNUpgradeHelperLogonPrompt_j'
- Login entry path 'C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_Owner.job'
- Login entry path '\RNUpgradeHelperLogonPrompt_ABDULAI'
- Login entry path '\RNUpgradeHelperLogonPrompt_Dr Ayman Elnemr'
- Login entry path '\RNUpgradeHelperLogonPrompt_Keonaona'
- Login entry path '\RNUpgradeHelperLogonPrompt_user'
- Login entry path '\RNUpgradeHelperLogonPrompt_Ola'
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
NANO AntiVirus |
0.22.6.49175 |
Trojan.Win32.Siggen.bbvqtf |
10.0.0.100 |
NANO AntiVirus |
0.20.4.48163 |
Trojan.Win32.Agent2.bbwggf |
10.0.0.100 |
The Hacker |
None |
Trojan/Agent.bjvu |
10.0.0.100 |
The Hacker |
None |
Trojan/Agent.bjvu |
10.0.0.100 |
All file variations of rnupgagent.exe
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
26.71% |
|
Windows 7 Home Premium |
25.47% |
|
Windows Vista Home Premium |
14.29% |
|
Microsoft Windows XP |
13.04% |
|
Windows 7 Professional |
9.94% |
|
Windows 8 Single Language |
3.11% |
|
Windows 7 Home Basic |
3.11% |
|
Windows 8 Pro with Media Center |
3.11% |
|
Windows 8 Pro |
0.62% |
|
Windows 7 Starter |
0.62% |
|
Distribution by country
United States installs about 39.75% of RealNetworks Installer (32-bit) .
Distribution by PC manufacturer
PC Manufacturer | distribution |
Toshiba |
33.60% |
|
Dell |
27.20% |
|
Hewlett-Packard |
21.60% |
|
Acer |
8.80% |
|
GIGABYTE |
4.00% |
|
Sony |
3.20% |
|
ASUS |
1.60% |
|