RtlService.exe
Realtek RtlService Application by Realtek Semiconductor
Version: | 700, 1007, 509, 2012 |
MD5: | 100817619f5ae04074d10427b3a7456a |
SHA1: | 5a664ad5875f485bb05c1c24ddcc04b68253d276 |
SHA256: | 90f50dd33d40091d3d0d6336e1bb15e40bdd8083d392db5c39ed15c1d23e978c |
Warning 3 antivirus scanners has detected malware.
Overview
rtlservice.exe is malware that runs as a service under the name RealtekCU with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including REALTEK Wireless LAN Driver published by Realtek Semiconductor Corp., REALTEK Wireless LAN Driver from Realtek Semiconductor Corp. and REALTEK Wireless LAN Driver by Realtek Semiconductor Corp.. This particular version is usually found on Windows 7 Ultimate (6.1.7601.65536).
Details
File name: | rtlservice.exe |
Publisher: | Realtek Semiconductor Corp. |
Product name: | Realtek RtlService Application |
Typical file path: | C:\Program Files\realtek\usb wireless lan utility\rtlservice.exe |
File version: | 700, 1007, 509, 2012 |
Size: | 36 KB (36,864 bytes) |
Digital DNA |
File packed: | No |
.NET CLR: | No |
More details
Programs
The following programs will install this file
This is the software driver and additional utilities required for managing and connecting the D-Link device to the computer. Uninstalling this driver may cause the hardware to stop functioning properly (only remove this package if you no longer have the networking device connected to your PC).
This is the software package that includes the required drivers, configuration and management utilities to support the netis Wireless LAN device.
This is the software package that includes the required drivers, configuration and management utilities to support the netis Wireless LAN device.
|
Realtek Semiconductor Corp. |
|
The REALTEK Wireless LAN Driver is the software driver for the Realtek Wireless LAN NICs. It is a program used to communicate from the Windows PC OS to the device. This software is required in most cases for the hardware device to function properly. In most cases, drivers come with Windows or can be found by going to Windows Update in Control Panel and checking for updates as well as downloaded from the Realtek support website.
|
Realtek Semiconductor Corp. |
|
The REALTEK Wireless LAN Driver is the software driver for the Realtek Wireless LAN NICs. It is a program used to communicate from the Windows PC OS to the device. This software is required in most cases for the hardware device to function properly. In most cases, drivers come with Windows or can be found by going to Windows Update in Control Panel and checking for updates as well as downloaded from the Realtek support website.
|
REALTEK Semiconductor Corp. |
|
This is the WiFi USB adapter N300 software driver and utilities required for managing and connecting the Sitecom networking device to the PC. Uninstalling this driver may cause the hardware to stop functioning properly (only remove this package if you no longer have the Sitecom networking device connected to your PC).
Behaviors
Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
Malware detections
Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engine | Engine version | Detection |
K7 AntiVirus |
9.174.10469 |
Trojan ( 0038e9931 ) |
K7GW |
9.174.10469 |
Trojan ( 0038e9931 ) |
Trend Micro HouseCall |
9.700-1001 |
TROJ_GEN.F47V0824 |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00005864% | |
Kernel CPU: | 0.00003464% | |
User CPU: | 0.00002401% | |
Kernel CPU time: | 203 ms/min | |
CPU cycles: | 146,824/sec | |
Memory |
Private memory: | 2.14 MB | |
Private (maximum): | 4.5 MB | |
Private (minimum): | 1.37 MB | |
Non-paged memory: | 2.14 MB | |
Virtual memory: | 37.34 MB | |
Virtual memory (peak): | 46.45 MB | |
Working set: | 1.38 MB | |
Working set (peak): | 4.73 MB | |
Page faults: | 31,491/min | |
I/O |
I/O read transfer: | 7 Bytes/sec | |
I/O read operations: | 1/sec | |
I/O write transfer: | 0 Bytes/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 2 Bytes/sec | |
I/O other operations: | 1/sec | |
Resource allocations |
Threads: | 4 | |
Handles: | 122 | |
Process properties
Threads
Averages
wow64.dll (Win32 Emulation on NT64 by Microsoft) |
Total CPU: | 0.00006954% | |
Kernel CPU: | 0.00003745% | |
User CPU: | 0.00003210% | |
CPU cycles: | 143,617/sec | |
Memory: | 252 KB | |
RtlService.exe (main module) |
Total CPU: | 0.00004280% | |
Kernel CPU: | 0.00003210% | |
User CPU: | 0.00001070% | |
CPU cycles: | 2,603/sec | |
Memory: | 40 KB | |
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
100.00% |
|
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
100.00% |
|