Virus disguised as Realtek HD Audio - This might interest you!

Greetings to you dear Avast Community :slight_smile: as been said in the title, this topic might interest some of you.
Whats the story? since few days I have been facing constant lag on my windows 7, videos did not play smoothly, very annoying few days to be honest. I noticed a process called rthdcpl.exe (Realtek HD Audio) that was consuming 25% of my CPU “see attachment 1” if I end the process the lag goes away in an instant. But it always comes back after I believe the problem was solved.

So i thought I need to update the Realtek Audio driver from my motherboard site but it didn’t help. The weird thing is the location of this rthdcpl.exe file which is not where the drivers get installed, the location is ( C:\Users\username\AppData\Local\Apple Computer\Realtek HD\rthdcpl.exe ) [color=blue]“see attachment 2”. I noticed the installation date and time was very recent, on July 11th 10:15pm which is the same date and time I installed Zona the Russian torrent software and downloaded a game from it. I tried to open the rthdcpl.exe but nothing appears then I checked the config.xml from the same folder and found a short script that triggers an action after 4 days of the installation to execute the rthdcpl.exe file. In “attachment 3” you can see the script. So I deleted the xml file only and the rthdcpl.exe process didn’t appear again.

P.S I ran Avast & Malwarebytes Anti-Malware and everything was clear.
Now I am worried what was the purpose of this file? In the few days it ran did it affect my PC? Do anyone know about this or faced this before? Can you explain the config.xml file script?
I am no expert by any means and your thoughts about the matter will be appreciated.
Thank you in advance :wink:

You can upload and check suspicious file(s) at > www.virustotal.com / www.metadefender.com / www.jotti.org
If scanned before, always click rescan for a fresh result

You may post link to scan result here

If you need assistance, follow instructions here and attach requested logs > https://forum.avast.com/index.php?topic=53253.0

Dear Pondus, here are the links and logs you requested :slight_smile:

Virustotal: https://www.virustotal.com/en/file/64a977eefc76f70f9e073712f5eac0d3b13de38bcd6e1482a6c33fc9ade097f0/analysis/1468927991/

Metadefender: https://www.metadefender.com/#!/results/file/d58bd53c696740d7820e3fef662d6e50/regular/analysis

Jotti: https://virusscan.jotti.org/en-US/filescanjob/7749bu969l

Send to avast lab >> https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Already sent Avast the files, whats the next step? should I delete the files normally?