Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

17.0.9.18 0.28%
1.7.0.24 0.28%
1.5.1.161 0.28%
1.3.3.66 18.66%
1.3.2.28 16.43%
1.3.1.2 13.09%
1.3.0.208 48.75%
1.2.0.144 1.67%
1.1.0.66 0.28%
1.0.2.49 0.28%

Relationships

Parent processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
FreeSid, OpenProcessToken, GetTokenInformation, ConvertSidToStringSidW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExA, RegEnumKeyExA, RegCreateKeyW, RegSetValueW, RegOpenKeyW, RegEnumKeyA, RegDeleteKeyA, RegCreateKeyA, RegSetValueA, RegQueryValueW, RegQueryValueA, RegDeleteValueA, RegOpenKeyExA, RegOpenKeyA, RegQueryValueExA, RegCloseKey
gdi32.dll
GetDeviceCaps
kernel32.dll
SetErrorMode, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetModuleFileNameW, CreateProcessW, GetCurrentProcessId, GetLocaleInfoW, LoadLibraryW, SetEnvironmentVariableW, GetEnvironmentVariableW, LocalFree, SetCurrentDirectoryA, GetCurrentDirectoryA, IsBadWritePtr, VirtualProtect, IsBadReadPtr, SetUnhandledExceptionFilter, TerminateThread, WaitForSingleObject, CreateThread, GetCurrentThreadId, SetEnvironmentVariableA, GetEnvironmentVariableA, GetCurrentProcess, GetModuleHandleExA, WriteFile, GetThreadContext, VirtualQuery, OpenProcess, SetFilePointer, GlobalMemoryStatus, SetProcessWorkingSetSize, WaitForMultipleObjects, Sleep, CreateProcessA, LoadLibraryExW, LoadLibraryExA, FreeLibraryAndExitThread, GetModuleHandleW, GetSystemDirectoryW, UnmapViewOfFile, MapViewOfFile, OpenFileMappingA, IsProcessorFeaturePresent, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EncodePointer, DecodePointer, InterlockedExchange, InterlockedCompareExchange, HeapSetInformation, GetStartupInfoW, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, QueryPerformanceCounter, SetLastError, RaiseException, GetLastError, CloseHandle, SetEvent, OpenEventA, WideCharToMultiByte, lstrlenW, MultiByteToWideChar, lstrlenA, GetModuleHandleA, CreateEventA, ReleaseMutex, CreateMutexA, InterlockedIncrement, InterlockedDecrement, FreeLibrary, GetProcAddress, LoadLibraryA, GetVersionExA, GetVersion, GetSystemInfo, GetTickCount, MoveFileA, CreateFileW, ReadFile, CreateDirectoryA, GetFileAttributesA, GetModuleFileNameA, CreateFileA, GetFileSize, DeleteFileA
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
StringFromCLSID, CoInitialize, CoUninitialize, CoTaskMemFree, CoCreateInstance
secur32.dll
GetUserNameExW
shell32.dll
SHGetFolderPathW, SHCreateDirectoryExW, ShellExecuteA, SHCreateDirectoryExA
shlwapi.dll
PathAddBackslashW, PathRemoveFileSpecW, PathStripPathW, PathAppendW, PathFileExistsW
user32.dll
RegisterClassExA, CreateWindowExA, SendMessageA, GetSystemMetrics, DestroyMenu, LoadCursorA, SetMenuDefaultItem, IsWindow, DestroyIcon, GetSubMenu, MessageBoxA, ShowWindow, UpdateWindow, FindWindowW, GetMessageA, TranslateMessage, DispatchMessageA, BeginPaint, EndPaint, PostQuitMessage, RegisterWindowMessageA, DefWindowProcA, PostMessageA, CharNextA, LoadMenuA, SetLastErrorEx, LoadIconA, GetWindowPlacement, SystemParametersInfoA, IsIconic, SetForegroundWindow, GetForegroundWindow, AttachThreadInput, FlashWindow, GetWindowThreadProcessId, GetDC, ReleaseDC, FindWindowA
version.dll
GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA

recordingmanager.exe

RealDownloader (32-bit) by RealNetworks (Signed)

Remove recordingmanager.exe
Version:   1.3.3.66
MD5:   ddbe89226d55d694f1b7b3dd0c324640
SHA1:   2f6c778d7d22d613c93aa8d01f586729054f6776
SHA256:   ee25ca30fba5f7fd9680e30c33173cd9f6fffaff2d7821f7282aaba633186506

About recordingmanager.exe (from RealNetworks)

Using RealDownloader, you can download videos from YouTube, Facebook, Vimeo, Metacafe, and more. Save your favorite free online videos from hundreds of Web sites. It’s never been easier to download vi

Overview

recordingmanager.exe executes as a process with the local user's privileges typically within the context of its parent chrome.exe (Google Chrome by Google Inc). The file is digitally signed by RealNetworks which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:recordingmanager.exe
Publisher:RealNetworks, Inc.
Product name:RealDownloader (32-bit)
Description:RealDownloader
Typical file path:C:\Program Files\realnetworks\realdownloader\recordingmanager.exe
File version:1.3.3.66
Size:227.59 KB (233,048 bytes)
Build date:8/14/2013 3:19 PM
Certificate
Issued to:RealNetworks
Authority (CA):Thawte
Effective date:Tuesday, March 8, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1423522360-3395476842-3449966222-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1423522360-3395476842-3449966222-1001'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3780133834-331337826-3407075997-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3780133834-331337826-3407075997-1001'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-874151087-749315904-2186047852-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-874151087-749315904-2186047852-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2714351487-4149610615-3439605620-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2714351487-4149610615-3439605620-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3478971812-858940020-2471763029-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3478971812-858940020-2471763029-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1409082233-725345543-682003330-1004' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1409082233-725345543-682003330-1004.job'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2426516273-3893298846-2812643595-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2426516273-3893298846-2812643595-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-917801239-2516116701-2666536058-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-917801239-2516116701-2666536058-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-4136827049-1587382504-3562502678-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-4136827049-1587382504-3562502678-1001'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2302185735-1820880577-3360714277-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2302185735-1820880577-3360714277-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3514410-921461477-147006633-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3514410-921461477-147006633-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1761162800-216172879-1472656228-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1761162800-216172879-1472656228-1001'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1460418714-1805443713-3851231066-1006' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1460418714-1805443713-3851231066-1006.job'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-73586283-746137067-839522115-1003' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-73586283-746137067-839522115-1003.job'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-789336058-706699826-839522115-1003' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-789336058-706699826-839522115-1003.job'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-4226971044-3753984958-3471663708-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-4226971044-3753984958-3471663708-1001'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-572681465-336890980-4167514758-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-572681465-336890980-4167514758-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1682383202-3072944920-2630020424-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1682383202-3072944920-2630020424-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2709236969-139009050-3515939019-1002' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2709236969-139009050-3515939019-1002'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3081201213-2557485704-3847274730-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3081201213-2557485704-3847274730-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1940068096-1023481402-460927341-1002' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1940068096-1023481402-460927341-1002'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2194461130-3394011999-86662213-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2194461130-3394011999-86662213-1000'
Network connections
  • [TCP] 173.194.3.139:80
  • [TCP] vs1.hardsextube.com (194.38.107.19:80)
  • [TCP] 93.184.215.132:80
  • [UDP] listens on port 59796
  • [UDP] listens on port 60793
  • [UDP] listens on port 54147
  • [UDP] listens on port 53951
  • [UDP] listens on port 52704

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00441975%
    0.028634%
    Kernel CPU:0.00298817%
    0.013761%
    User CPU:0.00143158%
    0.014873%
    Kernel CPU time:4,084 ms/min
    100,923,805ms/min
    CPU cycles:5,324,267/sec
    17,470,203/sec
    Context switches:437/sec
    284/sec
    Memory
    Private memory:9.17 MB
    21.59 MB
    Private (maximum):14.67 MB
    Private (minimum):7.49 MB
    Non-paged memory:9.17 MB
    21.59 MB
    Virtual memory:117.76 MB
    140.96 MB
    Virtual memory (peak):139.12 MB
    169.69 MB
    Working set:9.66 MB
    18.61 MB
    Working set (peak):31.16 MB
    37.95 MB
    Page faults:335,867/min
    2,039/min
    I/O
    I/O read transfer:380.18 KB/sec
    1.02 MB/min
    I/O read operations:16/sec
    343/min
    I/O write transfer:10.91 MB/sec
    274.99 KB/min
    I/O write operations:2,396/sec
    227/min
    I/O other transfer:1.14 MB/sec
    448.09 KB/min
    I/O other operations:2,080/sec
    1,671/min
    Resource allocations
    Threads:13
    12
    Handles:261
    600
    GUI GDI count:18
    103
    GUI GDI peak:22
    142
    GUI USER count:38
    49
    GUI USER peak:48
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command lines:
    • "C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /bgrecordhelpersvc
    • "C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /m "application/dash" /t "ancient egypt and the alternative story of mankind's origins (full documentary) - youtube" /pageurl "httC://www.youtube.com/watch?v=hol0rnxpplq&hd=1" /objecturl "httC://s.ytimg.com/yts/swfbin/player-vfle2qpz1/watch_as3.swf" /u "httC://r6---sn-aigllnek.googlevideo.com/videoplayback?algorithm=throttle-factor&burst=40&clen=390198292&cpn=nypionm2gnscgkkc&dur=12762.833&expire=1384241798&factor=1.25&
    • "C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /m "application/dash" /t "nasC: the end of mankind leaked document 2013 - youtube1" /pageurl "httpC://www.youtube.com/watch?v=en4xicoyrb8&list=wl231c9363073e3340" /objecturl "httpC://s.ytimg.com/yts/swfbin/player-vfle2qpz1/watch_as3.swf" /u "httC://r24---sn-nwj7knll.googlevideo.com/videoplayback?algorithm=throttle-factor&burst=40&clen=25629240&cpn=7xohjhkxr_3pujbr&dur=2156.924&expire=1384087866&factor=1.25&fexp=903309%2c90633
    • "C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /m "video/mpeg4" /t "fat slut fucks like crazy with her" /pageurl "httC://vipbbwtube.com/gals/hrdsxtb-fat-slut-fucks-like-crazy-with-her.html" /objecturl "httC://www.hardsextube.com/embed/1200246/" /u "httC://vs1.hardsextube.com/embedc/a193d069793d621b97a7e10c7dbec5b4/5272c432/2012/12/30/2012-12-30-hardsextube-393432617.mp4.mp4?mp4mod=1&start=0" /clipinfo "brname=ie,brmajor=10,brminor=0,brrelease=9200,brbuild=16537,r
    • "C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /m "video/mpeg4" /t "sinnamon love curly haired gets hard anal sex - v porn video" /pageurl "httC://www.vporn.com/bbw/sinnamon-love-curly-haired-gets-hard-anal-sex/155578/?utm_source=affiliate&utm_medium=gallery&utm_campaign=rolan" /objecturl "httC://www.vporn.com/swf/player-v8prebuff.swf?v1" /u "httC://vs750.vporn.com/vid2/5jb4xe_axzpdvfi78oftqg/1382851062/78/155578/155578_720x406_1000k.mp4" /reqheaders rpdl_shm_05065a
    • "C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /t "birdman handling ymcmb business in nyc keeping the company growing - youtube" /pageurl "httC://www.youtube.com/watch?v=0m_f8gwlvos" /objecturl "httC://r3---sn-uxa3vh-woce.c.youtube.com/videoplayback?ratebypass=yes&fexp=901803%2c936901%2c900398%2c924606%2c916914%2c929117%2c929121%2c929906%2c929907%2c929922%2c929923%2c929127%2c929129%2c929131%2c929930%2c936403%2c925724%2c925726%2c936310%2c925720%2c925722%2c925718%2c925714%2c
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    recordingmanager.exe (main module)
    Total CPU:0.02636380%
    0.272967%
    Kernel CPU:0.01836507%
    0.107585%
    User CPU:0.00799873%
    0.165382%
    CPU cycles:4,461,309/sec
    5,741,424/sec
    Context switches:53/sec
    79/sec
    Memory:236 KB
    1.16 MB
    msvcr100.dll (Microsoft Visual Studio 2010 by Microsoft)
    Total CPU:0.00888115%
    Kernel CPU:0.00646844%
    User CPU:0.00241271%
    CPU cycles:1,028,168/sec
    Context switches:14/sec
    Memory:764 KB
    wow64.dll
    Total CPU:0.00671277%
    Kernel CPU:0.00513329%
    User CPU:0.00157947%
    CPU cycles:131,248/sec
    Memory:276 KB
    MSWMDM.dll
    Total CPU:0.00124060%
    Kernel CPU:0.00103383%
    User CPU:0.00020677%
    Memory:328 KB
    ole32.dll
    Total CPU:0.00041350%
    Kernel CPU:0.00041350%
    User CPU:0.00000000%
    Memory:1.23 MB
    msvcrt.dll (Windows NT CRT DLL by Microsoft)
    Total CPU:0.00041077%
    Kernel CPU:0.00000000%
    User CPU:0.00041077%
    CPU cycles:4,171/sec
    Memory:680 KB
    mshtml.dll (Windows Internet Explorer by Microsoft)
    Total CPU:0.00025862%
    Kernel CPU:0.00010345%
    User CPU:0.00015517%
    CPU cycles:41,641/sec
    Context switches:3/sec
    Memory:13.69 MB
    ntdll.dll
    Total CPU:0.00025178%
    Kernel CPU:0.00013602%
    User CPU:0.00011577%
    CPU cycles:2,216/sec
    Memory:1.66 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 35.50%
    Windows 7 Ultimate 20.50%
    Microsoft Windows XP 12.00%
    Windows 8 6.50%
    Windows 7 Professional 5.50%
    Windows Vista Home Premium 5.00%
    Windows 8 Pro 3.50%
    Windows 8 Single Language 2.50%
    Windows 7 Home Basic 2.50%
    Windows 8 Pro with Media Center 2.00%
    Windows 8 Enterprise Evaluation 1.00%
    Windows 8.1 1.00%
    Windows Vista Business 1.00%
    Windows 8 Enterprise N 0.50%
    Windows 7 Starter 0.50%
    Windows Se7en Titan 0.50%

    Distribution by countryDistribution by country

    United States installs about 44.16% of RealDownloader (32-bit) .

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 26.12%
    Toshiba 20.90%
    Hewlett-Packard 16.42%
    Acer 11.57%
    Sony 6.72%
    Lenovo 5.22%
    Intel 2.99%
    Samsung 2.24%
    American Megatrends 1.49%
    ASUS 1.49%
    GIGABYTE 1.12%
    Compaq 0.75%
    Sahara 0.75%
    NEC 0.75%
    MSI 0.75%
    Gateway 0.75%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE