Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

17.0.9.18 0.28%
1.7.0.24 0.28%
1.5.1.161 0.28%
1.3.3.66 18.66%
1.3.2.28 16.43%
1.3.1.2 13.09%
1.3.0.208 48.75%
1.2.0.144 1.67%
1.1.0.66 0.28%
1.0.2.49 0.28%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
FreeSid, OpenProcessToken, GetTokenInformation, ConvertSidToStringSidW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExA, RegEnumKeyExA, RegCreateKeyW, RegSetValueW, RegOpenKeyW, RegEnumKeyA, RegDeleteKeyA, RegCreateKeyA, RegSetValueA, RegQueryValueW, RegQueryValueA, RegDeleteValueA, RegOpenKeyExA, RegOpenKeyA, RegQueryValueExA, RegCloseKey
gdi32.dll
GetDeviceCaps
kernel32.dll
SetErrorMode, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetModuleFileNameW, CreateProcessW, GetCurrentProcessId, GetLocaleInfoW, LoadLibraryW, SetEnvironmentVariableW, GetEnvironmentVariableW, LocalFree, SetCurrentDirectoryA, GetCurrentDirectoryA, IsBadWritePtr, VirtualProtect, IsBadReadPtr, SetUnhandledExceptionFilter, TerminateThread, WaitForSingleObject, CreateThread, GetCurrentThreadId, SetEnvironmentVariableA, GetEnvironmentVariableA, GetCurrentProcess, GetModuleHandleExA, WriteFile, GetThreadContext, VirtualQuery, OpenProcess, SetFilePointer, GlobalMemoryStatus, SetProcessWorkingSetSize, WaitForMultipleObjects, Sleep, CreateProcessA, LoadLibraryExW, LoadLibraryExA, FreeLibraryAndExitThread, GetModuleHandleW, GetSystemDirectoryW, UnmapViewOfFile, MapViewOfFile, OpenFileMappingA, IsProcessorFeaturePresent, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EncodePointer, DecodePointer, InterlockedExchange, InterlockedCompareExchange, HeapSetInformation, GetStartupInfoW, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, QueryPerformanceCounter, SetLastError, RaiseException, GetLastError, CloseHandle, SetEvent, OpenEventA, WideCharToMultiByte, lstrlenW, MultiByteToWideChar, lstrlenA, GetModuleHandleA, CreateEventA, ReleaseMutex, CreateMutexA, InterlockedIncrement, InterlockedDecrement, FreeLibrary, GetProcAddress, LoadLibraryA, GetVersionExA, GetVersion, GetSystemInfo, GetTickCount, MoveFileA, CreateFileW, ReadFile, CreateDirectoryA, GetFileAttributesA, GetModuleFileNameA, CreateFileA, GetFileSize, DeleteFileA
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
StringFromCLSID, CoInitialize, CoUninitialize, CoTaskMemFree, CoCreateInstance
secur32.dll
GetUserNameExW
shell32.dll
SHGetFolderPathW, SHCreateDirectoryExW, ShellExecuteA, SHCreateDirectoryExA
shlwapi.dll
PathAddBackslashW, PathRemoveFileSpecW, PathStripPathW, PathAppendW, PathFileExistsW
user32.dll
RegisterClassExA, CreateWindowExA, SendMessageA, GetSystemMetrics, DestroyMenu, LoadCursorA, SetMenuDefaultItem, IsWindow, DestroyIcon, GetSubMenu, MessageBoxA, ShowWindow, UpdateWindow, FindWindowW, GetMessageA, TranslateMessage, DispatchMessageA, BeginPaint, EndPaint, PostQuitMessage, RegisterWindowMessageA, DefWindowProcA, PostMessageA, CharNextA, LoadMenuA, SetLastErrorEx, LoadIconA, GetWindowPlacement, SystemParametersInfoA, IsIconic, SetForegroundWindow, GetForegroundWindow, AttachThreadInput, FlashWindow, GetWindowThreadProcessId, GetDC, ReleaseDC, FindWindowA
version.dll
GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA

recordingmanager.exe

RealDownloader (32-bit) by RealNetworks (Signed)

Remove recordingmanager.exe
Version:   1.5.1.161
MD5:   e5fb36a824f1f7cdb6ee089080b0aec1
SHA1:   83149ec64d5f5d81c18216919289f8fea96dd0e9
SHA256:   35595c4dfce607d49e2cd6125a0de556c78efdc743e27bbd5bb16bd447349320

About recordingmanager.exe (from RealNetworks)

Using RealDownloader, you can download videos from YouTube, Facebook, Vimeo, Metacafe, and more. Save your favorite free online videos from hundreds of Web sites. It’s never been easier to download vi

Overview

recordingmanager.exe executes as a process with the local user's privileges. The file is digitally signed by RealNetworks which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:recordingmanager.exe
Publisher:RealNetworks, Inc.
Product name:RealDownloader (32-bit)
Description:RealDownloader
Typical file path:C:\Program Files\realnetworks\realdownloader\recordingmanager.exe
File version:1.5.1.161
Size:247.59 KB (253,528 bytes)
Build date:9/23/2013 11:25 PM
Certificate
Issued to:RealNetworks
Authority (CA):Thawte
Effective date:Tuesday, March 8, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1423522360-3395476842-3449966222-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1423522360-3395476842-3449966222-1001'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3780133834-331337826-3407075997-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3780133834-331337826-3407075997-1001'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-874151087-749315904-2186047852-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-874151087-749315904-2186047852-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2714351487-4149610615-3439605620-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2714351487-4149610615-3439605620-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3478971812-858940020-2471763029-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3478971812-858940020-2471763029-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1409082233-725345543-682003330-1004' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1409082233-725345543-682003330-1004.job'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2426516273-3893298846-2812643595-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2426516273-3893298846-2812643595-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-917801239-2516116701-2666536058-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-917801239-2516116701-2666536058-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-4136827049-1587382504-3562502678-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-4136827049-1587382504-3562502678-1001'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2302185735-1820880577-3360714277-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2302185735-1820880577-3360714277-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3514410-921461477-147006633-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3514410-921461477-147006633-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1761162800-216172879-1472656228-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1761162800-216172879-1472656228-1001'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1460418714-1805443713-3851231066-1006' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1460418714-1805443713-3851231066-1006.job'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-73586283-746137067-839522115-1003' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-73586283-746137067-839522115-1003.job'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-789336058-706699826-839522115-1003' runs daily in the path 'C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-789336058-706699826-839522115-1003.job'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-4226971044-3753984958-3471663708-1001' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-4226971044-3753984958-3471663708-1001'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-572681465-336890980-4167514758-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-572681465-336890980-4167514758-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1682383202-3072944920-2630020424-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1682383202-3072944920-2630020424-1000'
  • The task 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2709236969-139009050-3515939019-1002' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2709236969-139009050-3515939019-1002'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-3081201213-2557485704-3847274730-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-3081201213-2557485704-3847274730-1000'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-1940068096-1023481402-460927341-1002' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-1940068096-1023481402-460927341-1002'
  • The job 'RealDownloaderDownloaderScheduledTaskS-1-5-21-2194461130-3394011999-86662213-1000' runs daily in the path '\RealDownloaderDownloaderScheduledTaskS-1-5-21-2194461130-3394011999-86662213-1000'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00013302%
0.028634%
Kernel CPU:0.00006215%
0.013761%
User CPU:0.00007087%
0.014873%
Kernel CPU time:671 ms/min
100,923,805ms/min
Memory
Private memory:8.89 MB
21.59 MB
Private (maximum):11.26 MB
Private (minimum):956 KB
Non-paged memory:8.89 MB
21.59 MB
Virtual memory:121.5 MB
140.96 MB
Virtual memory (peak):126.57 MB
169.69 MB
Working set:1.44 MB
18.61 MB
Working set (peak):14.43 MB
37.95 MB
Resource allocations
Threads:14
12
Handles:238
600
GUI GDI count:9
103
GUI GDI peak:10
142
GUI USER count:34
49
GUI USER peak:35
71

BehaviorsProcess properties

Integrety level:Undefined
Platform:64-bit
Command line:"C:\Program Files\realnetworks\realdownloader\recordingmanager.exe" /bgrecordhelpersvc
Owner:User

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.00017850%
0.272967%
Kernel CPU:0.00017850%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:86/sec
5,741,424/sec
Memory:1.66 MB
1.16 MB
recordingmanager.exe (main module)
Total CPU:0.00017345%
Kernel CPU:0.00008338%
User CPU:0.00009008%
CPU cycles:3,967,220/sec
Memory:256 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 35.50%
Windows 7 Ultimate 20.50%
Microsoft Windows XP 12.00%
Windows 8 6.50%
Windows 7 Professional 5.50%
Windows Vista Home Premium 5.00%
Windows 8 Pro 3.50%
Windows 8 Single Language 2.50%
Windows 7 Home Basic 2.50%
Windows 8 Pro with Media Center 2.00%
Windows 8 Enterprise Evaluation 1.00%
Windows 8.1 1.00%
Windows Vista Business 1.00%
Windows 8 Enterprise N 0.50%
Windows 7 Starter 0.50%
Windows Se7en Titan 0.50%

Distribution by countryDistribution by country

United States installs about 44.16% of RealDownloader (32-bit) .

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 26.12%
Toshiba 20.90%
Hewlett-Packard 16.42%
Acer 11.57%
Sony 6.72%
Lenovo 5.22%
Intel 2.99%
Samsung 2.24%
American Megatrends 1.49%
ASUS 1.49%
GIGABYTE 1.12%
Compaq 0.75%
Sahara 0.75%
NEC 0.75%
MSI 0.75%
Gateway 0.75%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE