TheRecordNavigatorDetector.exe

TheRecord

FTR Pty Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TheRecordNavigatorDetector’. This is installed with TheRecord Player.
Publisher:
FTR Pty. Ltd.  (signed by FTR Pty Ltd)

Product:
TheRecord

Description:
TheRecord Navigator Search Folder Detector

Version:
4.2.106.55

MD5:
30939b296a5fe5845c9eca1bd7fe5a8f

SHA-1:
4e44c3157faaf36ac62173713fea32a01cdeea8e

SHA-256:
676355b921ecb64ef3df3cd20e1f5761bf9a8603de7d5891ff2bdceb76ca4661

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 10:00:29 PM UTC  (today)

File size:
55.1 KB (56,448 bytes)

Product version:
4.2.0.1

Copyright:
Copyright © 1998-2007 FTR Pty. Ltd. All rights reserved.

Original file name:
TheRecordNavigatorDetector.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ftr\fortherecord\therecordnavigatordetector.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/16/2006 8:00:00 PM

Valid to:
8/30/2007 7:59:59 PM

Subject:
CN=FTR Pty Ltd, OU=R&D, OU=Digital ID Class 3 - Microsoft VBA Software Validation v2, O=FTR Pty Ltd, L=Perth, S=Western Australia, C=AU

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6D5298E9F8A507DE7D1A154478495D92

File PE Metadata
Compilation timestamp:
7/13/2007 3:32:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:7bpnXzLyO+6XXxChk8OrIggNvfn+bnbxx:fFzLl+SAVOrPqfn+bbv

Entry address:
0x2295

Entry point:
E8, 66, 04, 00, 00, E9, 36, FD, FF, FF, 53, 8A, 5C, 24, 08, F6, C3, 02, 56, 8B, F1, 74, 24, 57, 68, C2, 28, 40, 00, 8D, 7E, FC, FF, 37, 6A, 0C, 56, E8, 4D, 01, 00, 00, F6, C3, 01, 74, 07, 57, E8, A2, F9, FF, FF, 59, 8B, C7, 5F, EB, 13, E8, ED, 05, 00, 00, F6, C3, 01, 74, 07, 56, E8, 8C, F9, FF, FF, 59, 8B, C6, 5E, 5B, C2, 04, 00, 3B, 0D, 28, 50, 40, 00, 75, 02, F3, C3, E9, 9D, 04, 00, 00, 6A, 14, 68, E0, 3B, 40, 00, E8, 55, 03, 00, 00, FF, 35, 50, 55, 40, 00, 8B, 35, B4, 32, 40, 00, FF, D6, 59, 89, 45, E4...
 
[+]

Entropy:
3.9285

Code size:
8 KB (8,192 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TheRecordNavigatorDetector

Command:
C:\Program Files\ftr\fortherecord\therecordnavigatordetector.exe


The file TheRecordNavigatorDetector.exe has been discovered within the following program.

TheRecord Player  by FTR Pty Ltd
About 8% of users remove it
 
Powered by Should I Remove It?

Scan TheRecordNavigatorDetector.exe - Powered by Reason Core Security