1. /
  2. Security Response/
  3. GoRecord

GoRecord

Updated:
April 22, 2008 3:26:05 PM
Type:
Potentially Unwanted App
Name:
GoRecord
Version:
2.0.0.7
Risk Impact:
Low
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
This program must be manually downloaded and installed.




When the program is installed, it creates the following folder:
%UserProfile%\.gstreamer-0.10

Next, it creates the following files:
  • %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].dat
  • %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe
  • %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]_nav.dat
  • %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]_navps.dat
  • %UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS].tmp
  • C:\Documents and Settings\All Users\Desktop\GoRecord 2.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\GoRecord 2.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Privacy Policy.url
  • C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Terms and Conditions.url
  • C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Uninstall.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Website.url
  • %ProgramFiles%\GoRecord2\Gfx.bin
  • %ProgramFiles%\GoRecord2\GoRecord.exe
  • %ProgramFiles%\GoRecord2\iconv.dll
  • %ProgramFiles%\GoRecord2\intl.dll
  • %ProgramFiles%\GoRecord2\libglib-2.0-0.dll
  • %ProgramFiles%\GoRecord2\libgmodule-2.0-0.dll
  • %ProgramFiles%\GoRecord2\libgobject-2.0-0.dll
  • %ProgramFiles%\GoRecord2\libgstaudio-0.10.dll
  • %ProgramFiles%\GoRecord2\libgstaudioconvert.dll
  • %ProgramFiles%\GoRecord2\libgstbase-0.10.dll
  • %ProgramFiles%\GoRecord2\libgstcontroller-0.10.dll
  • %ProgramFiles%\GoRecord2\libgstcoreelements.dll
  • %ProgramFiles%\GoRecord2\libgstdecodebin.dll
  • %ProgramFiles%\GoRecord2\libgstdirectsound.dll
  • %ProgramFiles%\GoRecord2\libgstflump3dec.dll
  • %ProgramFiles%\GoRecord2\libgsticydemux.dll
  • %ProgramFiles%\GoRecord2\libgstid3demux.dll
  • %ProgramFiles%\GoRecord2\libgstinterfaces-0.10.dll
  • %ProgramFiles%\GoRecord2\libgstlevel.dll
  • %ProgramFiles%\GoRecord2\libgstneon.dll
  • %ProgramFiles%\GoRecord2\libgstogg.dll
  • %ProgramFiles%\GoRecord2\libgstreamer-0.10.dll
  • %ProgramFiles%\GoRecord2\libgstriff-0.10.dll
  • %ProgramFiles%\GoRecord2\libgsttag-0.10.dll
  • %ProgramFiles%\GoRecord2\libgsttypefindfunctions.dll
  • %ProgramFiles%\GoRecord2\libgstvolume.dll
  • %ProgramFiles%\GoRecord2\libgstvorbis.dll
  • %ProgramFiles%\GoRecord2\libgstwavparse.dll
  • %ProgramFiles%\GoRecord2\libgthread-2.0-0.dll
  • %ProgramFiles%\GoRecord2\libxml2.dll
  • %ProgramFiles%\GoRecord2\ogg.dll
  • %ProgramFiles%\GoRecord2\resources\config.bin
  • %ProgramFiles%\GoRecord2\resources\musics.s3db
  • %ProgramFiles%\GoRecord2\resources\radios.s3db
  • %ProgramFiles%\GoRecord2\sqlite3.dll
  • %ProgramFiles%\GoRecord2\uninst.exe
  • %ProgramFiles%\GoRecord2\vorbis.dll
  • %ProgramFiles%\GoRecord2\zlib1.dll
  • %System%\nvs2.inf
  • %Windìr%\Temp\msksetup.log


It creates the following registry subkeys:
  • HKEY_CURRENT_USER\Software\GoRecord
  • HKEY_CURRENT_USER\Software\LanConfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\GoRecord
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoRecord
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\[RANDOM CHARACTERS]


It also creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "C:\Documents and Settings\administrator\Local Settings\Application Data\[RANDOM CHARACTERS].exe [RANDOM CHARACTERS]"

Next, the program may drop a copy of Trojan.Skintrim on to the computer.

The program then attempts to connect to the gorecord.com domain.
Summary| Technical Details| Removal

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report, Volume 17
Symantec DeepSight Screensaver