This program must be manually downloaded and installed.

When the program is installed, it creates the following folder:
%UserProfile%\.gstreamer-0.10
Next, it creates the following files:
- %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].dat
- %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe
- %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]_nav.dat
- %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]_navps.dat
- %UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS].tmp
- C:\Documents and Settings\All Users\Desktop\GoRecord 2.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\GoRecord 2.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Privacy Policy.url
- C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Terms and Conditions.url
- C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Uninstall.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\GoRecord 2\Website.url
- %ProgramFiles%\GoRecord2\Gfx.bin
- %ProgramFiles%\GoRecord2\GoRecord.exe
- %ProgramFiles%\GoRecord2\iconv.dll
- %ProgramFiles%\GoRecord2\intl.dll
- %ProgramFiles%\GoRecord2\libglib-2.0-0.dll
- %ProgramFiles%\GoRecord2\libgmodule-2.0-0.dll
- %ProgramFiles%\GoRecord2\libgobject-2.0-0.dll
- %ProgramFiles%\GoRecord2\libgstaudio-0.10.dll
- %ProgramFiles%\GoRecord2\libgstaudioconvert.dll
- %ProgramFiles%\GoRecord2\libgstbase-0.10.dll
- %ProgramFiles%\GoRecord2\libgstcontroller-0.10.dll
- %ProgramFiles%\GoRecord2\libgstcoreelements.dll
- %ProgramFiles%\GoRecord2\libgstdecodebin.dll
- %ProgramFiles%\GoRecord2\libgstdirectsound.dll
- %ProgramFiles%\GoRecord2\libgstflump3dec.dll
- %ProgramFiles%\GoRecord2\libgsticydemux.dll
- %ProgramFiles%\GoRecord2\libgstid3demux.dll
- %ProgramFiles%\GoRecord2\libgstinterfaces-0.10.dll
- %ProgramFiles%\GoRecord2\libgstlevel.dll
- %ProgramFiles%\GoRecord2\libgstneon.dll
- %ProgramFiles%\GoRecord2\libgstogg.dll
- %ProgramFiles%\GoRecord2\libgstreamer-0.10.dll
- %ProgramFiles%\GoRecord2\libgstriff-0.10.dll
- %ProgramFiles%\GoRecord2\libgsttag-0.10.dll
- %ProgramFiles%\GoRecord2\libgsttypefindfunctions.dll
- %ProgramFiles%\GoRecord2\libgstvolume.dll
- %ProgramFiles%\GoRecord2\libgstvorbis.dll
- %ProgramFiles%\GoRecord2\libgstwavparse.dll
- %ProgramFiles%\GoRecord2\libgthread-2.0-0.dll
- %ProgramFiles%\GoRecord2\libxml2.dll
- %ProgramFiles%\GoRecord2\ogg.dll
- %ProgramFiles%\GoRecord2\resources\config.bin
- %ProgramFiles%\GoRecord2\resources\musics.s3db
- %ProgramFiles%\GoRecord2\resources\radios.s3db
- %ProgramFiles%\GoRecord2\sqlite3.dll
- %ProgramFiles%\GoRecord2\uninst.exe
- %ProgramFiles%\GoRecord2\vorbis.dll
- %ProgramFiles%\GoRecord2\zlib1.dll
- %System%\nvs2.inf
- %Windìr%\Temp\msksetup.log
It creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\GoRecord
- HKEY_CURRENT_USER\Software\LanConfig
- HKEY_LOCAL_MACHINE\SOFTWARE\GoRecord
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoRecord
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\[RANDOM CHARACTERS]
It also creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "C:\Documents and Settings\administrator\Local Settings\Application Data\[RANDOM CHARACTERS].exe [RANDOM CHARACTERS]"
Next, the program may drop a copy of
Trojan.Skintrim on to the computer.
The program then attempts to connect to the gorecord.com domain.