We checked some samples of GOCLEAR.EXE and detected the file GOCLEAR.EXE as threat.
Remove the GOCLEAR.EXE file from your computer right now.
Removal tool: http://www.unhackme.com
Malware Analysis of GOCLEAR.EXE
Full path on a computer: %SysDir%\Goclear.exe
Detected by UnHackMe:
GOCLEAR.EXE
Default location: %SysDir%\Goclear.exe
Removal Results: Success
Number of reboot: 1
GOCLEAR.EXE is known as:
Trojan.Gamania, ServStart.E, Backdoor.Zegost.wsd, Trojan.ServStart.+H6nxLyr7Uc, Trojan.Agent.90112.DP, Trojan.PWS.Gamania.39048, Trojan.Redosdru.C (v), Troj.Undef.(kcloud), Trojan.Agent, Trojan.ServStart.BX, Win32.ServStart.BX, Trojan.KillAV, W32.Zegost.BX.tr.bdr
GOCLEAR.EXE hash:
- MD5: 5a331b85ac349ad40555a6822e02a608
How to quickly detect GOCLEAR.EXE presence?
Registry:
- HKLM\System\CurrentControlSet\Services\Windows DPCDS V2\ImagePath: “%SysDir%\Goclear.exe”
- HKLM\System\CurrentControlSet\Services\Windows DPCDS V2\DisplayName: “Windows DPCDS V2 Server 1.0″
Files:
- %SysDir%\Goclear.exe