Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for GoPCPro

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,132 posts
Content is republished with permission from Malwarebytes.

What is GoPCPro?

The Malwarebytes research team has determined that GoPCPro is a fake system optimizer. These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Unpacked blog.

How do I know if I am infected with GoPCPro?

This is how the main screen of the registry cleaning application looks:

main.png

You will see these warnings during install:

warning1.png

warning2.png

and these screens during "operations":

warning5.png

warning6.png

warning7.png

You may see this entry in your list of installed programs:

warning4.png

and this task in your Task Scheduler:

warning3.png

How did GoPCPro get on my computer?

These so-called system optimizers use different methods of getting installed. This particular one is advertized as the #1 registry optimizer..

How do I remove GoPCPro?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-{version}.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to:
    Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • If an update is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of GoPCPro?
  • No, Malwarebytes' Anti-Malware removes GoPCPro completely.
  • This PUP creates a scheduled task. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this system optimizer.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the GoPCPro installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

protection1.png


and it stops some of the connections it tries to make:

protection2.png


Technical details for experts

You may see these entries in FRST logs:

 (GoPcPro) C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.exe
 Startup: C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoPcPro.lnk [2016-09-16]
 ShortcutTarget: GoPcPro.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
 S2 Service1; C:\Program Files (x86)\GoPcPro\GoPcPro\updater.exe [51200 2015-09-10] () [File not signed]
 C:\Windows\System32\Tasks\GoPcPro
 C:\Users\{username}\Desktop\GoPcPro.lnk
 C:\Program Files (x86)\GoPcPro

GoPcPro (HKLM-x32\...\GoPcPro) (Version: 2.1.0 - GoPcPro)
Task: {D899F01E-2606-4FB8-810D-7C360EDD439F} - System32\Tasks\GoPcPro => C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.exe [2015-09-11] (GoPcPro)
Alterations made by the installer:

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\GoPcPro\GoPcPro
       Adds the file CircularProgressBar.dll"="2/4/2015 4:57 AM, 33792 bytes, A
       Adds the file CircularProgressBar.pdb"="2/4/2015 4:57 AM, 67072 bytes, A
       Adds the file ColourSliderLibrary.dll"="2/19/2015 12:20 AM, 12800 bytes, A
       Adds the file ColourSliderLibrary.pdb"="2/19/2015 5:28 AM, 26112 bytes, A
       Adds the file Comparers.dll"="4/17/2015 11:00 PM, 6144 bytes, A
       Adds the file cpupdates.exe"="9/10/2015 1:30 AM, 12288 bytes, A
       Adds the file cpupdates.exe.config"="3/11/2015 10:26 PM, 174 bytes, A
       Adds the file cpupdates.pdb"="3/12/2015 4:36 AM, 13824 bytes, A
       Adds the file DesktopAlert.dll"="5/14/2015 1:49 AM, 10752 bytes, A
       Adds the file DesktopAlert.pdb"="5/14/2015 1:49 AM, 24064 bytes, A
       Adds the file GetCurrentDirectory.dat"="5/13/2015 10:59 PM, 125 bytes, A
       Adds the file GoPcPro.application"="5/14/2015 1:50 AM, 1800 bytes, A
       Adds the file GoPcPro.exe"="9/11/2015 4:35 AM, 8693760 bytes, A
       Adds the file GoPcPro.exe.config"="3/31/2015 9:37 PM, 1508 bytes, A
       Adds the file GoPcPro.exe.manifest"="9/11/2015 4:35 AM, 23201 bytes, A
       Adds the file GoPcPro.pdb"="5/14/2015 1:50 AM, 1365504 bytes, A
       Adds the file GoPcPro.vshost.application"="5/13/2015 9:21 AM, 1800 bytes, A
       Adds the file GoPcPro.vshost.exe"="5/13/2015 10:55 PM, 22984 bytes, A
       Adds the file GoPcPro.vshost.exe.config"="3/31/2015 9:37 PM, 1508 bytes, A
       Adds the file GoPcPro.vshost.exe.manifest"="5/13/2015 9:21 AM, 23489 bytes, A
       Adds the file Hashing.dll"="4/17/2015 11:00 PM, 24576 bytes, A
       Adds the file InstallUtil.InstallLog"="9/16/2016 8:44 AM, 652 bytes, A
       Adds the file instservice.exe"="5/14/2015 1:58 AM, 38912 bytes, A
       Adds the file instservice.exe.config"="1/28/2015 12:16 AM, 613 bytes, A
       Adds the file instservice.pdb"="1/31/2015 1:24 AM, 110080 bytes, A
       Adds the file instservice.vshost.exe"="1/30/2015 12:09 AM, 22472 bytes, A
       Adds the file Ionic.Zip.Reduced.dll"="7/14/2014 5:36 PM, 253440 bytes, A
       Adds the file LedControl.dll"="3/6/2012 7:14 PM, 13824 bytes, A
       Adds the file LedControl.pdb"="3/6/2012 7:14 PM, 38400 bytes, A
       Adds the file license.txt"="7/22/2014 1:55 PM, 20597 bytes, A
       Adds the file log.txt"="9/16/2016 8:45 AM, 603 bytes, A
       Adds the file Logger.dll"="4/14/2003 2:06 PM, 7168 bytes, A
       Adds the file logo.ico"="2/3/2015 12:57 AM, 43737 bytes, A
       Adds the file Microsoft.Win32.TaskScheduler.dll"="7/14/2014 5:36 PM, 185856 bytes, A
       Adds the file Microsoft.Windows.Shell.dll"="10/19/2010 9:00 PM, 167808 bytes, A
       Adds the file mindscape.wpfelements.dll"="6/9/2014 3:36 PM, 3036672 bytes, A
       Adds the file mindscape.wpfelements.xml"="6/9/2014 3:36 PM, 1634501 bytes, A
       Adds the file MyWpfLibrary.dll"="4/5/2011 7:38 AM, 10752 bytes, A
       Adds the file MyWpfLibrary.pdb"="4/5/2011 7:38 AM, 28160 bytes, A
       Adds the file outputfilePath"="9/4/2015 2:23 AM, 0 bytes, A
       Adds the file pan.txt"="1/21/2015 2:28 AM, 3 bytes, A
       Adds the file passuac.exe"="6/9/2015 4:39 AM, 63488 bytes, A
       Adds the file passuac.exe.config"="5/12/2015 12:49 PM, 239 bytes, A
       Adds the file passuac.pdb"="2/26/2015 4:11 AM, 26112 bytes, A
       Adds the file passuac.vshost.exe"="2/26/2015 4:09 AM, 21464 bytes, A
       Adds the file PDSA.Common.dll"="2/19/2015 12:20 AM, 9728 bytes, A
       Adds the file PDSA.Common.pdb"="2/19/2015 5:28 AM, 26112 bytes, A
       Adds the file PDSA.WPF.dll"="2/19/2015 12:20 AM, 45056 bytes, A
       Adds the file PDSA.WPF.pdb"="2/19/2015 5:28 AM, 97792 bytes, A
       Adds the file RibbonControlsLibrary.dll"="12/9/2011 2:11 AM, 737280 bytes, A
       Adds the file ScanResults.Xml"="9/10/2015 12:30 AM, 1040 bytes, A
       Adds the file System.Windows.Controls.DataVisualization.Toolkit.dll"="3/2/2010 11:09 AM, 278872 bytes, A
       Adds the file System.Windows.Controls.Input.Toolkit.dll"="4/30/2015 10:15 PM, 109400 bytes, A
       Adds the file System.Windows.Controls.Layout.Toolkit.dll"="4/30/2015 10:15 PM, 95064 bytes, A
       Adds the file telerik.windows.controls.chart.dll"="10/16/2013 3:30 AM, 1308672 bytes, A
       Adds the file telerik.windows.controls.chart.pdb"="10/16/2013 3:30 AM, 2973184 bytes, A
       Adds the file telerik.windows.controls.chart.xml"="10/16/2013 3:30 AM, 819680 bytes, A
       Adds the file telerik.windows.controls.datavisualization.dll"="10/16/2013 3:32 AM, 4346368 bytes, A
       Adds the file telerik.windows.controls.datavisualization.pdb"="10/16/2013 3:32 AM, 6338048 bytes, A
       Adds the file telerik.windows.controls.datavisualization.xml"="10/16/2013 3:32 AM, 2527518 bytes, A
       Adds the file telerik.windows.controls.dll"="10/16/2013 3:27 AM, 3376640 bytes, A
       Adds the file telerik.windows.controls.pdb"="10/16/2013 3:27 AM, 4128256 bytes, A
       Adds the file telerik.windows.controls.xml"="10/16/2013 3:27 AM, 1882790 bytes, A
       Adds the file Telerik.Windows.Data.dll"="10/16/2013 3:28 AM, 453632 bytes, A
       Adds the file Telerik.Windows.Data.pdb"="10/16/2013 3:28 AM, 1607168 bytes, A
       Adds the file Telerik.Windows.Data.xml"="10/16/2013 3:28 AM, 351104 bytes, A
       Adds the file testwcf.exe"="10/5/2015 11:12 AM, 27648 bytes, A
       Adds the file testwcf.exe.config"="1/21/2015 1:56 AM, 614 bytes, A
       Adds the file testwcf.pdb"="2/20/2015 12:09 AM, 71168 bytes, A
       Adds the file testwcf.vshost.exe"="2/20/2015 12:10 AM, 22472 bytes, A
       Adds the file UIAutomationProvider.dll"="3/18/2010 6:31 PM, 21352 bytes, A
       Adds the file Uninstall.exe"="9/16/2016 8:44 AM, 145604 bytes, A
       Adds the file Uninstall.ini"="9/16/2016 8:44 AM, 8999 bytes, A
       Adds the file Update.exe"="8/25/2014 12:44 PM, 19968 bytes, A
       Adds the file updater.exe"="9/10/2015 1:30 AM, 51200 bytes, A
       Adds the file updater.exe.config"="3/18/2015 12:13 AM, 590 bytes, A
       Adds the file updater.InstallLog"="9/16/2016 8:44 AM, 669 bytes, A
       Adds the file updater.InstallState"="9/16/2016 8:44 AM, 7466 bytes, A
       Adds the file updater.pdb"="3/19/2015 11:40 PM, 134656 bytes, A
       Adds the file UpdateVersionId.dat"="4/29/2015 4:45 AM, 2 bytes, A
       Adds the file UrlHistoryLibrary.dll"="2/3/2015 11:12 PM, 24576 bytes, A
       Adds the file UrlHistoryLibrary.pdb"="2/3/2015 11:12 PM, 24064 bytes, A
       Adds the file VTRegScan.dll"="1/30/2015 11:29 PM, 75264 bytes, A
       Adds the file VTRegScan.pdb"="1/30/2015 11:29 PM, 93696 bytes, A
       Adds the file WpfAnimatedGif.dll"="5/2/2015 4:35 AM, 40448 bytes, A
       Adds the file WpfAnimatedGif.xml"="5/2/2015 4:35 AM, 11068 bytes, A
       Adds the file WPFToolkit.dll"="3/2/2010 11:09 AM, 467288 bytes, A
    Adds the folder C:\Program Files (x86)\GoPcPro\GoPcPro\ServerUpdate
       Adds the file Update.exe"="8/25/2014 12:44 PM, 19968 bytes, A
    Adds the folder C:\Program Files (x86)\GoPcPro\GoPcPro\Xml
       Adds the file GetCurrentDirectory.dat"="1/11/2015 7:57 AM, 28 bytes, A
       Adds the file log.txt"="1/21/2015 2:28 AM, 307 bytes, A
       Adds the file pan.txt"="1/21/2015 2:28 AM, 3 bytes, A
       Adds the file ScanResults.xml"="2/17/2015 4:16 AM, 1040 bytes, A
       Adds the file UpdateVersionId.dat"="3/11/2015 10:53 PM, 1 bytes, A
    Adds the folder C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\Img
       Adds the file logo.png"="7/14/2014 5:36 PM, 26506 bytes, A
    In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
       Adds the file GoPcPro.lnk"="9/16/2016 8:44 AM, 1845 bytes, A
    In the existing folder C:\Users\{username}\Desktop
       Adds the file GoPcPro.lnk"="9/16/2016 8:44 AM, 1809 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file GoPcPro"="9/16/2016 8:44 AM, 3270 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GoPcPro]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\GoPcPro\GoPcPro\Uninstall.exe"
       "DisplayName"="REG_SZ", "GoPcPro"
       "DisplayVersion"="REG_SZ", "2.1.0"
       "EstimatedSize"="REG_DWORD", 47735
       "HelpLink"="REG_SZ", "mailto:[email protected]"
       "InstallDate"="REG_SZ", "20160916"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\GoPcPro\GoPcPro\"
       "InstallSource"="REG_SZ", "C:\Users\{username}\Desktop\"
       "Language"="REG_DWORD", 1033
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "GoPcPro"
       "UninstallString"="REG_SZ", "C:\Program Files (x86)\GoPcPro\GoPcPro\Uninstall.exe"
       "URLInfoAbout"="REG_SZ", "http://www.gopcpro.com/"
       "VersionMajor"="REG_DWORD", 2
       "VersionMinor"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Service1]
       "EventMessageFile"="REG_EXPAND_SZ, "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Service1]
       "DelayedAutostart"="REG_DWORD", 0
       "Description"="REG_SZ", "Plugins Update Service"
       "DisplayName"="REG_SZ", "Plugins Service"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files (x86)\GoPcPro\GoPcPro\updater.exe""
       "ObjectName"="REG_SZ", "LocalSystem"
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 16

Malwarebytes Anti-Malware log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 9/16/2016
Scan Time: 8:53 AM
Logfile: mbamGoPCPro.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.09.16.03
Rootkit Database: v2016.08.15.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 320836
Time Elapsed: 9 min, 9 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 1
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.exe, 3384, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b]

Modules: 0
(No malicious items detected)

Registry Keys: 3
PUP.Optional.GoPcPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\GoPcPro, Delete-on-Reboot, [f1e291e19dfdc3735d7bbd3246be3fc1], 
PUP.Optional.GoPcPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SERVICE1, Quarantined, [08cba3cf356568ce2ca711defa0a19e7], 
PUP.Optional.GoPcPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GoPcPro, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 

Registry Values: 1
PUP.Optional.GoPcPro, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SERVICE1|ImagePath, "C:\Program Files (x86)\GoPcPro\GoPcPro\updater.exe", Quarantined, [08cba3cf356568ce2ca711defa0a19e7]

Registry Data: 0
(No malicious items detected)

Folders: 5
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\ServerUpdate, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\Img, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 

Files: 98
PUP.Optional.GoPcPro, C:\Users\{username}\Desktop\setup.exe, Quarantined, [43905022247681b5efeb8b645ca8d030], 
PUP.Optional.GoPcPro, C:\Users\{username}\Desktop\GoPcPro.lnk, Quarantined, [24af353dd5c5ce68ad230ce3c53f926e], 
PUP.Optional.GoPcPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoPcPro.lnk, Quarantined, [51824c263b5f340299394fa0947019e7], 
PUP.Optional.GoPcPro, C:\Windows\System32\Tasks\GoPcPro, Quarantined, [3b98d69c683246f06373c9269371e11f], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\updater.exe, Quarantined, [08cba3cf356568ce2ca711defa0a19e7], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\CircularProgressBar.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\CircularProgressBar.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\ColourSliderLibrary.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\ColourSliderLibrary.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Comparers.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\cpupdates.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\cpupdates.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\cpupdates.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\DesktopAlert.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GetCurrentDirectory.dat, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.application, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.exe, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.exe.manifest, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.vshost.application, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.vshost.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.vshost.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\GoPcPro.vshost.exe.manifest, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Hashing.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\InstallUtil.InstallLog, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\instservice.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\instservice.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\instservice.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\instservice.vshost.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Ionic.Zip.Reduced.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\LedControl.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\LedControl.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\license.txt, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\log.txt, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Logger.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\logo.ico, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Microsoft.Win32.TaskScheduler.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Microsoft.Windows.Shell.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\mindscape.wpfelements.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\mindscape.wpfelements.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\MyWpfLibrary.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\MyWpfLibrary.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\outputfilePath, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\pan.txt, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\passuac.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\passuac.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\passuac.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\passuac.vshost.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\PDSA.Common.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\PDSA.Common.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\PDSA.WPF.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\PDSA.WPF.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\RibbonControlsLibrary.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\System.Windows.Controls.DataVisualization.Toolkit.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\System.Windows.Controls.Input.Toolkit.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\System.Windows.Controls.Layout.Toolkit.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.chart.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.chart.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.chart.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.datavisualization.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\DesktopAlert.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\ScanResults.Xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.datavisualization.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\UpdateVersionId.dat, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.datavisualization.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\telerik.windows.controls.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Telerik.Windows.Data.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Telerik.Windows.Data.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Telerik.Windows.Data.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\testwcf.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\testwcf.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\testwcf.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\testwcf.vshost.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\UIAutomationProvider.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Uninstall.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Uninstall.ini, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Update.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\updater.exe.config, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\updater.InstallLog, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\updater.InstallState, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\updater.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\UrlHistoryLibrary.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\UrlHistoryLibrary.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\VTRegScan.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\VTRegScan.pdb, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\WpfAnimatedGif.dll, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\WpfAnimatedGif.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\WPFToolkit.dll, Delete-on-Reboot, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\ServerUpdate\Update.exe, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\GetCurrentDirectory.dat, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\log.txt, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\pan.txt, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\ScanResults.xml, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\UpdateVersionId.dat, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 
PUP.Optional.GoPcPro, C:\Program Files (x86)\GoPcPro\GoPcPro\Xml\Img\logo.png, Quarantined, [488bdd954b4fd85e1db4d81741c3857b], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.