PUP.Optional.MyPCBackup

Short bio

PUP.Optional.MyPCBackup is the detection name for MyPC Backup, a Potentially Unwanted Program (PUP)that is an online backup solution marketed by JDI Backup.

Type and source of infection

PUP.Optional.MyPCBackup stands out from their other products because it is often included in bundles, and you will see advertisements for it in almost every corner of the Internet. They do actually provide a backup solution, but it is not customer-friendly and expensive compared to other such services.There are two common methods of infection: either users install the trial of the product themselves, or the product gets bundled with other software. In both cases, the trial will keep reminding users to register and buy the product.

Protection

block PUP.Optional.MyPCBackup

Malwarebytes blocks PUP.Optional.MyPCBackup

Remediation

Malwarebytes can detect and remove PUP.Optional.MyPCBackup without further user interaction.

  1. Please download Malwarebytesto your desktop.
  2. Double-click MBSetup.exeand follow the prompts to install the program.
  3. When your Malwarebytes for Windowsinstallation completes, the program opens to the Welcome to Malwarebytes screen.
  4. Click on the Get started button.
  5. Click Scan to start a Threat Scan.
  6. Click Quarantineto remove the found threats.
  7. Reboot the system if prompted to complete the removal process.
If you have registered the product, you may get some spam on the address you used. Unsubscribing from the email list might help stop that.

Malwarebytes removal log

A Malwarebytes log of removal will look similar to this:Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 9/22/2016Scan Time: 11:12 AMLogfile: mbamMyPCBackup.txtAdministrator: YesVersion: 2.2.1.1043Malware Database: v2016.09.22.07Rootkit Database: v2016.08.15.01License: PremiumMalware Protection: DisabledMalicious Website Protection: EnabledSelf-protection: EnabledOS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser:{username}Scan Type: Threat ScanResult: CompletedObjects Scanned: 321533Time Elapsed: 8 min, 44 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: EnabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 1PUP.Optional.MyPCBackup, C:\Program Files (x86)\OLBPre\OLBPre.exe, 2632, Delete-on-Reboot, [0f202b4aecaef2443ad9fc94e21fce32]Modules: 0(No malicious items detected)Registry Keys: 3PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OLBPre, Quarantined, [50dfacc9e0ba85b13fc96fddce364bb5],PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{33A0B791-213F-48AD-AC7D-989EE32023B7}, Delete-on-Reboot, [41ee066fb4e6181ef873529dd23157a9],PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\LaunchPreSignup, Delete-on-Reboot, [45ead79eebaf92a40ed0aefe9370d62a],Registry Values: 2PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{33A0B791-213F-48AD-AC7D-989EE32023B7}|Path, \LaunchPreSignup, Delete-on-Reboot, [41ee066fb4e6181ef873529dd23157a9]PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OLBPRE|DisplayName, MyPC Backup , Quarantined, [3bf480f59ffb73c3a79ace142fd435cb]Registry Data: 0(No malicious items detected)Folders: 1PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre, Delete-on-Reboot, [8ea10c69d0ca3cfa073a8a26cb3820e0],Files: 15PUP.Optional.MyPCBackup, C:\Program Files (x86)\OLBPre\OLBPre.exe, Delete-on-Reboot, [0f202b4aecaef2443ad9fc94e21fce32],PUP.Optional.MyPCBackup, C:\Users\{username}\Desktop\setup.exe, Quarantined, [d55a6312653501356ca7cfc1976aa55b],PUP.Optional.MyPCBackup, C:\Program Files (x86)\OLBPre\uninst.exe, Quarantined, [50dfacc9e0ba85b13fc96fddce364bb5],PUP.Optional.MyPCBackup, C:\Users\{username}\Desktop\MyPC Backup.lnk, Quarantined, [44eb0a6b9bff1d19e5f4ddcf2cd77d83],PUP.Optional.MyPCBackup, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk, Quarantined, [2609d3a27b1f76c0f4e76349db28a957],PUP.Optional.MyPCBackup, C:\Windows\System32\Tasks\LaunchPreSignup, Quarantined, [9e910f663f5b4fe7c01c7d2f2fd450b0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\OLBPre.exe.config, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\brand.jdat, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\de_DE.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\es_ES.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\fr_FR.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\it_IT.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\LinqBridge.dll, Delete-on-Reboot, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\pt_PT.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\state.jdat, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],Physical Sectors: 0(No malicious items detected)(end)

Add an exclusion

Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.

  • Open Malwarebytes for Windows.
  • Click the Detection History
  • Click the Allow List
  • To add an item to the Allow List, click Add.
  • Select the exclusion type Allow a file or folderand use the Select a folderbutton to select the main folder for the software that you wish to keep.
  • Repeat this for any secondary files or folder(s) that belong to the software.
If you want to allow the program to connect to the Internet, for example to fetch updates, also add an exclusion of the type Allow an application to connect to the internet and use theBrowse button to select the file you wish to grant access.

Traces/IOCs

You may see these entries in FRST logs:() C:\Program Files (x86)\OLBPre\OLBPre.exeStartup: C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2016-09-22]ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\OLBPre\OLBPre.exe ()C:\Windows\System32\Tasks\LaunchPreSignupC:\Users\{username}\Desktop\MyPC Backup.lnkC:\Program Files (x86)\OLBPreMyPC Backup (HKLM\...\OLBPre) (Version: - MyPC Backup) <====ATTENTION Task:{33A0B791-213F-48AD-AC7D-989EE32023B7} - System32\Tasks\LaunchPreSignup=> C:\Program Files (x86)\OLBPre\OLBPre.exe [2016-01-03] () <====ATTENTION() C:\Program Files (x86)\OLBPre\OLBPre.exe() C:\Program Files (x86)\OLBPre\LinqBridge.dll

Select your language