PUP.Optional.MyPCBackup is the detection name for MyPC Backup, a Potentially Unwanted Program (PUP)that is an online backup solution marketed by JDI Backup.
PUP.Optional.MyPCBackup stands out from their other products because it is often included in bundles, and you will see advertisements for it in almost every corner of the Internet. They do actually provide a backup solution, but it is not customer-friendly and expensive compared to other such services.There are two common methods of infection: either users install the trial of the product themselves, or the product gets bundled with other software. In both cases, the trial will keep reminding users to register and buy the product.
Malwarebytes can detect and remove PUP.Optional.MyPCBackup without further user interaction.
A Malwarebytes log of removal will look similar to this:Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 9/22/2016Scan Time: 11:12 AMLogfile: mbamMyPCBackup.txtAdministrator: YesVersion: 2.2.1.1043Malware Database: v2016.09.22.07Rootkit Database: v2016.08.15.01License: PremiumMalware Protection: DisabledMalicious Website Protection: EnabledSelf-protection: EnabledOS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser:{username}Scan Type: Threat ScanResult: CompletedObjects Scanned: 321533Time Elapsed: 8 min, 44 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: EnabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 1PUP.Optional.MyPCBackup, C:\Program Files (x86)\OLBPre\OLBPre.exe, 2632, Delete-on-Reboot, [0f202b4aecaef2443ad9fc94e21fce32]Modules: 0(No malicious items detected)Registry Keys: 3PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OLBPre, Quarantined, [50dfacc9e0ba85b13fc96fddce364bb5],PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{33A0B791-213F-48AD-AC7D-989EE32023B7}, Delete-on-Reboot, [41ee066fb4e6181ef873529dd23157a9],PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\LaunchPreSignup, Delete-on-Reboot, [45ead79eebaf92a40ed0aefe9370d62a],Registry Values: 2PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{33A0B791-213F-48AD-AC7D-989EE32023B7}|Path, \LaunchPreSignup, Delete-on-Reboot, [41ee066fb4e6181ef873529dd23157a9]PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OLBPRE|DisplayName, MyPC Backup , Quarantined, [3bf480f59ffb73c3a79ace142fd435cb]Registry Data: 0(No malicious items detected)Folders: 1PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre, Delete-on-Reboot, [8ea10c69d0ca3cfa073a8a26cb3820e0],Files: 15PUP.Optional.MyPCBackup, C:\Program Files (x86)\OLBPre\OLBPre.exe, Delete-on-Reboot, [0f202b4aecaef2443ad9fc94e21fce32],PUP.Optional.MyPCBackup, C:\Users\{username}\Desktop\setup.exe, Quarantined, [d55a6312653501356ca7cfc1976aa55b],PUP.Optional.MyPCBackup, C:\Program Files (x86)\OLBPre\uninst.exe, Quarantined, [50dfacc9e0ba85b13fc96fddce364bb5],PUP.Optional.MyPCBackup, C:\Users\{username}\Desktop\MyPC Backup.lnk, Quarantined, [44eb0a6b9bff1d19e5f4ddcf2cd77d83],PUP.Optional.MyPCBackup, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk, Quarantined, [2609d3a27b1f76c0f4e76349db28a957],PUP.Optional.MyPCBackup, C:\Windows\System32\Tasks\LaunchPreSignup, Quarantined, [9e910f663f5b4fe7c01c7d2f2fd450b0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\OLBPre.exe.config, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\brand.jdat, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\de_DE.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\es_ES.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\fr_FR.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\it_IT.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\LinqBridge.dll, Delete-on-Reboot, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\pt_PT.mo, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],PUP.Optional.PreBackup, C:\Program Files (x86)\OLBPre\state.jdat, Quarantined, [8ea10c69d0ca3cfa073a8a26cb3820e0],Physical Sectors: 0(No malicious items detected)(end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
You may see these entries in FRST logs:() C:\Program Files (x86)\OLBPre\OLBPre.exeStartup: C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2016-09-22]ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\OLBPre\OLBPre.exe ()C:\Windows\System32\Tasks\LaunchPreSignupC:\Users\{username}\Desktop\MyPC Backup.lnkC:\Program Files (x86)\OLBPreMyPC Backup (HKLM\...\OLBPre) (Version: - MyPC Backup) <====ATTENTION Task:{33A0B791-213F-48AD-AC7D-989EE32023B7} - System32\Tasks\LaunchPreSignup=> C:\Program Files (x86)\OLBPre\OLBPre.exe [2016-01-03] () <====ATTENTION() C:\Program Files (x86)\OLBPre\OLBPre.exe() C:\Program Files (x86)\OLBPre\LinqBridge.dll
Select your language