Endpoint Protection

 View Only
Expand all | Collapse all

MyPCBackup risk

ℬrίαη

ℬrίαηSep 17, 2014 12:08 PM

  • 1.  MyPCBackup risk

    Posted Sep 16, 2014 10:41 PM
    C:\windows\microsoft.net\framework64\v2.0.50727\config\security.config.cch file quarantined after SEP flagged it as security risk 'my pcbackup' Does anyone have details on this?


  • 2.  RE: MyPCBackup risk
    Best Answer

    Posted Sep 16, 2014 10:47 PM

    It's considered a PUP, potentially unwanted program.

    "MyPCBackup is a potentially unwanted app that displays ads and popup notifications on the computer."

    Here is the writeup from Symantec:

    http://www.symantec.com/security_response/writeup.jsp?docid=2014-080811-2516-99

    And an another link:

    http://www.wikihow.com/Uninstall-MyPC-Backup

    A google search will reveal a bunch more links to go thru.



  • 3.  RE: MyPCBackup risk

    Posted Sep 17, 2014 01:25 AM

    You can remove the application as it count a virus

    http://malwaretips.com/blogs/mypc-backup-virus-removal/#uninstall

    Run the symhelp tool to clean your system from other virus activity

    How to run the Threat Analysis Scan in Symantec Help (SymHelp)

    Article:TECH215519  |  Created: 2014-03-03  |  Updated: 2014-07-10  |  Article URL http://www.symantec.com/docs/TECH215519


  • 4.  RE: MyPCBackup risk

    Posted Sep 17, 2014 02:13 AM

    Hi @Nav,

    You can remove the application as it count a virus

    It is Grayware / Potenially Unwanted Application (see http://www.symantec.com/security_response/glossary/define.jsp?letter=p&word=potentially-unwanted-application) rather than a virus (http://www.symantec.com/security_response/glossary/define.jsp?letter=v&word=virus).  Consider it more of a "risk" than a "threat." A list of other recently-added risk detections can be seen at http://www.symantec.com/security_response/landing/risks/.

    MyPCBackup is definitely annoying, getting installed in unwanted bundles with other noisy PUAs of very limited value and misleading pop-ups.  It will not steal your bank details but many, many customers have requested that Symantec detect and remove it.

    Please do update this thread with news of whwther or not this has answered your query!  &: )

    Many thanks,

    Mick



  • 5.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:01 AM

    What I am trying to find is how I got this? I have not installed any new program except for MS patches.

    Moreover, I did not find this app installed on my computer.



  • 6.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:02 AM

    It only comes from a download.

    What usually happens is you download a legit file. When you go to do the install, this junkware comes bundled with it and it's strategically hidden/placed so that there is a check box you may need to uncheckduring the install to NOT install this stuff. Very tricky....

    CNET.com is well known for doing this...



  • 7.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:04 AM

    The above is correct- I went to a download site as a test recently and unchecked every check box when installing a free download.  This particular PUA still came with along with it and was installed.

    Mick



  • 8.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:06 AM

    I agree but I have not downloaded anything that day. All that was done, I installed bunch of MS patches through SCCM. I doubt It would come bundled with them :)



  • 9.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:07 AM

    It's possible this was on there before definitions were detecting it. New defs came out recently, now it's being detected.



  • 10.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:27 AM

    Thanks Brian.

    I am being asked to find the root cause. Is it possile somehow to trace back its source?



  • 11.  RE: MyPCBackup risk

    Posted Sep 17, 2014 09:30 AM

    Do you have something in place like a proxy to monitor web usage, etc?

    If only using SEP, this won't be likely as it's "after the fact"



  • 12.  RE: MyPCBackup risk

    Posted Sep 17, 2014 10:16 AM

    No. I believe I wont be able to dig deep then. My other concern is I do not see MyPCBackup installed on my computer or in control panel. So I was thinking if it is possible that SEP is just flagging the file to have MyPCBackup "type" of risk.



  • 13.  RE: MyPCBackup risk

    Posted Sep 17, 2014 10:17 AM

    Does the risk log show it was removed/deleted?



  • 14.  RE: MyPCBackup risk

    Posted Sep 17, 2014 10:30 AM

    Logs show it was Quarantined.

     

    Filename - security.config.cch and enterprisesec.config.cch



  • 15.  RE: MyPCBackup risk

    Posted Sep 17, 2014 10:34 AM

    For the ones I've see, it won't show in Add/Remove programs but the files you reference are there. More specifically, located at:

    C:\Users\<username>\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\



  • 16.  RE: MyPCBackup risk

    Posted Sep 17, 2014 11:01 AM

    @ Brian - I ran a manual scan and it did refer to the path you mentioned.



  • 17.  RE: MyPCBackup risk

    Posted Sep 17, 2014 11:04 AM

    You should be good to go then if SEP remediated it.

    Findiong out how it got there is another story. It typically starts with a download and being bundled with some other legit software.



  • 18.  RE: MyPCBackup risk

    Posted Sep 17, 2014 12:08 PM

    Thanks Brian. I have marked your first post as Solution which provide detail about the risk.



  • 19.  RE: MyPCBackup risk

    Posted Sep 17, 2014 12:08 PM

    Thanks :)