PUP.Optional.HighStairs

Logo_Malware
HighStairs is a software usually installs without your knowledge vith the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing.  As a general rule, should focus on the author’s official site to download your software. Identified the 08/20/2015.

Features:

– It belongs to a family of PUP (Potentially Unwanted Program).
– Vendor : PUP.Optional

Main actions :

– It installs as a process launched at startup of the system (RP),
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a service to be launched each time the system (O23),(SS/SR).
– It installs as a program (O42),
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45).
– It installs as a driver system (O58),
– It creates multiple files users (O61),

ZHPDiag report:

O2 – BHO: High Stairs – {45e60e41-85ee-4c01-9dac-1ecb9bf64179} . (…) — C:Program FilesHigh StairsExtensions45e60e41-85ee-4c01-9dac-1ecb9bf64179.dll
O23 – Service: Service Mgr HighStairs (Service Mgr HighStairs) . (…) – C:ProgramDatab4bc9939-75e9-422b-af5c-653de35c4f4bplugincontainer.exe
O23 – Service: Update Mgr HighStairs (Update Mgr HighStairs) . (…) – C:Program FilesCommon Filesb4bc9939-75e9-422b-af5c-653de35c4f4bUpdater.exe
HKLMSOFTWAREHighStairs
O42 – Logiciel: High Stairs – (.High Stairs.) — High Stairs
O43 – CFD: 2015/08/20 22:43:32 – [] D — C:Program FilesHigh Stairs
SR – Auto Service Mgr HighStairs (Service Mgr HighStairs) . (…) – C:ProgramDatab4bc9939-75e9-422b-af5c-653de35c4f4bplugincontainer.exe
SR – Auto Update Mgr HighStairs (Update Mgr HighStairs) . (…) – C:Program FilesCommon Filesb4bc9939-75e9-422b-af5c-653de35c4f4bUpdater.exe

Alias:

PUP.Optional.TermTrident.A
a variant of Win64/NetFilter.A
not-a-virus:NetTool.Win64.NetFilter.
Adware.BrowseFox

Remove:

– Remove software in Windows Configuration Panel,
Remove with ZHPcleaner

Diagnose with ZHPDiag

1 Vote2 Votes3 Votes4 Votes5 Votes (No Ratings Yet)
SOSVirusLoading...

Leave a Comment