dsrsetup.exe

Keep-My-Search LTD

The application dsrsetup.exe by Keep-My-Search has been detected as adware by 15 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program Yahoo! Search by Pay-By-Ads. This file is typically installed with the program Yahoo! Search by Pay-by-Ads Ltd which is a potentially unwanted software program. While running, it connects to the Internet address NY1WV3561 on port 80 using the HTTP protocol.
Publisher:
Keep-My-Search LTD  (signed and verified)

Version:
1.3.0.0

MD5:
8c81bb4adce06c868ed162b5a6793827

SHA-1:
8debaa735f01bd4dafe9912d773977108bb716cb

SHA-256:
2a225f451ab7f87e9f231482c325794e2808405a57f709b3828dcb6dfb8b3e3a

Scanner detections:
15 / 68

Status:
Adware

Analysis date:
11/18/2024 9:35:48 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Strictor.64185
492

Arcabit
Trojan.Application.Strictor.DFAB9
1.0.0.567

AVG
Generic
2016.0.2970

Bitdefender
Gen:Variant.Application.Strictor.64185
1.0.20.1365

Bkav FE
W32.HfsAdware
1.3.0.7237

Dr.Web
Adware.Downware.12026
9.0.1.0273

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.96362
8.15.10.09.05

ESET NOD32
Win32/Toolbar.Montiera.R potentially unwanted (variant)
9.12329

F-Secure
Gen:Variant.Application.Strictor
11.2015-30-09_4

G Data
Gen:Variant.Application.Strictor.64185
15.9.25

Kaspersky
not-a-virus:Downloader.Win32.Montiera
14.0.0.1345

Malwarebytes
PUP.Optional.PayByAds
v2015.09.30.10

MicroWorld eScan
Gen:Variant.Application.Strictor.64185
16.0.0.819

Reason Heuristics
PUP.Montiera.KeepMySearch.Installer (M)
15.9.30.22

VIPRE Antivirus
Trojan.Win32.Generic
44338

File size:
452.3 KB (463,104 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\pay-by-ads\yahoo! search\1.4.2.9\dsrsetup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
9/7/2014 5:00:00 PM

Valid to:
11/12/2015 4:00:00 AM

Subject:
CN=Keep-My-Search LTD, O=Keep-My-Search LTD, L=Tel Aviv, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
087407E453FFF7E46DB51873975E63CB

File PE Metadata
Compilation timestamp:
9/29/2015 9:09:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Y8tbgPlDdfF+LB4d7fCMw0ODZXJTdSAVvK:hqLNvODPTdL

Entry address:
0x37F9A

Entry point:
E8, 63, 85, 00, 00, E9, 89, FE, FF, FF, CC, B8, 47, 10, 44, 00, A3, 60, 54, 46, 00, C7, 05, 64, 54, 46, 00, 3D, 07, 44, 00, C7, 05, 68, 54, 46, 00, F1, 06, 44, 00, C7, 05, 6C, 54, 46, 00, 2A, 07, 44, 00, C7, 05, 70, 54, 46, 00, 93, 06, 44, 00, A3, 74, 54, 46, 00, C7, 05, 78, 54, 46, 00, BF, 0F, 44, 00, C7, 05, 7C, 54, 46, 00, AF, 06, 44, 00, C7, 05, 80, 54, 46, 00, 11, 06, 44, 00, C7, 05, 84, 54, 46, 00, 9D, 05, 44, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 50, 90, 00, 00...
 
[+]

Entropy:
6.3424

Code size:
315 KB (322,560 bytes)

Program Uninstaller
Program name:
Yahoo! Search

Display publisher:
Pay-By-Ads

Uninstall string:
"C:\users\{user}\appdata\local\pay-by-ads\yahoo! search\1.4.2.9\dsrsetup.exe" \uninstl


The file dsrsetup.exe has been discovered within the following program.

Yahoo! Search  by Pay-by-Ads Ltd
This is NOT associated with Yahoo. Pay-By-Ads' Yahoo! Search is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
66% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-216-166.mrs50.r.cloudfront.net  (54.230.216.166:80)

TCP (HTTP):
Connects to c4.3e.559e.ip4.static.sl-reverse.com  (158.85.62.196:80)

TCP (HTTP):
Connects to server-54-230-216-227.mrs50.r.cloudfront.net  (54.230.216.227:80)

TCP (HTTP):
Connects to NY1WV3659  (204.145.82.27:80)

TCP (HTTP):
Connects to NY1WV3561  (204.145.82.26:80)

TCP (HTTP):
Connects to NY1WV3438  (204.145.82.24:80)

TCP (HTTP):
Connects to ny1wv3280.xglobe.net  (204.145.82.20:80)

TCP (HTTP):
Connects to 131.subnet180-250-66.speedy.telkom.net.id  (180.250.66.131:80)

Remove dsrsetup.exe - Powered by Reason Core Security