dsrsetup.exe

Keep-My-Search LTD

The application dsrsetup.exe by Keep-My-Search has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program Yahoo! Search by Pay-By-Ads. While running, it connects to the Internet address ny1wv3280.xglobe.net on port 80 using the HTTP protocol.
Publisher:
Pay By Ads LTD  (signed by Keep-My-Search LTD)

Version:
1.3.0.0

MD5:
937b8f29e166a73620e938f7bf926c4d

SHA-1:
846e8373f8eb9fd48f7e37f3bfa2b076858dc00e

SHA-256:
f39ca8054e889cd5873a9f41ebc2e740139d4c6a94b8c8525b05e06a71c6ca40

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/9/2024 5:30:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera (M)
17.3.6.22

File size:
1.5 MB (1,570,048 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pay-by-ads\yahoo! search\1.3.24.4\dsrsetup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
9/7/2014 9:00:00 PM

Valid to:
11/12/2015 9:00:00 AM

Subject:
CN=Keep-My-Search LTD, O=Keep-My-Search LTD, L=Tel Aviv, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
087407E453FFF7E46DB51873975E63CB

File PE Metadata
Compilation timestamp:
3/13/2015 1:30:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x35F47

Entry point:
E8, 0E, 82, 00, 00, E9, 89, FE, FF, FF, B8, 9F, EC, 43, 00, A3, E0, 23, 46, 00, C7, 05, E4, 23, 46, 00, 95, E3, 43, 00, C7, 05, E8, 23, 46, 00, 49, E3, 43, 00, C7, 05, EC, 23, 46, 00, 82, E3, 43, 00, C7, 05, F0, 23, 46, 00, EB, E2, 43, 00, A3, F4, 23, 46, 00, C7, 05, F8, 23, 46, 00, 17, EC, 43, 00, C7, 05, FC, 23, 46, 00, 07, E3, 43, 00, C7, 05, 00, 24, 46, 00, 69, E2, 43, 00, C7, 05, 04, 24, 46, 00, F5, E1, 43, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, FC, 8C, 00, 00, DB...
 
[+]

Code size:
306 KB (313,344 bytes)

Program Uninstaller
Program name:
Yahoo! Search

Display publisher:
Pay-By-Ads

Uninstall string:
"C:\Program Files\Pay-By-Ads\Yahoo! Search\1.3.24.4\dsrsetup.exe" /uninstl


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to NY1WV3659  (204.145.82.27:80)

TCP (HTTP):
Connects to ny1wv3280.xglobe.net  (204.145.82.20:80)

Remove dsrsetup.exe - Powered by Reason Core Security