dsrsetup.exe

Keep-My-Search LTD

The application dsrsetup.exe by Keep-My-Search has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the uninstaller utility registered in the Windows Control Panel for the program $crrUnisntlDsply$ by $cmpny$. This file is typically installed with the program Yahoo! Search by Pay-by-Ads Ltd which is a potentially unwanted software program. It is also typically executed from the user's temporary directory.
Publisher:
Keep-My-Search LTD  (signed and verified)

Version:
1.3.0.0

MD5:
8c81bb4adce06c868ed162b5a6793827

SHA-1:
bb98d1d4888e945671d6642b44602cc7d35fa478

SHA-256:
2a225f451ab7f87e9f231482c325794e2808405a57f709b3828dcb6dfb8b3e3a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/9/2024 4:52:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera (M)
17.3.6.11

File size:
452.3 KB (463,104 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\dsrsetup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
9/8/2014 5:30:00 AM

Valid to:
11/12/2015 5:30:00 PM

Subject:
CN=Keep-My-Search LTD, O=Keep-My-Search LTD, L=Tel Aviv, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
087407E453FFF7E46DB51873975E63CB

File PE Metadata
Compilation timestamp:
9/29/2015 9:39:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x37F9A

Entry point:
E8, 63, 85, 00, 00, E9, 89, FE, FF, FF, CC, B8, 47, 10, 44, 00, A3, 60, 54, 46, 00, C7, 05, 64, 54, 46, 00, 3D, 07, 44, 00, C7, 05, 68, 54, 46, 00, F1, 06, 44, 00, C7, 05, 6C, 54, 46, 00, 2A, 07, 44, 00, C7, 05, 70, 54, 46, 00, 93, 06, 44, 00, A3, 74, 54, 46, 00, C7, 05, 78, 54, 46, 00, BF, 0F, 44, 00, C7, 05, 7C, 54, 46, 00, AF, 06, 44, 00, C7, 05, 80, 54, 46, 00, 11, 06, 44, 00, C7, 05, 84, 54, 46, 00, 9D, 05, 44, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 50, 90, 00, 00...
 
[+]

Entropy:
6.3424

Code size:
315 KB (322,560 bytes)

Program Uninstaller
Program name:
$crrUnisntlDsply$

Display publisher:
$cmpny$

Uninstall string:
"C:\users\{user}\appdata\local\temp\{random}.tmp\uninstl


The file dsrsetup.exe has been discovered within the following program.

Yahoo! Search  by Pay-by-Ads Ltd
This is NOT associated with Yahoo. Pay-By-Ads' Yahoo! Search is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
66% remove it
 
Powered by Should I Remove It?

Remove dsrsetup.exe - Powered by Reason Core Security