mysearchs.exe

PayByAds ltd.

The application mysearchs.exe by PayByAds ltd has been detected as adware by 24 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named MySearchs triggered by a time event. This file is typically installed with the program MySearchs by Montiera Technologies LTD which is a potentially unwanted software program. While running, it connects to the Internet address server-54-230-38-139.jfk1.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Pay By Ads LTD  (signed by PayByAds ltd.)

Version:
1.3.0.0

MD5:
099883589fcb3f203e01dd2b659a83e3

SHA-1:
43fa920f16127560d0f6d88bdbe6581b79a0fe2b

SHA-256:
b54a37544627237c663e5b31f12a500079a0a6e276c6ff6ca00814981435ba64

Scanner detections:
24 / 68

Status:
Adware

Analysis date:
5/4/2024 3:50:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.PAI
750

Avira AntiVirus
Adware/Montiera.532840
7.11.185.150

AVG
Paybyads
2015.0.3328

Baidu Antivirus
Hacktool.Win32.Montiera
4.0.3.15116

Bitdefender
Adware.Agent.PAI
1.0.20.80

Comodo Security
UnclassifiedMalware
20077

Dr.Web
Adware.Searcher.2712
9.0.1.016

ESET NOD32
Win32/Toolbar.Montiera (variant)
8.10489

Fortinet FortiGate
Riskware/Montiera
1/16/2015

G Data
Adware.Agent.PAI
15.1.24

IKARUS anti.virus
not-a-virus:Downloader.Montiera
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.14021

Kaspersky
not-a-virus:Downloader.Win32.Montiera
14.0.0.3137

Malwarebytes
PUP.Optional.PayByAds.A
v2014.10.07.01

McAfee
RDN/Generic PUP.x!c2e
5600.6884

MicroWorld eScan
Adware.Agent.PAI
16.0.0.48

Panda Antivirus
Trj/Chgt.I
14.10.07.01

Qihoo 360 Security
Win32/Virus.Downloader.42e
1.0.0.1015

Reason Heuristics
PUP.Task.Montiera
15.1.16.1

Sophos
PayByAds
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0EJG14
7.2.16

Trend Micro
TROJ_GEN.R0C1C0EJG14
10.465.16

Vba32 AntiVirus
Downloader.Montiera
3.12.26.3

VIPRE Antivirus
Montiera
33558

File size:
520.4 KB (532,840 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\mysearchs\mysearchs\1.3.14.2\mysearchs.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/28/2014 2:00:00 AM

Valid to:
7/29/2015 1:59:59 AM

Subject:
CN=PayByAds ltd., O=PayByAds ltd., STREET="Herbert Samuel, 46", L=Tel Aviv, S=Israel, PostalCode=6330303, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CA9E6FD9AC89FBB9BC192CA9530A98F5

File PE Metadata
Compilation timestamp:
9/29/2014 10:24:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:ECD5Xt5bCvNoCM45rUivvfEym4i0lDATxpyHR2DmNJ:OBvg4i0lDCAx2DmNJ

Entry address:
0x41529

Entry point:
E8, 4A, 84, 00, 00, E9, 89, FE, FF, FF, B8, BD, A4, 44, 00, A3, D0, 39, 47, 00, C7, 05, D4, 39, 47, 00, B3, 9B, 44, 00, C7, 05, D8, 39, 47, 00, 67, 9B, 44, 00, C7, 05, DC, 39, 47, 00, A0, 9B, 44, 00, C7, 05, E0, 39, 47, 00, 09, 9B, 44, 00, A3, E4, 39, 47, 00, C7, 05, E8, 39, 47, 00, 35, A4, 44, 00, C7, 05, EC, 39, 47, 00, 25, 9B, 44, 00, C7, 05, F0, 39, 47, 00, 87, 9A, 44, 00, C7, 05, F4, 39, 47, 00, 13, 9A, 44, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 38, 8F, 00, 00, DB...
 
[+]

Code size:
359.5 KB (368,128 bytes)

Scheduled Task
Task name:
MySearchs

Trigger:
Time (Next runs on 07/10/2014 at 19:35)


The file mysearchs.exe has been discovered within the following program.

MySearchs  by Montiera Technologies LTD
Pay-By-Ads from Montiera is a web browser search injector and hijacker which also includes an installer which bundles legitimate and open-sourced programs with offers for additional third party applications that may be unwanted by the user.
www.montiera.com
87% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-38-139.jfk1.r.cloudfront.net  (54.230.38.139:80)

TCP (HTTP):
Connects to float.1143.bm-impbus.prod.fra1.adnexus.net  (37.252.170.1:80)

TCP (HTTP):

TCP (HTTP):
Connects to bzq-218-31-162.cablep.bezeqint.net  (81.218.31.162:80)

TCP (HTTP SSL):
Connects to a23-37-84-101.deploy.static.akamaitechnologies.com  (23.37.84.101:443)

TCP (HTTP):
Connects to a23-214-71-131.deploy.static.akamaitechnologies.com  (23.214.71.131:80)

TCP (HTTP):
Connects to 67-217-177-94.ash01.latisys.net  (67.217.177.94:80)

TCP (HTTP):
Connects to 67-217-177-158.ash01.latisys.net  (67.217.177.158:80)

Remove mysearchs.exe - Powered by Reason Core Security