Solved! Use DSRSETUP.EXE (Trojan Artemis) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DSRSETUP.EXE – Trojan Artemis removal

File MD5 Virus Alias
DSRSETUP.EXE 10b2c9b29985f055af0b35f2bb13beb0 Trojan Artemis
DSRSETUP.EXE 10b2c9b29985f055af0b35f2bb13beb0 Trojan UnwantedProgram
DSRSETUP.EXE 10b2c9b29985f055af0b35f2bb13beb0 Trojan Generic
DSRSETUP.EXE 10b2c9b29985f055af0b35f2bb13beb0 Trojan Eldorado
DSRSETUP.EXE 10b2c9b29985f055af0b35f2bb13beb0 Trojan Downloader
DSRSETUP.EXE 10b2c9b29985f055af0b35f2bb13beb0 Trojan Agent

DSRSETUP.EXE size: 457472 bytes
DSRSETUP.EXE hash: 10B2C9B29985F055AF0B35F2BB13BEB0

Created files:

%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\chromext64.dll
%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\dsrlte.exe
%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\dsrsetup.exe
%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\hlpr64.exe
%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\res.dll
%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\uckpdfcS.dll
%Program Files%\Pay-By-Ads\Yahoo! Search\1.3.26.12\Xmnjnyfx.dll
%AppData%\Microsoft\CryptnetUrlCache\Content\34DA60AA966CD9270C5362E6AEF824CF
%AppData%\Microsoft\CryptnetUrlCache\Content\74FBF93595CFC8459196065CE54AD928
%AppData%\Microsoft\CryptnetUrlCache\MetaData\34DA60AA966CD9270C5362E6AEF824CF
%AppData%\Microsoft\CryptnetUrlCache\MetaData\74FBF93595CFC8459196065CE54AD928

Detected by UnHackMe:

DSRSETUP.EXE
Default location: %PROGRAM FILES%\PAY-BY-ADS\YAHOO! SEARCH\1.3.26.12\DSRSETUP.EXE

Dropper information:
MD5: eee9ea850aa8dce4b76c8b94352aa000
File size: 1203968 bytes

Leave a Reply