ElectroLyrics-1

ElectroLyrics-1

Known Malware

by CrossLyrics

What is ElectroLyrics-1?

ElectroLyrics-1 is software application developed by CrossLyrics. It is most commonly found on computers running Windows 7 with nearly 64.77% of installations running this operating system. ElectroLyrics-1's installer is typically 1.00 MB in size and installs around 16 files. The most common release is 1.28.153.3 with 73.86% of all installations currently using this version.

ElectroLyrics-1 is most popular in the United States with 41.18% of installations residing in this country.

About ElectroLyrics-1?

ElectroLyrics-1 is a malicious web browser extension that is designed with the intent to commandeer the user's browser, redirecting web searches and injecting advertising. It operates as a Browser Helper Object in Internet Explorer and engages in various behaviors that compromise user experience, including hijacking advertising on unrelated websites and injecting its own advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including those from established ad serving sites. This malware is often bundled with unwanted third-party applications and spread through web browser exploits. While the program is equipped with an uninstaller and is listed in Windows Add/Remove Programs, its complete removal may prove to be challenging, often necessitating the use of anti-malware software. ElectroLyrics-1 is frequently distributed through co-bundle monetization installers, such as Amonetize ltd. (amoninst.com), and is included in 3rd party bundled apps like FlashPlayer.

Multiple virus scanners have detected malware in ElectroLyrics-1.

utils.exe (MD5: dcd2a1d3562d11267588f2f4f8355baa) has been flagged by 30 scanners:
Scanner Software Result
avast! NSIS:Adware-LH [PUP]
Baidu-International Trojan.Win32.Packed.AfS
Bitdefender Gen:Adware.AddLyrics.1
Dr.Web Trojan.Crossrider.9
Emsisoft Anti-Malware Gen:Adware.AddLyrics
ESET-NOD32 Win32/Packed.ScrambleWrapper.C
Fortinet FortiGate Adware/AddLyrics
F-Secure Gen:Adware.AddLyrics.1
G Data Gen:Adware.AddLyrics
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
TrendMicro-HouseCall TROJ_GEN.R0C1H0AIF13
VIPRE Antivirus Adware.AddLyrics (fs)
Lavasoft Ad-Aware Adware.Generic.605829
Antiy-AVL AdWare/Win32.Lyckriks
AVG Generic5.AIKL
CMC Antivirus AdWare.Win32.Lyckriks!O
Comodo Security ApplicUnwnt
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.lb
McAfee Artemis!AC3541568E18
McAfee-GW-Edition Artemis!AC3541568E18
MicroWorld-eScan Adware.Generic.605829
NANO AntiVirus Trojan.Win32.Crossrider.cidtam
Panda Antivirus Suspicious file
Sophos Generic PUA MN
Symantec Adware.Adpopup
Trend Micro TROJ_GEN.F0C2C00KT13
Vba32 AntiVirus AdWare.Lyckriks
ElectroLyrics-1-updater.exe (MD5: a4b98adc77287478c6d158ef7795955f) has been flagged by 10 scanners:
Scanner Software Result
AVG Generic_r.GS
Baidu-International Trojan.Win32.Toolbar.AXwF
Comodo Security UnclassifiedMalware
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
Malwarebytes PUP.Optional.Lyrics.A
McAfee PUP-FEJ!A4B98ADC7728
McAfee-GW-Edition PUP-FEJ!A4B98ADC7728
TrendMicro-HouseCall TROJ_GEN.R0C1H0AID13
VIPRE Antivirus Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
ElectroLyrics-1-firefoxinstaller.exe (MD5: 5a84df35f61fb0475ccdffb3ede7dfbe) has been flagged by 14 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Toolbar.CrossRider.J
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
K7 AntiVirus Trojan ( 0048e2ed1 )
K7GW Trojan ( 0048e2ed1 )
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
McAfee PUP-FEJ!5A84DF35F61F
McAfee-GW-Edition PUP-FEJ!5A84DF35F61F
Sophos Generic PUA FI
Symantec Adware.FindLyrics
TrendMicro-HouseCall TROJ_GEN.R0CBH05JB13
VIPRE Antivirus Crossrider (fs)
AVG Generic_r.GS
Comodo Security UnclassifiedMalware
ElectroLyrics-1-enabler.exe (MD5: 40893b65c91c8320221791eb27fedf7f) has been flagged by 5 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Toolbar.CrossRider.J
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
VIPRE Antivirus Crossrider (fs)
ElectroLyrics-1-codedownloader.exe (MD5: 261b8de5367337ecf4538f14e1e1a1b1) has been flagged by 2 scanners:
Scanner Software Result
Malwarebytes PUP.Optional.Lyrics.A
VIPRE Antivirus Crossrider (fs)

Startup Entries

Startup tasks:
  • ElectroLyrics-1-enabler.exe is automatically launched at startup through a scheduled task named ElectroLyrics-1-enabler.
  • ElectroLyrics-1-updater.exe is automatically launched at startup through a scheduled task named ElectroLyrics-1-updater.
  • ElectroLyrics-1-firefoxinstaller.exe is automatically launched at startup through a scheduled task named ElectroLyrics-1-firefoxinstaller.
  • ElectroLyrics-1-codedownloader.exe is automatically launched at startup through a scheduled task named ElectroLyrics-1-codedownloader.
  • ElectroLyrics-1-chromeinstaller.exe is automatically launched at startup through a scheduled task named ElectroLyrics-1-chromeinstaller.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\ElectroLyrics-1
Uninstaller:
C:\Program Files\ElectroLyrics-1\Uninstall.exe /fromcontrolpanel=1
Size:
1.00 MB
Language:
English

ElectroLyrics-1 Executable Details

Primary executable:
utils.exe
Name:
ElectroLyrics-1
Path:
C:\Program Files\ElectroLyrics-1\utils.exe
MD5:
dcd2a1d3562d11267588f2f4f8355baa
SHA-1:
–
SHA-256:
–
Files installed by ElectroLyrics-1
File Type Filename MD5
EXE
3b89b951c4a042bf0f1af73c0ec75831
EXE
bd3530fa5d13174078caef483e570a05
DLL
cbebbb251cf9760ed63eaddfd6952845
DLL
ac3541568e185c8c6d678096a078a66d
EXE
882db958faba18204ba570ece4a01352
XPI
bd6cd57290a1716620a0ac8df4e96da6