LyricsBuddy-1

LyricsBuddy-1

Known Malware

by CrossLyrics

What is LyricsBuddy-1?

LyricsBuddy-1 is software application developed by CrossLyrics. It is most commonly found on computers running Windows 7 with nearly 63.24% of installations running this operating system. LyricsBuddy-1's installer is typically 7.00 MB in size and installs around 15 files. The most common release is 1.28.153.3 with 76.47% of all installations currently using this version.

LyricsBuddy-1 is most popular in the United States with 20.71% of installations residing in this country.

About LyricsBuddy-1?

LyricsBuddy-1 is a web browser extension that is designed to control the user's browser by redirecting web searches and injecting advertising. It operates as a Browser Helper Object in Internet Explorer and conducts various behaviors such as hijacking advertising on unrelated websites and injecting its own advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including the hijacking of known ad serving sites. This malware is commonly bundled with unwanted third-party applications and spread through web browser exploits. While it does come with an uninstaller and is listed in the Windows Add/Remove Programs, fully removing it can be quite challenging and may require the use of an anti-malware product.

Multiple virus scanners have detected malware in LyricsBuddy-1.

utils.exe (MD5: ea90ab30cd0b9865fbfe53ded4597475) has been flagged by 31 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Packed.ScrambleWrapper.C
Bkav FE HW32.CDB
ESET-NOD32 Win32/Packed.ScrambleWrapper.C
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
TrendMicro-HouseCall TROJ_GEN.F47V0825
VIPRE Antivirus Adware.AddLyrics (fs)
Lavasoft Ad-Aware Adware.Generic.608156
Antiy-AVL AdWare/Win32.Lyckriks
avast! Win32:AddLyrics-AU [Adw]
AVG Generic5.AIKL
Bitdefender Adware.Generic.608156
CAT-QuickHeal Adware.AddLyrics (Not a Virus)
Comodo Security UnclassifiedMalware
Dr.Web Trojan.Crossrider.7
Emsisoft Anti-Malware Adware.Generic.608156 (B)
Fortinet FortiGate Adware/Lyckriks
G Data Adware.Generic.608156
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.lb
McAfee Artemis!629DC76B3338
McAfee-GW-Edition Artemis!629DC76B3338
Microsoft Security Essentials Adware:Win32/AddLyrics
MicroWorld-eScan Adware.Generic.608156
NANO AntiVirus Riskware.Win32.Lyckriks.cqrozn
Sophos AppRider
Symantec Adware.Crossid
Trend Micro TROJ_SPNR.0BKD13
Vba32 AntiVirus AdWare.Lyckriks
Jiangmin AdWare/Lyckriks.dm
LyricsBuddy-1-updater.exe (MD5: 7cc630196deec8df90af4da5839cae5f) has been flagged by 8 scanners:
Scanner Software Result
ESET-NOD32 probably a variant of Win32/Toolbar.CrossRider.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
McAfee Artemis!7CC630196DEE
McAfee-GW-Edition Artemis!7CC630196DEE
TrendMicro-HouseCall TROJ_GEN.F47V0927
VIPRE Antivirus Crossrider (fs)
avast! Win32:AddLyrics-AV [Adw]
LyricsBuddy-1-firefoxinstaller.exe (MD5: c6ae7182eafe044810f40bb0cc7ebdee) has been flagged by 20 scanners:
Scanner Software Result
Baidu-International HackTool.Win32.CrossRider.J
Bkav FE W32.Clodc54.Trojan.95ab
Comodo Security UnclassifiedMalware
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
K7 AntiVirus Trojan ( 0048e2ed1 )
K7GW Trojan ( 0048e2ed1 )
Malwarebytes PUP.Optional.Lyrics.A
McAfee PUP-FEJ!C6AE7182EAFE
McAfee-GW-Edition PUP-FEJ!C6AE7182EAFE
Sophos Generic PUA BJ
Symantec Adware.FindLyrics
Trend Micro TROJ_SPNR.3AKH13
TrendMicro-HouseCall TROJ_SPNR.3AKH13
VIPRE Antivirus Crossrider (fs)
Antiy-AVL AdWare/Win32.Lyckriks
AVG Generic5.AIIQ
Jiangmin AdWare/Lyckriks.dm
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
avast! Win32:AddLyrics-AV [Adw]
LyricsBuddy-1-enabler.exe (MD5: 651f7cc04fd96d014c76c91f03ee26f7) has been flagged by 21 scanners:
Scanner Software Result
avast! Win32:AddLyrics-AV [Adw]
AVG Generic5.AJKB
Baidu-International Trojan.Win32.Toolbar.ay
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
McAfee PUP-FEJ!651F7CC04FD9
McAfee-GW-Edition PUP-FEJ!651F7CC04FD9
Microsoft Security Essentials Adware:Win32/AddLyrics
Sophos AppRider
Symantec Adware.BL
Trend Micro TROJ_GEN.R0CBC0SJT13
TrendMicro-HouseCall TROJ_GEN.R0CBC0SJT13
VIPRE Antivirus Crossrider (fs)
Bkav FE W32.Clodc54.Trojan.95ab
Comodo Security UnclassifiedMalware
Antiy-AVL AdWare/Win32.Lyckriks
Jiangmin AdWare/Lyckriks.dm
Vba32 AntiVirus AdWare.Lyckriks
LyricsBuddy-1-codedownloader.exe (MD5: b09677983317677c484e5d1a4ae65e66) has been flagged by 6 scanners:
Scanner Software Result
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
TrendMicro-HouseCall TROJ_GEN.R0C1H0AIE13
VIPRE Antivirus Crossrider (fs)
avast! Win32:AddLyrics-AV [Adw]

Startup Entries

Startup tasks:
  • LyricsBuddy-1-enabler.exe is automatically launched at startup through a scheduled task named LyricsBuddy-1-enabler.
  • LyricsBuddy-1-firefoxinstaller.exe is automatically launched at startup through a scheduled task named LyricsBuddy-1-firefoxinstaller.
  • LyricsBuddy-1-updater.exe is automatically launched at startup through a scheduled task named LyricsBuddy-1-updater.
  • LyricsBuddy-1-codedownloader.exe is automatically launched at startup through a scheduled task named LyricsBuddy-1-codedownloader.
  • LyricsBuddy-1-chromeinstaller.exe is automatically launched at startup through a scheduled task named LyricsBuddy-1-chromeinstaller.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\lyricsbuddy-1
Uninstaller:
C:\Program Files\LyricsBuddy-1\Uninstall.exe /fromcontrolpanel=1
Size:
7.00 MB
Language:
English

LyricsBuddy-1 Executable Details

Primary executable:
utils.exe
Name:
LyricsBuddy-1
Path:
C:\Program Files\lyricsbuddy-1\utils.exe
MD5:
ea90ab30cd0b9865fbfe53ded4597475
SHA-1:
–
SHA-256:
–
Files installed by LyricsBuddy-1
File Type Filename MD5
EXE
756f238d9d267a4a550f792f5522c68e
EXE
ea90ab30cd0b9865fbfe53ded4597475
EXE
7cc630196deec8df90af4da5839cae5f
EXE
c6ae7182eafe044810f40bb0cc7ebdee
EXE
651f7cc04fd96d014c76c91f03ee26f7
EXE
b09677983317677c484e5d1a4ae65e66
EXE
fb93c1238f40356c5d92efe64ac515f3
EXE
344e05fd9794192ab4cb14db8365602d
EXE
7bfa95f433e95aa69f7daff894ce223b
DLL
bed70d00c92f02c697eca8d005fa11c9