LyricsMonkey-1

LyricsMonkey-1

Known Malware

by CrossLyrics

What is LyricsMonkey-1?

LyricsMonkey-1 is software application developed by CrossLyrics. It is most commonly found on computers running Windows 7 with nearly 58.70% of installations running this operating system. LyricsMonkey-1's installer is typically 8.00 MB in size and installs around 15 files. The most common release is 1.28.153.3 with 81.16% of all installations currently using this version.

LyricsMonkey-1 is most popular in the United States with 68.86% of installations residing in this country.

About LyricsMonkey-1?

LyricsMonkey-1 is a web browser extension that has been found to engage in malicious behavior. It claims to display lyrics while watching YouTube videos, but in reality, it takes control of the user's browser to redirect web searches and inject advertising. It operates as a Browser Helper Object in Internet Explorer and injects its own advertising in various forms such as contextual link ads, banner ads, and popups. This malware is often bundled with unwanted third party applications and distributed through web browser exploits. While an uninstaller is provided and the program is listed in the Windows Add/Remove Programs, completely removing LyricsMonkey-1 may be challenging and could require the use of anti-malware software.

Multiple virus scanners have detected malware in LyricsMonkey-1.

utils.exe (MD5: 5a14a3bbd439d13f202408bb614ae520) has been flagged by 29 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Packed.ScrambleWrapper.C
Bkav FE HW32.CDB
ESET-NOD32 Win32/Packed.ScrambleWrapper.C
TrendMicro-HouseCall TROJ_GEN.F47V0825
VIPRE Antivirus Adware.AddLyrics (fs)
Lavasoft Ad-Aware Adware.Generic.633271
Antiy-AVL AdWare/Win32.Lyckriks
AVG Generic5.AIKL
Bitdefender Adware.Generic.633271
Dr.Web Trojan.Crossrider.7
Emsisoft Anti-Malware Adware.Generic.633271 (B)
Fortinet FortiGate Adware/Lyckriks
G Data Adware.Generic.633271
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.lb
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
McAfee Artemis!55A5C22D6AFB
McAfee-GW-Edition Artemis!55A5C22D6AFB
Microsoft Security Essentials Adware:Win32/AddLyrics
MicroWorld-eScan Adware.Generic.633271
NANO AntiVirus Trojan.Win32.Crossrider.cjzkzc
Sophos Generic PUA CI
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R0CBC0DKH13
Vba32 AntiVirus AdWare.Lyckriks
Comodo Security UnclassifiedMalware
Panda Antivirus Suspicious file
LyricsMonkey-1-updater.exe (MD5: c0939e0e40de4c54819498eddbd9267d) has been flagged by 6 scanners:
Scanner Software Result
ESET-NOD32 probably a variant of Win32/Toolbar.CrossRider.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
TrendMicro-HouseCall TROJ_GEN.F47V0924
LyricsMonkey-1-firefoxinstaller.exe (MD5: 8d9f3643cc05ad8845745f2b71237f90) has been flagged by 6 scanners:
Scanner Software Result
Malwarebytes PUP.Optional.Lyrics.A
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0924
VIPRE Antivirus Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
LyricsMonkey-1-enabler.exe (MD5: 9042a3341297505389511960ff845879) has been flagged by 18 scanners:
Scanner Software Result
AVG Generic5.AJKA
Baidu-International HackTool.Win32.CrossRider.J
Bkav FE W32.Clod0e6.Trojan.c944
Comodo Security UnclassifiedMalware
Dr.Web Trojan.Crossrider.27
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
Fortinet FortiGate Riskware/PUP_FEJ
K7 AntiVirus Trojan ( 0048c68d1 )
K7GW Trojan ( 0048c68d1 )
Malwarebytes PUP.Optional.Lyrics.A
McAfee PUP-FEJ!9042A3341297
McAfee-GW-Edition PUP-FEJ!9042A3341297
Panda Antivirus Suspicious file
Sophos Generic PUA EJ
VIPRE Antivirus Crossrider (fs)
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Symantec Adware.FindLyrics
TrendMicro-HouseCall TROJ_GEN.R0C1H05JL13
LyricsMonkey-1-codedownloader.exe (MD5: 9bd37e7e753a08600e8d7ff2d0450ce1) has been flagged by 5 scanners:
Scanner Software Result
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.I
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Lyrics.A
VIPRE Antivirus Crossrider (fs)
TrendMicro-HouseCall TROJ_GEN.F47V0918

Startup Entries

Startup tasks:
  • LyricsMonkey-1-enabler.exe is automatically launched at startup through a scheduled task named LyricsMonkey-1-enabler.
  • LyricsMonkey-1-firefoxinstaller.exe is automatically launched at startup through a scheduled task named LyricsMonkey-1-firefoxinstaller.
  • LyricsMonkey-1-updater.exe is automatically launched at startup through a scheduled task named LyricsMonkey-1-updater.
  • LyricsMonkey-1-codedownloader.exe is automatically launched at startup through a scheduled task named LyricsMonkey-1-codedownloader.
  • LyricsMonkey-1-chromeinstaller.exe is automatically launched at startup through a scheduled task named LyricsMonkey-1-chromeinstaller.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\lyricsmonkey-1
Uninstaller:
C:\Program Files\LyricsMonkey-1\Uninstall.exe /fromcontrolpanel=1
Size:
8.00 MB
Language:
English

LyricsMonkey-1 Executable Details

Primary executable:
utils.exe
Name:
LyricsMonkey-1
Path:
C:\Program Files\lyricsmonkey-1\utils.exe
MD5:
5a14a3bbd439d13f202408bb614ae520
SHA-1:
–
SHA-256:
–
Files installed by LyricsMonkey-1
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
utils.exe
Malware
5a14a3bbd439d13f202408bb614ae520
DLL
fb6e47e6bae4cdd67c64b066d91bc892
EXE
c0939e0e40de4c54819498eddbd9267d
EXE
8d9f3643cc05ad8845745f2b71237f90
EXE
9042a3341297505389511960ff845879
EXE
9bd37e7e753a08600e8d7ff2d0450ce1
EXE
317e130b95fc421b8acc217aa60eec75
EXE
c83fa57df58f50406e0cf6b5f3135fcd
EXE
32531dbd0d27fab8427dcfabc8e253a3