LyricsSay-16

LyricsSay-16

Known Toolbar

by FIRSERIA

What is LyricsSay-16?

LyricsSay-16 is software application developed by FIRSERIA. It is most commonly found on computers running Windows 7 with nearly 48.44% of installations running this operating system. LyricsSay-16's installer is typically 4.00 MB in size and installs around 15 files.

LyricsSay-16 is most popular in the United States with 43.06% of installations residing in this country.

About LyricsSay-16?

Lyrics Say is presented to users as part of a co-bundled offer with the purported aim of displaying lyrics while viewing YouTube videos. However, its actual function involves the display of search ads through web browser hijacking. Operated primarily as a potentially unwanted application, Lyrics Say functions as a toolbar and web extension within the web browser. The application's main objective is to seize control of the user's browser, manipulating the search provider and redirecting web searches to affiliated search engine partners (SERPs) with whom the publisher holds revenue relationships. The toolbar/extension engages in various tactics to increase the likelihood of user clicks on sponsored advertisements via search and other ad-supported mechanisms. This includes altering the web browser's default home page to a partner search portal and modifying the browser's search provider, built-in search box, and address bar.

Multiple virus scanners have detected malware in LyricsSay-16.

LyricsSay-16-updater.exe (MD5: 3828335fe3cf5db370791d14ab6359ea) has been flagged by 13 scanners:
Scanner Software Result
Baidu-International HackTool.Win32.CrossRider.K
Dr.Web Adware.Plugin.73
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.K
Fortinet FortiGate Adware/Lyckriks
Malwarebytes PUP.Optional.Adlyrics
McAfee PUP-FEJ!3828335FE3CF
McAfee-GW-Edition PUP-FEJ!3828335FE3CF
TrendMicro-HouseCall TROJ_GEN.R0CBH06KB13
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AJKA
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Bkav FE W32.Clod7ad.Trojan.8141
Microsoft Security Essentials Adware:Win32/AddLyrics
LyricsSay-16-firefoxinstaller.exe (MD5: d65065e841be455a718a8705c18cb4dd) has been flagged by 17 scanners:
Scanner Software Result
Baidu-International Trojan.Win32.Toolbar.CrossRider.J
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
K7 AntiVirus Trojan ( 0048c68d1 )
K7GW Trojan ( 0048c68d1 )
Malwarebytes PUP.Optional.Adlyrics
McAfee PUP-FEJ!D65065E841BE
McAfee-GW-Edition PUP-FEJ!D65065E841BE
Sophos Generic PUA DK
Symantec Adware.FindLyrics
TrendMicro-HouseCall TROJ_GEN.R0C1H05JK13
VIPRE Antivirus Crossrider (fs)
Dr.Web Adware.Plugin.73
Fortinet FortiGate Adware/Lyckriks
AVG Generic5.AJKA
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Bkav FE W32.Clod7ad.Trojan.8141
Microsoft Security Essentials Adware:Win32/AddLyrics
LyricsSay-16-enabler.exe (MD5: c5af9d56545028c104b86baefc699ec2) has been flagged by 12 scanners:
Scanner Software Result
AVG Generic5.AJKA
Baidu-International Trojan.Win32.Toolbar.CrossRider.J
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Adlyrics
McAfee PUP-FEJ!C5AF9D565450
McAfee-GW-Edition PUP-FEJ!C5AF9D565450
TrendMicro-HouseCall TROJ_GEN.R0CBH06KC13
VIPRE Antivirus Crossrider (fs)
Bkav FE W32.Clod7ad.Trojan.8141
Microsoft Security Essentials Adware:Win32/AddLyrics
Fortinet FortiGate Adware/Lyckriks
LyricsSay-16-codedownloader.exe (MD5: 4ba00beaec2f498b965e0dea64b63c22) has been flagged by 6 scanners:
Scanner Software Result
Baidu-International Adware.Win32.Lyrics.83
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.K
Fortinet FortiGate Adware/Lyckriks
Malwarebytes PUP.Optional.Adlyrics
TrendMicro-HouseCall TROJ_GEN.R0CBH06KG13
VIPRE Antivirus Crossrider (fs)
LyricsSay-16-chromeinstaller.exe (MD5: 07e4730a257116ddc7a19fed788f928b) has been flagged by 25 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Lyckriks
AVG Generic5
Baidu-International Trojan.Win32.Toolbar.CrossRider.J
Bitdefender Adware.Generic.610381
Bkav FE W32.Clod023.Trojan
Emsisoft Anti-Malware Adware.Generic.610381
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.K
F-Secure Adware.Generic.610381
G Data Adware.Generic.610381
K7 AntiVirus Trojan
K7GW Trojan ( 0048c68d1 )
Kaspersky not-a-virus:AdWare.Win32.Lyckriks
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Adlyrics
McAfee PUP-FEJ!07E4730A2571
McAfee-GW-Edition PUP-FEJ!07E4730A2571
MicroWorld-eScan Adware.Generic.610381
Sophos Generic PUA HO
Symantec Adware.FindLyrics
Trend Micro TROJ_GEN.R0CBC0OKG13
TrendMicro-HouseCall TROJ_GEN.R0CBC0OKG13
VIPRE Antivirus Crossrider (fs)
Dr.Web Adware.Plugin.73
Fortinet FortiGate Adware/Lyckriks
Microsoft Security Essentials Adware:Win32/AddLyrics

Startup Entries

Startup tasks:
  • LyricsSay-16-firefoxinstaller.exe is automatically launched at startup through a scheduled task named LyricsSay-16-firefoxinstaller.
  • LyricsSay-16-updater.exe is automatically launched at startup through a scheduled task named LyricsSay-16-updater.
  • LyricsSay-16-enabler.exe is automatically launched at startup through a scheduled task named LyricsSay-16-enabler.
  • LyricsSay-16-codedownloader.exe is automatically launched at startup through a scheduled task named LyricsSay-16-codedownloader.
  • LyricsSay-16-chromeinstaller.exe is automatically launched at startup through a scheduled task named LyricsSay-16-chromeinstaller.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\lyricssay-16
Uninstaller:
C:\Program Files\LyricsSay-16\Uninstall.exe /fromcontrolpanel=1
Size:
4.00 MB
Language:
English

LyricsSay-16 Executable Details

Primary executable:
utils.exe
Name:
LyricsSay-16
Path:
C:\Program Files\lyricssay-16\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by LyricsSay-16
File Type Filename MD5
EXE
756f238d9d267a4a550f792f5522c68e
EXE
a0bdc8051a740904d9e5f24d697f6875
EXE
c4a814439f70cf369dc0b93edd24df97
DLL
868b962d9826568a4484c76c6626b577
DLL
58492586f8fb221c5e459d357703153b
EXE
3828335fe3cf5db370791d14ab6359ea
EXE
d65065e841be455a718a8705c18cb4dd
EXE
c5af9d56545028c104b86baefc699ec2
EXE
4ba00beaec2f498b965e0dea64b63c22
EXE
07e4730a257116ddc7a19fed788f928b