Home Malware Programs Adware Adware.AddLyrics

Adware.AddLyrics

Posted: February 26, 2013

Threat Metric

Ranking: 6,913
Threat Level: 2/10
Infected PCs: 901,744
First Seen: February 26, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Adware:Win32/Addlyrics is a browser add-on that displays lyrics for Youtube videos – but also makes your browser display additional advertisements without any means of disabling this function. While sometimes installed willingly from the addlyrics.net website, Adware:Win32/Addlyrics more often is installed through third parties, which bundle Adware:Win32/Addlyrics with unrelated applications that are installed for free. Unless you have full trust in the Addlyrics website and are certain you wish to use Adware:Win32/Addlyrics's features, SpywareRemove.com malware researchers recommend deleting Adware:Win32/Addlyrics with anti-malware software, just as they'd suggest for all similar types of adware.

The Plugin that Adds Plenty More Than Just Lyrics to Your Web Browser

Adware:Win32/Addlyrics isn't rated as entirely malicious, since Adware:Win32/Addlyrics does include lyrics-displaying features that may be beneficial for any musically-inclined Web surfers. However, SpywareRemove.com malware researchers do classify Adware:Win32/Addlyrics as adware due to its display of advertisements, which cannot be disabled and appear on sites (such as Google or Bing) that are unrelated to Adware:Win32/Addlyrics's main feature. Adware:Win32/Addlyrics's advertisements may be embedded directly into a Web page as Adware:Win32/Addlyrics is loaded or occur as pop-ups that cover the original content of a Web page. While they are clearly marked as separate from a site's main content, current advertisement formats from Adware:Win32/Addlyrics may blend in its advertisements with the normal advertising content of the websites being visited.

Adware:Win32/Addlyrics includes separate installation methods for the Google's Chrome, Microsoft's Internet Explorer and Mozilla's Firefox brands of Web browsers, thus further proving that plugin coders are doing their best to achieve cross-compatibility between browsers to maximize their profits. Each of these versions of Adware:Win32/Addlyrics may need to be removed separately, along with Adware:Win32/Addlyrics's automatic updater (which SpywareRemove.com malware researchers have confirmed to launch regularly without your permission). Ordinarily, Adware:Win32/Addlyrics will install itself to all of these browsers at the same time, rather than selecting a single browser to modify.

The PC Pied Piper to Sing Adware:Win32/Addlyrics Off of Your Browser

In a signature of Adware:Win32/Addlyrics's less than overtly malicious intentions, Adware:Win32/Addlyrics does include a default uninstaller. Nonetheless, SpywareRemove.com malware researchers still suggest using anti-malware products to clean up your PC after removing Adware:Win32/Addlyrics, since this will allow you to be certain of getting rid of all browser changes associated with Adware:Win32/Addlyrics and any other PC threats. Doing this as soon as possible after Adware:Win32/Addlyrics is spotted is suggested, since the automatic updates to Adware:Win32/Addlyrics's software (which occur on a daily basis) may enable Adware:Win32/Addlyrics to use additional functions not included in this article that could pose a security risk.

If you take heed to avoid installers from untrustworthy locations and carefully inspect all install options before installing any software, your computer should have little, if any, contact with Adware:Win32/Addlyrics, which doesn't appear to use drive-by-downloads or other malicious exploits to install itself automatically.

Aliases

AddLyrics_r.OI [AVG]PUP/AdvertisingApps [Panda]Artemis!43C0EA49FC00 [McAfee]Generic PUA AE [Sophos]Artemis!PUP [McAfee-GW-Edition]not-a-virus:AdWare.Win32.AddLyrics.dko [Kaspersky]AdWare.AddLyrics.r6 [CAT-QuickHeal]Artemis!A089F3BCD07C [McAfee]Generic_r.XA [AVG]Trojan/Win32.TSGeneric [Antiy-AVL]Adware.AddLyrics.1 [DrWeb]Artemis!D32E94F0505D [McAfee]Win32.SuspectCrc [Ikarus]Artemis!C21B073DD396 [McAfee]Generic.3E5 [AVG]
More aliases (140)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\system32\drivers\webinstrnhk.sys File name: webinstrnhk.sys
Size: 56.43 KB (56432 bytes)
MD5: 3b130f4fb69cb7312d03332d4dc42c6e
Detection count: 10,240
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\webinstrnhk.sys
Group: Malware file
Last Updated: January 31, 2022
C:\Windows.old.000\Program Files\ver2SpeedChecker\x86\webTinst.sys File name: webTinst.sys
Size: 43.56 KB (43560 bytes)
MD5: 82e0d650c5fc3db3a709e2218a717382
Detection count: 6,659
File type: System file
Mime Type: unknown/sys
Path: C:\Windows.old.000\Program Files\ver2SpeedChecker\x86\webTinst.sys
Group: Malware file
Last Updated: April 12, 2022
C:\Windows.old.000\Program Files\ver6SpeedCheck\x86\webinstrNHK.sys File name: webinstrNHK.sys
Size: 49.21 KB (49216 bytes)
MD5: 2774be9ff34177fc03748ab4d234df17
Detection count: 5,740
File type: System file
Mime Type: unknown/sys
Path: C:\Windows.old.000\Program Files\ver6SpeedCheck\x86\webinstrNHK.sys
Group: Malware file
Last Updated: March 18, 2022
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\ver2BlockAndSurf\x64\webinstrNHKT.sys.vir File name: webinstrNHKT.sys.vir
Size: 56.43 KB (56432 bytes)
MD5: 49cc36b75a20d7c7b0fa7be9840f5118
Detection count: 4,424
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\ver2BlockAndSurf\x64\webinstrNHKT.sys.vir
Group: Malware file
Last Updated: January 31, 2023
c:\windows\system32\drivers\webinstrnhkt.sys File name: webinstrnhkt.sys
Size: 43.56 KB (43560 bytes)
MD5: b0f99f135c032a816e1837a307b6776f
Detection count: 3,590
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\webinstrnhkt.sys
Group: Malware file
Last Updated: August 28, 2021
\??\C:\windows\system32\Drivers\webinstrNHKT.sys File name: webinstrNHKT.sys
Size: 50.26 KB (50264 bytes)
MD5: 428cb469ef499de03452814f0493699f
Detection count: 2,806
File type: System file
Mime Type: unknown/sys
Path: \??\C:\windows\system32\Drivers
Group: Malware file
Last Updated: April 22, 2020
\??\C:\Windows\system32\Drivers\webinstrNHK.sys File name: webinstrNHK.sys
Size: 56.43 KB (56432 bytes)
MD5: 9a81d42eda50d12a6775c96af28035db
Detection count: 2,576
File type: System file
Mime Type: unknown/sys
Path: \??\C:\Windows\system32\Drivers
Group: Malware file
Last Updated: October 18, 2018
C:\Program Files (x86)\ver9PaceItUp\x64\webinstrNHKT.sys File name: webinstrNHKT.sys
Size: 50.8 KB (50800 bytes)
MD5: c5cb03065308e25a900480277c0ebb56
Detection count: 2,113
File type: System file
Mime Type: unknown/sys
Path: C:\Program Files (x86)\ver9PaceItUp\x64\webinstrNHKT.sys
Group: Malware file
Last Updated: August 27, 2023
%WINDIR%\System32\drivers\webTinstMK.sys File name: webTinstMK.sys
Size: 50.8 KB (50800 bytes)
MD5: 8841a35c4479d703613d91e25312d77a
Detection count: 749
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers\webTinstMK.sys
Group: Malware file
Last Updated: August 8, 2022
%PROGRAMFILES%\LyricsParty\LprtyUP.exe File name: LprtyUP.exe
Size: 229.88 KB (229888 bytes)
MD5: d0992437b0afe72f0958dd863ef1964a
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\LyricsParty
Group: Malware file
Last Updated: September 14, 2016
%PROGRAMFILES(x86)%\LyricsParty\LyricsParty155.exe File name: LyricsParty155.exe
Size: 180.22 KB (180224 bytes)
MD5: 080d0c14cf938d908212847fa61ef212
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\LyricsParty
Group: Malware file
Last Updated: September 14, 2016
%PROGRAMFILES%\LyricsNotes\120.dll File name: 120.dll
Size: 185.85 KB (185856 bytes)
MD5: 65fb64d8b08781ab1fa6928f7894f1ac
Detection count: 43
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\LyricsNotes
Group: Malware file
Last Updated: August 11, 2017
%PROGRAMFILES%\ElectroLyrics-1\ElectroLyrics-1-helper.exe File name: ElectroLyrics-1-helper.exe
Size: 311.29 KB (311296 bytes)
MD5: ffbd082e18d9f8812c099669c32657c5
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ElectroLyrics-1
Group: Malware file
Last Updated: January 23, 2023
%PROGRAMFILES(x86)%\bLyrics\Uninstall.exe File name: Uninstall.exe
Size: 173.47 KB (173471 bytes)
MD5: 6b950e3d09444514cece252108550fc3
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\bLyrics
Group: Malware file
Last Updated: August 18, 2017
%PROGRAMFILES%\AddLyrics\AddLyrics.dll File name: AddLyrics.dll
Size: 20B (20 bytes)
MD5: 16351160c73346b3cbdf424e06fc4ea3
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\AddLyrics
Group: Malware file
Last Updated: March 23, 2016
\??\C:\Windows\system32\Drivers\webTinstMKTN.sys File name: webTinstMKTN.sys
Size: 14.04 KB (14040 bytes)
MD5: 3a5e5dc16b59de998b7ef770c4a26a85
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: \??\C:\Windows\system32\Drivers
Group: Malware file
Last Updated: June 10, 2017
%PROGRAMFILES(x86)%\ver4ElectroLyrics\S2ElectroLyricsp.exe File name: S2ElectroLyricsp.exe
Size: 101.37 KB (101376 bytes)
MD5: 20c11cfedb2ccb4783a6561f99698370
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ver4ElectroLyrics
Group: Malware file
Last Updated: September 14, 2016
%PROGRAMFILES(x86)%\ver4ElectroLyrics\w7ElectroLyricsBb175.exe File name: w7ElectroLyricsBb175.exe
Size: 161.28 KB (161280 bytes)
MD5: 8d4f4f59a51ed8f67f436e055bd0efe1
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ver4ElectroLyrics
Group: Malware file
Last Updated: September 14, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{A3DAEB01-4C15-4AC6-A689-6406FD954EE0}Regexp file mask%LOCALAPPDATA%\AddLyrics.exe%WINDIR%\system32\Drivers\webinstrNew.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\AddLyricsSoftware\AppDataLow\Software\AddLyricsSoftware\AppDataLow\Software\SuperLyrics-1SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\AddLyrics-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\AddLyrics-bg.exeSYSTEM\ControlSet001\Enum\Root\LEGACY_WEBTINSTMKTN84SYSTEM\ControlSet001\services\webTinstMKTN84SYSTEM\ControlSet002\Enum\Root\LEGACY_WEBTINSTMKTN84SYSTEM\ControlSet002\services\webTinstMKTN84SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WEBTINSTMKTN84SYSTEM\CurrentControlSet\services\webTinstMKTN84

Additional Information

The following directories were created:
%LOCALAPPDATA%\AddLyrics%PROGRAMFILES%\AddLyrics%PROGRAMFILES%\Auto-Lyrics%PROGRAMFILES%\CoolLyrics%PROGRAMFILES%\DealsCompare%PROGRAMFILES%\EZLyrics%PROGRAMFILES%\GetLyrics%PROGRAMFILES%\Lyrics-Show%PROGRAMFILES%\LyricsBD%PROGRAMFILES%\LyricsDroid%PROGRAMFILES%\LyricsPlus%PROGRAMFILES%\Lyrics_Fan%PROGRAMFILES%\M-Lyrics%PROGRAMFILES%\Show-Lyrics%PROGRAMFILES%\Super_Lyrics%PROGRAMFILES%\XingHaoLyrics%PROGRAMFILES%\bLyrics%PROGRAMFILES%\coolwords corp%PROGRAMFILES%\show-password-soft%PROGRAMFILES(x86)%\AddLyrics%PROGRAMFILES(x86)%\Auto-Lyrics%PROGRAMFILES(x86)%\Cool-Lyrics%PROGRAMFILES(x86)%\CoolLyrics%PROGRAMFILES(x86)%\DealsCompare%PROGRAMFILES(x86)%\EZLyrics%PROGRAMFILES(x86)%\GetLyrics%PROGRAMFILES(x86)%\LyricSearch%PROGRAMFILES(x86)%\Lyrics-Show%PROGRAMFILES(x86)%\LyricsBD%PROGRAMFILES(x86)%\LyricsDroid%PROGRAMFILES(x86)%\LyricsPlus%PROGRAMFILES(x86)%\LyricsWatch%PROGRAMFILES(x86)%\Lyrics_Fan%PROGRAMFILES(x86)%\M-Lyrics%PROGRAMFILES(x86)%\MLyrics%PROGRAMFILES(x86)%\Show-Lyrics%PROGRAMFILES(x86)%\Super_Lyrics%PROGRAMFILES(x86)%\XingHaoLyrics%PROGRAMFILES(x86)%\bLyrics%PROGRAMFILES(x86)%\coolwords corp%PROGRAMFILES(x86)%\find-a-deal%PROGRAMFILES(x86)%\show-password-soft%UserProfile%\Local Settings\Application Data\AddLyrics
Loading...