Threat Database Adware Adware.AddLyrics

Adware.AddLyrics

By CagedTech in Adware
Published:
Last updated:

Threat Scorecard

Popularity Rank: 8,650
Threat Level: 20 % (Normal)
Infected Computers: 385,337
First Seen: February 26, 2013
Last Seen: September 29, 2026
OS(es) Affected: Windows

The detection of Adware.AddLyrics on your system indicates the presence of a potentially unwanted program that may be causing unwanted advertisements and potentially collecting your browsing data. Adware programs like this one are designed to generate revenue for their creators by displaying ads, often in the form of pop-ups, banners, or sponsored search results. In this report, we will provide an overview of what Adware.AddLyrics is, how it operates, the symptoms of infection, and steps you can take to remove it from your system.

What Is Adware.AddLyrics?

Adware.AddLyrics is a type of adware program that is designed to display unwanted advertisements on your computer. The name "AddLyrics" suggests that it may be related to music or lyrics, but it is unlikely to be a legitimate program that provides a useful service. Instead, it is likely to be a program that is designed to generate revenue for its creators by displaying ads and collecting your browsing data. Adware programs like Adware.AddLyrics are often bundled with other software or downloaded from the internet, and they can be difficult to remove without the right tools and techniques.

How Adware.AddLyrics Operates

Adware.AddLyrics operates by installing itself on your system and then displaying unwanted advertisements. It may do this by adding a browser extension or plugin to your web browser, or by installing a program that runs in the background and displays ads. The program may also collect your browsing data, including your search history and the websites you visit, in order to display targeted ads. This can be a privacy concern, as your browsing data may be shared with third parties or used to display ads that are tailored to your interests.

Symptoms of Infection

The symptoms of an Adware.AddLyrics infection can vary, but common signs include unwanted advertisements, such as pop-ups, banners, or sponsored search results. You may also notice that your web browser is slow or unresponsive, or that your system is running slowly. In some cases, you may see a new browser extension or plugin that you did not install, or you may notice that your homepage or search engine has been changed. If you are experiencing any of these symptoms, it is likely that your system is infected with Adware.AddLyrics or another type of adware program.

How to Remove Adware.AddLyrics

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading and to allow you to access the internet.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove the adware.
  3. Uninstall any suspicious programs that you do not recognize or that you did not install intentionally.
  4. Reset your web browser to its default settings, including Chrome, Firefox, and Edge, to remove any unwanted extensions or plugins.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the adware has been completely removed.

Conclusion

In conclusion, Adware.AddLyrics is a potentially unwanted program that can cause unwanted advertisements and collect your browsing data. By understanding how it operates and the symptoms of infection, you can take steps to remove it from your system and prevent future infections. It is always a good idea to be cautious when downloading software or clicking on links from the internet, and to use reputable anti-malware tools to protect your system from adware and other types of malware. By following the steps outlined in this report, you can help to keep your system safe and secure.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG AddLyrics_r.OI
Panda PUP/AdvertisingApps
McAfee Artemis!43C0EA49FC00
Sophos Generic PUA AE
McAfee-GW-Edition Artemis!PUP
Kaspersky not-a-virus:AdWare.Win32.AddLyrics.dko
CAT-QuickHeal AdWare.AddLyrics.r6
McAfee Artemis!A089F3BCD07C
AVG Generic_r.XA
Antiy-AVL Trojan/Win32.TSGeneric
McAfee Artemis!D32E94F0505D
Ikarus Win32.SuspectCrc
McAfee Artemis!C21B073DD396
AVG Generic.3E5
Ikarus PUA.AddLyrics

SpyHunter Detects & Remove Adware.AddLyrics

File System Details

Adware.AddLyrics may create the following file(s):
# File Name MD5 Detections
1. webinstrNewH.sys fe56abb7e2f8e279ba12e3b156edfb01 3,088
2. webinstrNew.sys c21b073dd39644db158a93070a6e6ea8 3,065
3. webTinst.sys 82e0d650c5fc3db3a709e2218a717382 2,843
4. webinstrNHK.sys 2774be9ff34177fc03748ab4d234df17 2,451
5. webinstrh.sys 4ea2efc7a4ccd37174160e0fb0677706 2,082
6. webinstrnhkt.sys b0f99f135c032a816e1837a307b6776f 1,534
7. webinstrT.sys d32e94f0505df666706e0939d596bc90 1,423
8. webinstrH.sys.vir 0838b7a97de8072f59d69ffe3b0e765b 1,404
9. webinstrNHKT.sys.vir 1712807a9c919fd1da58640ffb97d7c0 1,395
10. webTinstMKTN.sys.vir 545b5ddae4305cbd52b8909806e5517e 1,018
11. LyricsTabyY161.exe 8c02778765ad8a134b5a413c41c2ab77 76
12. LyricsTaby.exe c8e092fb35c243f9cf9c7fa0302c2892 76
13. LyricsTabPUE.exe e72106bf925e283d263ccb1cb3206c66 49
14. show-passwordh.exe f45a4b01a673ceb3a7e5c41c19759ac4 17
15. ElectroLyrics-1-helper.exe ffbd082e18d9f8812c099669c32657c5 15
16. Uninstall.exe 6b950e3d09444514cece252108550fc3 8
17. di6LyricsArtN22.exe a68b46ebfaf878746da50277271021f0 2
18. AddLyrics.dll 16351160c73346b3cbdf424e06fc4ea3 2
19. 128.dll f8151683310be2896883079071e6e51f 2
20. webTinstMKTN.sys 3a5e5dc16b59de998b7ef770c4a26a85 2
21. A2ElectroLyricsr14.exe 74336377c5d2e8d2772b4056a89c829c 1
22. 175.dll 97afe33381b0f411045152f87529c9e6 1
23. LyricsParty155.exe 080d0c14cf938d908212847fa61ef212 1
24. webTinstMK.sys cdbd731c9d7e882464ab815f3694ec40 1
25. l6ElectroLyricsO05.exe f0db79bf3ed5f10fa2ba85c6eb5c8e97 1
26. 120.dll 65fb64d8b08781ab1fa6928f7894f1ac 1
27. w7ElectroLyricsBb175.exe 8d4f4f59a51ed8f67f436e055bd0efe1 1
28. S2ElectroLyricsp.exe 20c11cfedb2ccb4783a6561f99698370 1
29. LprtyUP.exe d0992437b0afe72f0958dd863ef1964a 1
More files

Registry Details

Adware.AddLyrics may create the following registry entry or registry entries:
CLSID
{A3DAEB01-4C15-4AC6-A689-6406FD954EE0}
Regexp file mask
%LOCALAPPDATA%\AddLyrics.exe
%WINDIR%\system32\Drivers\webinstrNew.sys
SOFTWARE\AddLyrics
Software\AppDataLow\Software\AddLyrics
Software\AppDataLow\Software\SuperLyrics-1
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\AddLyrics-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\AddLyrics-bg.exe
SYSTEM\ControlSet001\Enum\Root\LEGACY_WEBTINSTMKTN84
SYSTEM\ControlSet001\services\webTinstMKTN84
SYSTEM\ControlSet002\Enum\Root\LEGACY_WEBTINSTMKTN84
SYSTEM\ControlSet002\services\webTinstMKTN84
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WEBTINSTMKTN84
SYSTEM\CurrentControlSet\services\webTinstMKTN84

Directories

Adware.AddLyrics may create the following directory or directories:

%LOCALAPPDATA%\AddLyrics
%PROGRAMFILES%\AddLyrics
%PROGRAMFILES%\Auto-Lyrics
%PROGRAMFILES%\CoolLyrics
%PROGRAMFILES%\DealsCompare
%PROGRAMFILES%\EZLyrics
%PROGRAMFILES%\GetLyrics
%PROGRAMFILES%\Lyrics-Show
%PROGRAMFILES%\LyricsBD
%PROGRAMFILES%\LyricsDroid
%PROGRAMFILES%\LyricsPlus
%PROGRAMFILES%\Lyrics_Fan
%PROGRAMFILES%\M-Lyrics
%PROGRAMFILES%\Show-Lyrics
%PROGRAMFILES%\Super_Lyrics
%PROGRAMFILES%\XingHaoLyrics
%PROGRAMFILES%\bLyrics
%PROGRAMFILES%\coolwords corp
%PROGRAMFILES%\show-password-soft
%PROGRAMFILES(x86)%\AddLyrics
%PROGRAMFILES(x86)%\Auto-Lyrics
%PROGRAMFILES(x86)%\Cool-Lyrics
%PROGRAMFILES(x86)%\CoolLyrics
%PROGRAMFILES(x86)%\DealsCompare
%PROGRAMFILES(x86)%\EZLyrics
%PROGRAMFILES(x86)%\GetLyrics
%PROGRAMFILES(x86)%\LyricSearch
%PROGRAMFILES(x86)%\Lyrics-Show
%PROGRAMFILES(x86)%\LyricsBD
%PROGRAMFILES(x86)%\LyricsDroid
%PROGRAMFILES(x86)%\LyricsPlus
%PROGRAMFILES(x86)%\LyricsWatch
%PROGRAMFILES(x86)%\Lyrics_Fan
%PROGRAMFILES(x86)%\M-Lyrics
%PROGRAMFILES(x86)%\MLyrics
%PROGRAMFILES(x86)%\Show-Lyrics
%PROGRAMFILES(x86)%\Super_Lyrics
%PROGRAMFILES(x86)%\XingHaoLyrics
%PROGRAMFILES(x86)%\bLyrics
%PROGRAMFILES(x86)%\coolwords corp
%PROGRAMFILES(x86)%\find-a-deal
%PROGRAMFILES(x86)%\show-password-soft
%UserProfile%\Local Settings\Application Data\AddLyrics

Analysis Report

General information

Family Name: Adware.AddLyrics
Signature status: Root Not Trusted

Known Samples

MD5: a3777abb3124b81f6f8119f8125e138f
SHA1: 6a8312e2a7d49e786e0aef7512eb58f227dee3f4
File Size: 112.38 KB, 112384 bytes
MD5: c319acce7f5b8accdfc2bf7f5f2042dc
SHA1: a2854b11b9da7f8132f19e575e080d8e09a8dbab
SHA256: D258B9DD372C5AD5218A591A06469E52701A9A16F94D8BDC7859224AD1D5C15E
File Size: 745.98 KB, 745984 bytes
MD5: 11649169b4b87e379a8acba9c19114f5
SHA1: 725999c2d4ace814a0380c2dd0afa08bf646318a
SHA256: 153C5362AA678BB4174441D063787301A89D78151A385CCCC0EA566B97363D3B
File Size: 906.38 KB, 906376 bytes
MD5: e7310c1404d2c1327958e4877f643c36
SHA1: ae72d80022471dd698040cd668b2acfba36ebd70
SHA256: 016D7DF8B76B3E2F6FF1C52075141235ED3862A652C71CF0B06E18AA86DC617D
File Size: 403.44 KB, 403440 bytes
MD5: 7890f5025ee6d9c4f31ba0310e96b763
SHA1: cd1958d40a78d7437cbfcb6d6b11f4bed3e2eac7
SHA256: 831289914708B95FDC8A7ED84D02591E2AC07F47EF5D2F261ED639F9D8D010F9
File Size: 197.63 KB, 197632 bytes
Show More
MD5: 501102772eb00473465b699153517217
SHA1: c267404369f4400112ee3483999527b7011753d7
SHA256: 48B58CF162AC0D35DFF0A364AC8285EDEB0555D0A82E2079316BB09C3E6E506F
File Size: 8.12 MB, 8124782 bytes
MD5: 957ab1118be5d8534284980d82d170cb
SHA1: 0c04a3dee3bcb57921d41387f3b61302029e598d
SHA256: 76A886F1FCFAEEB3E0B02EB3972C62F71BE195888FFCE0A77417B0D7E0CF422D
File Size: 794.66 KB, 794656 bytes
MD5: d88d453c3ddbe7cd0056b36ffa115573
SHA1: bdc166c341e031b513527a6d2153c46e7a3971ab
SHA256: F9A1A21787C7A3FCD901E1661C908B48D26E09D15D31FB5F7C488640E8F758B9
File Size: 7.90 MB, 7900944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments QuickShare
Company Name QuickShare
File Description
  • CheckMeUp
  • QuickShare
File Version
  • 1.0
  • 1 . 1 . 0 . 0
Internal Name CheckMeUp
Legal Copyright
  • Copyright (C) 2014
  • © QuickShare
Legal Trademarks QuickShare
Original Filename CheckMeUp.exe
Product Name
  • CheckMeUp
  • QuickShare
Product Version 1 . 1 . 0 . 0

Digital Signatures

Signer Root Status
Meta Installer LLC Go Daddy Class 2 Certification Authority Root Not Trusted
Meta Installer LLC Meta Installer LLC Root Not Trusted
Meta Installer LLC Starfield Class 2 Certification Authority Root Not Trusted

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Similar Families

  • KillMBR.XE
  • Superweb.CA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\installer.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\installer_java_portuguese.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\installer_java_portuguese.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsb270d.tmp\installeronekit.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsib764.tmp\registry.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsla479.tmp\registry.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsmfd06.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsmfd06.tmp\nsurl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsmfd06.tmp\nsurl.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsr1063.tmp\headerleft.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_de.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_en.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_es.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_fr.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_it.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_nl.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\metainstallerlicense_pt.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\nsarray.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\nsisdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\nsrichedit.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr1063.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsub944.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsub944.tmp\tkdecript.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsub944.tmp\tkdecript.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsub944.tmp\version.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsub944.tmp\version.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsx1084.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\smartbarexeinstaller.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Quhkxibs\AppData\Local\Temp\nsmFD06.tmp\ RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob ់㇤㹧ৢ䗾鍗૳ᳺứ霞輫穆轙⊩㢅즔Sc愰ℰଆ虠ňŅᜇ〆〒ؐ⬊ĆĄ㞂ļ́ダ؟怉䢆蘁泽ĂሰူਆثЁ舁㰷āȃ쀀ᬰԆ腧Č〃〒ؐ⬊ĆĄ㞂ļ́翀Ā⨀ ب⬈Ćԅ̇؂⬈Ćԅ̇؃⬈Ćԅ̇؄⬈Ćԅ̇ँĀ⨀ ب⬈Ćԅ̇؂⬈Ćԅ RegNtPreCreateKey
Show More
HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob \ص�6�hbu�B�Ҫ�7N��xI��_X�V�=�gD��h~�/-������\L�A��T�a VeriSign�e�����0 �C9��313b �ϫ~C�؀�k&*����e������d��� *0( RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\root\certificates\be36a4562fb2ee05dbb3d32323adf445084ed656::blob \Ѐ볝蚽㾜ࠛ컯퇄춈ᔻᰘ兘槹镹⍋ .Thawte Timestamping CA  ਰࠆثԁ܅ࠃ㚾嚤눯׮돛⏓괣䗴丈囖晿煺硩騠ᑑ莝⃚ꗨ뺘芄ﺎ炮ᔑ㔁뉶 ʥ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetSetOption
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • inet_addr
  • socket
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\Users\Quhkxibs\AppData\Local\Temp\installer_java_Portuguese.exe
C:\Users\Shbqfagu\AppData\Local\Temp\Installer.exe
C:\Users\Duxczawf\AppData\Local\Temp\SmartbarExeInstaller.exe