Threat Database Adware Adware.Addlyrics.DC

Adware.Addlyrics.DC

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 65
First Seen: June 16, 2022
Last Seen: April 18, 2026
OS(es) Affected: Windows

The detection of Adware.Addlyrics.DC on your system indicates that your computer has been infected with a potentially unwanted program (PUP) that exhibits adware-like behavior. This type of malware is designed to display unwanted advertisements, collect user data, and potentially redirect users to malicious websites. In this report, we will provide an overview of Adware.Addlyrics.DC, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Adware.Addlyrics.DC?

Adware.Addlyrics.DC is a type of adware that is designed to display unwanted advertisements on infected systems. The name "Adware.Addlyrics.DC" suggests that it may be related to a family of adware programs that use similar tactics to infect and exploit user systems. However, without further information, it is difficult to determine the exact nature and origins of this malware. Adware programs like Adware.Addlyrics.DC are often bundled with free software downloads, infected email attachments, or exploited vulnerabilities in software.

How Adware.Addlyrics.DC Operates

Adware.Addlyrics.DC operates by infiltrating a user's system and displaying unwanted advertisements, such as pop-ups, banners, and redirects. It may also collect user data, such as browsing history, search queries, and other sensitive information, to deliver targeted advertisements. This type of malware can also slow down system performance, cause browser crashes, and increase the risk of further malware infections. Adware.Addlyrics.DC may use various tactics to evade detection, such as code obfuscation, anti-debugging techniques, and exploiting vulnerabilities in software.

Symptoms of Infection

Common symptoms of Adware.Addlyrics.DC infection include an increase in unwanted advertisements, slow system performance, browser redirects, and suspicious program installations. Users may also notice that their browser homepage or search engine has been changed without their consent. Additionally, infected systems may experience frequent crashes, freezes, or errors, which can be indicative of a larger malware problem. If you are experiencing any of these symptoms, it is essential to take immediate action to remove the malware and prevent further damage.

How to Remove Adware.Addlyrics.DC

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Adware.Addlyrics.DC.
  3. Uninstall any suspicious programs or applications that may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that all remnants of the malware have been removed.

Conclusion

In conclusion, Adware.Addlyrics.DC is a potentially unwanted program that can cause significant disruptions to your system and online activities. By following the removal steps outlined in this report, you can effectively remove the malware and prevent further damage. It is essential to remain vigilant and take proactive measures to protect your system from future malware infections, such as keeping your software up-to-date, using reputable anti-malware tools, and avoiding suspicious downloads or email attachments. By taking these steps, you can help ensure the security and integrity of your system and protect your sensitive information from potential threats.

Analysis Report

General information

Family Name: Adware.Addlyrics.DC
Signature status: No Signature

Known Samples

MD5: 559a51261b157bfa783f5d20f9c071ff
SHA1: ce37d103fb3c7eb27d063d7adbdc3c1ea901d530
SHA256: 24A763B9C3D3233AAB4188D70DD76D69C7F3A5D4726F44752AA09E5D0B55FF37
File Size: 172.96 KB, 172956 bytes
MD5: 8c34d366db5131880231335ce9242b78
SHA1: 1cb5711d5d1e0046b683d01c03134c53d89c96a8
SHA256: B4F59950638C670053024F0C2D397F1988C46003BC6449B867785ABFD751C794
File Size: 293.44 KB, 293441 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Copyright (c) 2014
File Description For Windows
File Version
  • 1.186.0.0
  • 1.157.0.0
Legal Copyright
  • Copyright (c) 2014
  • Copyright 2013

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsia8ee.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsic13d.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsic13d.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsic13d.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsnbfd5.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nssc0de.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nstaa17.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nstaa66.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstaa66.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nstaa66.tmp\iospecial.ini Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nstaa66.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l�8��8��B�8 �� �6 �v �Z 7� xy �� �aT�B���������%���5����Bx�<�!!wz"Wc#�#��$kF$��%:�%�&� '�!(�(X�(�) ;*J*9*�"+�[,=�,��/9�/��1`1�1HO1�D5,]5�05�G9ߔ<.:>3� RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Evfzfyuu\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Mhhyvqpz\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\

Related Posts

Trending

Most Viewed

Loading...