autolrcs.dll

Auto Lyrics

Castel Communication Ltd.

The module autolrcs.dll by Castel Communication has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Auto Lyrics’. This file is typically installed with the program Auto Lyrics by Mansoft Union which is a potentially unwanted software program.
Publisher:
Mansoft Union  (signed by Castel Communication Ltd.)

Product:
Auto Lyrics

Version:
111

MD5:
910fbefd3544be80d1edb326cec91af4

SHA-1:
2f6d8c1a512cf5cb79a6e7797bef9893aa370147

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 7:37:11 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Revizer.CastelCo (M)
16.4.12.8

File size:
130.4 KB (133,528 bytes)

Product version:
111

Copyright:
Copyright 2013

Original file name:
autolrcs.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\autolyrics\autolrcs.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/25/2013 7:00:00 PM

Valid to:
2/26/2014 6:59:59 PM

Subject:
CN=Castel Communication Ltd., O=Castel Communication Ltd., STREET=5 Oded st., L=Ramat Gan, S=Israel, PostalCode=52223, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4B95965A86A77BF4007748964F3622CC

Registration
CLSID:
{DAEB9E85-4694-4F9B-85CB-2F28987872D7}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
4/23/2013 11:45:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:qIcnPp4qO2gAmmn63a2kIdBYuPnY0lBk:Xs46Tmmnia2kIjrj

Entry address:
0x9CB7

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, AC, 56, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 60, C7, 01, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, F5, DC, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, E5, DC, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B...
 
[+]

Entropy:
6.4675

Code size:
84 KB (86,016 bytes)

Internet Explorer BHO
Display name:
Auto Lyrics

CLSID:
{DAEB9E85-4694-4F9B-85CB-2F28987872D7}


The file autolrcs.dll has been discovered within the following program.

Auto Lyrics  by Mansoft Union
Auto Lyrics is a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search.
66% remove it
 
Powered by Should I Remove It?

Remove autolrcs.dll - Powered by Reason Core Security