autolrcs.dll

Auto Lyrics

Castel Communication Ltd.

The module autolrcs.dll by Castel Communication has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Auto Lyrics’. This file is typically installed with the program Auto Lyrics by Mansoft Union which is a potentially unwanted software program.
Publisher:
Mansoft Union  (signed by Castel Communication Ltd.)

Product:
Auto Lyrics

Version:
111

MD5:
5b2a7832f3c8d4b47ffcac9a133595ad

SHA-1:
bb5643dfa65825beafd77c8606c2e5571351b930

SHA-256:
5a90af1bfde8f8c5c585e9deb18419a8d97d6ca02a2dd23ccb3220edfc11aef6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 2:00:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Revizer.CastelCo (M)
16.3.15.2

File size:
127.7 KB (130,800 bytes)

Product version:
111

Copyright:
Copyright 2013

Original file name:
autolrcs.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\autolyrics\autolrcs.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/26/2013 1:00:00 AM

Valid to:
2/27/2014 12:59:59 AM

Subject:
CN=Castel Communication Ltd., O=Castel Communication Ltd., STREET=5 Oded st., L=Ramat Gan, S=Israel, PostalCode=52223, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4B95965A86A77BF4007748964F3622CC

Registration
CLSID:
{DAEB9E85-4694-4F9B-85CB-2F28987872D7}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
4/24/2013 12:54:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:HIcnPp4qO2gAmmn63a2kICOYu3nY0OBk:os46Tmmnia2kITro

Entry address:
0x9CB7

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, AC, 56, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 60, C7, 01, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, F5, DC, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, E5, DC, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B...
 
[+]

Code size:
84 KB (86,016 bytes)

Internet Explorer BHO
Display name:
Auto Lyrics

CLSID:
{DAEB9E85-4694-4F9B-85CB-2F28987872D7}


The file autolrcs.dll has been discovered within the following program.

Auto Lyrics  by Mansoft Union
Auto Lyrics is a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search.
66% remove it
 
Powered by Should I Remove It?

Remove autolrcs.dll - Powered by Reason Core Security