autolrcstmp.exe

Castel Communication Ltd.

The application autolrcstmp.exe by Castel Communication has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to Microsoft Security Essentials, this AddLyrics variant installs itself as a Chrome extension, an Internet Explorer add-on, and a Firefox plug-in and displays advertisements in the browser, and also display the lyrics to songs viewed on YouTube. It is also typically executed from the user's temporary directory.
Publisher:
Castel Communication Ltd.  (signed and verified)

Description:
Auto Lyrics

Version:
111.0.0.0

MD5:
81e0897cc3b0d647071e76909bacbf00

SHA-1:
ab8ba81573d9ee23935dcfd7a64c20e523335c1b

SHA-256:
2f44ec66a3fab3192f7957adb6aff3eed8b25d3a2b5731a73e9e8c4f96455778

Scanner detections:
22 / 68

Status:
Adware

Analysis date:
4/25/2024 2:56:21 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-ATG [Adw]
2014.9-150722

AVG
Generic5
2016.0.3041

Bitdefender
Application.Generic.570382
1.0.20.1015

Comodo Security
Application.Win32.AddLyrics.B
17100

Dr.Web
Adware.Shopper.341
9.0.1.0203

ESET NOD32
Win32/Adware.AddLyrics (variant)
9.8912

Fortinet FortiGate
Adware/Lyckriks
7/22/2015

F-Secure
Application.Generic.570382
11.2015-22-07_4

G Data
Application.Generic.570382
15.7.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.0.127

K7 AntiVirus
Unwanted-Program
13.173.9850

Malwarebytes
PUP.LyricsAd
v2015.07.22.10

McAfee
Artemis!81E0897CC3B0
5600.6697

Microsoft Security Essentials
1.163.1557.0

MicroWorld eScan
Application.Generic.570382
16.0.0.609

NANO AntiVirus
Riskware.Script.Lyckriks.cdohoz
0.26.0.55366

Reason Heuristics
PUP.CastelCommunication.Installer (M)
15.7.22.10

Sophos
Generic PUA IJ
4.93

SUPERAntiSpyware
Adware.Shopper
9738

Trend Micro House Call
TROJ_GEN.F47V0922
7.2.203

Vba32 AntiVirus
AdWare.Lyckriks
3.12.24.3

VIPRE Antivirus
Adware.Singalng
22348

File size:
275.2 KB (281,768 bytes)

Copyright:
Auto Lyrics

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\autolrcstmp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/26/2013 1:00:00 AM

Valid to:
2/27/2014 12:59:59 AM

Subject:
CN=Castel Communication Ltd., O=Castel Communication Ltd., STREET=5 Oded st., L=Ramat Gan, S=Israel, PostalCode=52223, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4B95965A86A77BF4007748964F3622CC

File PE Metadata
Compilation timestamp:
6/6/2009 11:41:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:IsANk5RP/NBTIBMsY60Mh22WkEt9b5c+sAdx0i4:Ak5RdBlX60M42WkQds

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove autolrcstmp.exe - Powered by Reason Core Security