I - Cinema

I - Cinema

Known Adware

by Bright circle investments Ltd.

What is I - Cinema?

I - Cinema is software application developed by Bright circle investments Ltd.. It is most commonly found on computers running Windows 7 with nearly 74.11% of installations running this operating system. I - Cinema's installer is typically 15.00 MB in size and installs around 478 files. The most common release is 1.36.01.22 with 29.02% of all installations currently using this version.

I - Cinema is most popular in Brazil with 20.60% of installations residing in this country.

I - Cinema adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About I - Cinema?

i - cinema is a web browser extension designed to inject display advertising into the user's browser experience. Ads are presented as banners and contextual text-links, strategically placed in the white space areas of HTML pages or over existing ads within the underlying website. The advertisements primarily promote PC optimization utilities, bundled malware, and other types of potentially harmful content.

Multiple virus scanners have detected malware in I - Cinema.

utils.exe (MD5: e8faaa8fa19605bfcadf0f0df2826b28) has been flagged by 50 scanners:
Scanner Software Result
AegisLab AdWare.NSIS.Indirect
avast! NSIS:InstMonetizer-BP [PUP]
Baidu-International PUA.Win32.VMDetector.BI
Bkav FE HW32.Packed
Dr.Web Trojan.Crossrider.33784
ESET-NOD32 Win32/Packed.VMDetector.I
G Data NSIS.Adware.Crossrider
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!E8FAAA8FA196
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider.dftchh
Qihoo-360 HEUR/Malware.QVM20.Gen
Symantec WS.Reputation
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Adware.AdWrapper.A
AhnLab-V3 PUP/Win32.CrossRider
ALYac Adware.AdWrapper.A
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper.do
AVG Generic.EC3
Avira ADWARE/CrossRider.Gen7
AVware Crossrider (fs)
Bitdefender Adware.AdWrapper.A
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/S-a64d6097!Eldorado
Emsisoft Anti-Malware Adware.AdWrapper.A (B)
Fortinet FortiGate Adware/Adwapper
F-Prot W32/S-a64d6097!Eldorado
F-Secure Adware.AdWrapper.A
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Jiangmin AdWare/NSIS.eaf
K7 AntiVirus Unwanted-Program ( 0040f9a31 )
K7GW Unwanted-Program ( 0040f9a31 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.do
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
MicroWorld-eScan Adware.AdWrapper.A
nProtect Trojan-Clicker/W32.Agent.929248
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.R0C1C0VAA15
TrendMicro-HouseCall TROJ_GEN.R0C1C0VAA15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.1543
Agnitum Outpost PUA.Toolbar.CrossRider!
Arcabit Trojan.Adware.Graftor.D29ED5
Clam AntiVirus Win.Adware.Graftor-752
SUPERAntiSpyware Adware.CrossRider/Variant
ViRobot Adware.CrossRider.2020328[h]
30e4fefd-94c4-42e7-891a-1095d00be41e-2.exe (MD5: ca55a8c8d5ad82e24ebeab413301cc60) has been flagged by 37 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG Generic.95F
Avira ADWARE/CrossRider.Gen4
Baidu-International PUA.Win32.CrossRider.bBM
Dr.Web Trojan.Crossrider.49260
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BM
Fortinet FortiGate Riskware/CrossRider
G Data Win32.Adware.Crossrider.L
IKARUS anti.virus PUA.Toolbar.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kee
Malwarebytes PUP.Optional.ICinema.A
McAfee Artemis!CA55A8C8D5AD
McAfee-GW-Edition Artemis
NANO AntiVirus Trojan.Win32.Crossrider.dlftec
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec Adware.Crossid
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall Suspicious_GEN.F47V1231
VIPRE Antivirus Adware.Crossid
Lavasoft Ad-Aware Gen:Application.Heur.nz1@kOy9ECai
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.nz1@kOy9ECai
F-Secure Gen:Application.Heur.nz1@kOy9ECai
MicroWorld-eScan Gen:Application.Heur.nz1@kOy9ECai
Sophos Generic PUA DE
avast! Win32:Crossrider-AH [PUP]
Comodo Security Application.Win32.Plush.GRI
K7 AntiVirus Unwanted-Program ( 004b1bb21 )
K7GW Unwanted-Program ( 004b1bb21 )
F-Prot W32/A-73a7935c!Eldorado
Clam AntiVirus Win.Adware.Agent-14079
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
Zillya Trojan.GoogUpdate.Win32.3288
Vba32 AntiVirus Trojan.GoogUpdate
30e4fefd-94c4-42e7-891a-1095d00be41e-11.exe (MD5: ea051c069a998f90cdf67e2276e81910) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Xv1@mG@JLpaO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kti
avast! Win32:Crossrider-BX [PUP]
AVG Generic.95F
Avira ADWARE/CrossRider.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International PUA.Win32.CrossRider.BBV
Bitdefender Gen:Application.Heur.Xv1@mG@JLpaO
Bkav FE W32.HfsAdware.CC58
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security Application.Win32.Plush.GRI
Cyren W32/Application.XVLB-0263
Dr.Web Trojan.Crossrider.49258
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CB potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.Xv1@mG@JLpaO
G Data Gen:Application.Heur.Xv1@mG@JLpaO
K7 AntiVirus Unwanted-Program ( 0040f9a31 )
K7GW Unwanted-Program ( 0040f9a31 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kti
Malwarebytes PUP.Optional.ICinema.A
McAfee Artemis!EA051C069A99
McAfee-GW-Edition BehavesLike.Win32.PUP.th
MicroWorld-eScan Gen:Application.Heur.Xv1@mG@JLpaO
NANO AntiVirus Trojan.Win32.Crossrider.dlgwuv
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos AppRider
Symantec Trojan.Gen
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00A515
TrendMicro-HouseCall TROJ_GEN.F0C2C00A515
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.CrossRider.Win32.859
Agnitum Outpost PUA.Toolbar.CrossRider!
Rising Antivirus PE:Malware.Adwapper!6.23ED
SUPERAntiSpyware Adware.CrossRider/Variant
Clam AntiVirus Win.Adware.Agent-39894
F-Prot W32/A-6583813c!Eldorado
Jiangmin AdWare/NSIS.dhh
Vba32 AntiVirus AdWare.Adwapper
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
nProtect Trojan-Clicker/W32.Agent.1987032
IKARUS anti.virus PUA.Toolbar.CrossRider
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
ALYac Gen:Variant.Adware.Graftor.171733
2170c3ed-5ded-4f8e-8b6b-5f470186e1b7-7.exe (MD5: b1de0ed79923f96d6836d75f69e46438) has been flagged by 39 scanners:
Scanner Software Result
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
avast! Win32:Crossrider-AI [PUP]
AVG Morgan.7D2
Avira ADWARE/CrossRider.Gen
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAY
CAT-QuickHeal AdWare.NSIS.g5 (Not a Virus)
Dr.Web Trojan.Crossrider.36570
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AY
Fortinet FortiGate Adware/Adwapper
F-Prot W32/A-1a27c920!Eldorado
G Data Win32.Adware.Crossrider.R
K7 AntiVirus Unwanted-Program ( 004afade1 )
K7GW Unwanted-Program ( 004afade1 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.cd
Malwarebytes PUP.Optional.ICinema.A
McAfee Artemis!B1DE0ED79923
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
NANO AntiVirus Trojan.Win32.Crossrider.dgzqor
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos Generic PUA AP
Symantec Trojan.Gen
Tencent Nsis.Adware.Adwapper.Pfte
TrendMicro-HouseCall Suspicious_GEN.F47V1106
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.688
Lavasoft Ad-Aware Gen:Application.Heur.hv1@mqxZ12kO
Bitdefender Gen:Application.Heur.hv1@mqxZ12kO
F-Secure Gen:Application.Heur.hv1@mqxZ12kO
IKARUS anti.virus PUA.Toolbar.CrossRider
MicroWorld-eScan Gen:Application.Heur.hv1@mqxZ12kO
Panda Antivirus Generic Suspicious
AhnLab-V3 PUP/Win32.CrossRider
ALYac Gen:Variant.Adware.Graftor.171733
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
Comodo Security Application.Win32.Plush.GRI
Rising Antivirus PE:Malware.Obscure!1.9C59
Clam AntiVirus Win.Adware.Agent-14079
2170c3ed-5ded-4f8e-8b6b-5f470186e1b7-6.exe (MD5: 1650aea6a4e8dc8f0f7517165453a501) has been flagged by 39 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
avast! Win32:Crossrider-AI [PUP]
AVG Morgan.7D2
Avira ADWARE/CrossRider.Gen4
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAY
Clam AntiVirus Win.Adware.Crossrider-65
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AY
Fortinet FortiGate Adware/Adwapper
F-Prot W32/A-865d81b8!Eldorado
G Data Win32.Adware.Crossrider.R
K7 AntiVirus Unwanted-Program ( 004afade1 )
K7GW Unwanted-Program ( 004afade1 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.cd
Malwarebytes PUP.Optional.ICinema.A
McAfee Artemis!1650AEA6A4E8
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Qihoo-360 Win32/Virus.Adware.de5
Sophos Generic PUA LN
Symantec Trojan.Gen.2
Tencent Nsis.Adware.Adwapper.Dxcy
TrendMicro-HouseCall Suspicious_GEN.F47V1106
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Adwapper.Win32.683
CAT-QuickHeal AdWare.NSIS.g5 (Not a Virus)
Dr.Web Trojan.Crossrider.36570
NANO AntiVirus Trojan.Win32.Crossrider.dgzqor
Lavasoft Ad-Aware Gen:Application.Heur.hv1@mqxZ12kO
Bitdefender Gen:Application.Heur.hv1@mqxZ12kO
F-Secure Gen:Application.Heur.hv1@mqxZ12kO
IKARUS anti.virus PUA.Toolbar.CrossRider
MicroWorld-eScan Gen:Application.Heur.hv1@mqxZ12kO
Panda Antivirus Generic Suspicious
ALYac Gen:Variant.Adware.Graftor.171733
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
Rising Antivirus PE:Malware.Obscure!1.9C59

Software Behaviors

Scheduled tasks:
  • 30e4fefd-94c4-42e7-891a-1095d00be41e-5.exe is scheduled as a task named '30e4fefd-94c4-42e7-891a-1095d00be41e-5_user'.

Startup Entries

Startup tasks:
  • 378cb8d1-c404-45a3-a934-6b2413fae652-7.exe is automatically launched at startup through a scheduled task named 0150c948-3971-4b08-bbe1-3a800301f282-1.
  • 378cb8d1-c404-45a3-a934-6b2413fae652-2.exe is automatically launched at startup through a scheduled task named 378cb8d1-c404-45a3-a934-6b2413fae652-2.
  • 0150c948-3971-4b08-bbe1-3a800301f282-2.exe is automatically launched at startup through a scheduled task named 0150c948-3971-4b08-bbe1-3a800301f282-2.
  • I - Cinema-codedownloader.exe is automatically launched at startup through a scheduled task named a4992cdc-a0e9-4b1e-b435-5298c827136f-7.
  • a4992cdc-a0e9-4b1e-b435-5298c827136f-6.exe is automatically launched at startup through a scheduled task named a4992cdc-a0e9-4b1e-b435-5298c827136f-6.
  • a4992cdc-a0e9-4b1e-b435-5298c827136f-4.exe is automatically launched at startup through a scheduled task named a4992cdc-a0e9-4b1e-b435-5298c827136f-4.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\i - cinema
Uninstaller:
C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe /UNINSTALL=3c91fcc2-ce59-42b3-b901-f68079520898
Size:
15.00 MB
Language:
English

I - Cinema Executable Details

Primary executable:
utils.exe
Name:
I - Cinema
Path:
C:\Program Files\i - cinema\utils.exe
MD5:
e8faaa8fa19605bfcadf0f0df2826b28
SHA-1:
–
SHA-256:
–
Files installed by I - Cinema
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
e8faaa8fa19605bfcadf0f0df2826b28
EXE
ca55a8c8d5ad82e24ebeab413301cc60
EXE
ea051c069a998f90cdf67e2276e81910
EXE
811219bf6664c8fcbae054812e93dfe1
EXE
886378c43fbbcdacdef2a63eefe3752c
EXE
e633dfd558c1989a019bd86a6035452d
EXE
70a6026d0a82c3d608182ba54fa98536
EXE
a23dc295c8959ab6f4f0365924eaa25c
EXE
0efc9fdb207e5284917dd446224fea7b