CinemaDPV2

CinemaDPV2

Known Toolbar

by Robokid Technologies

What is CinemaDPV2?

CinemaDPV2 is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 42.86% of installations running this operating system. CinemaDPV2's installer is typically 15.00 MB in size and installs around 73 files.

CinemaDPV2 is most popular in United Kingdom with 41.67% of installations residing in this country.

About CinemaDPV2?

Cinema DPV / Plus HD is an adware Internet toolbar/extension designed to deliver ads to the browser on web pages that are not affiliated with the ads or the extension. The software injects ads as new pop-ups that are not typically present or on top of the existing ads on websites. Clicking on these offers can lead to redirects, potentially leading to unwanted software downloads or affiliate product purchases. Furthermore, the adware communicates with a remote server to track user habits, including visited domains, viewed pages, and interactions with advertisements. This information is then used for targeted ad delivery.

Multiple virus scanners have detected malware in CinemaDPV2.

CinemaDPV2-codedownloader.exe (MD5: e53c5680c16b154b5dac8903ca6e3521) has been flagged by 19 scanners:
Scanner Software Result
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28286
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Trojan.Win32.Crossrider.ddurda
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.329
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
McAfee Artemis!DEF7BDBB143E
Qihoo-360 HEUR/Malware.QVM10.Gen
Tencent Nsis.Trojan.Googupdate.Wxhv
Fortinet FortiGate W32/GoogUpdate.AG!tr
K7GW Adware ( 0049f20e1 )
Rising Antivirus PE:Malware.Obscure!1.9C59
CinemaDPV2-bho.dll (MD5: 063cade70fe68586a12a9485ad873cf7) has been flagged by 24 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.BHO
AVG Generic.332
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAF
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AF
IKARUS anti.virus not-a-virus:WebToolbar.CroRi
K7 AntiVirus Trojan ( 0049b8981 )
K7GW Trojan ( 0049b8981 )
McAfee Artemis!063CADE70FE6
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0814
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/Kazy.374109.595
Dr.Web Trojan.Crossrider.29496
NANO AntiVirus Trojan.Win32.GoogUpdate.debbyh
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM10.Gen
Zillya Trojan.GoogUpdate.Win32.572
Fortinet FortiGate W32/GoogUpdate.AK!tr
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Tencent Nsis.Trojan.Googupdate.Lndw
ccc83f51-22ea-40af-bc9c-59dd095b74fb-5.exe (MD5: ede80095651d587982d5bbc84cc87900) has been flagged by 24 scanners:
Scanner Software Result
Avira AntiVir Adware/Kazy.374109.487
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28289
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
K7GW Adware ( 0049f20e1 )
NANO AntiVirus Trojan.Win32.Crossrider.dduofb
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.303
Baidu-International PUA.Win32.CrossRider.BAK
Fortinet FortiGate Riskware/CrossRider
K7 AntiVirus Trojan ( 0049c2a41 )
McAfee Artemis!B1EF5BB9ED07
TrendMicro-HouseCall Suspicious_GEN.F47V0814
AhnLab-V3 PUP/Win32.BHO
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Tencent Nsis.Trojan.Googupdate.Lndw
ccc83f51-22ea-40af-bc9c-59dd095b74fb-4.exe (MD5: a14e19987a842cc0fb05101fd7ca8b6d) has been flagged by 20 scanners:
Scanner Software Result
Avira AntiVir Adware/Kazy.433849
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28282
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Trojan.Win32.GoogUpdate.ddyjss
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.282
Fortinet FortiGate W32/GoogUpdate.AK!tr
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Qihoo-360 Win32/Trojan.a2d
Tencent Nsis.Trojan.Googupdate.Lndw
McAfee Artemis!DEF7BDBB143E
K7GW Adware ( 0049f20e1 )
Rising Antivirus PE:Malware.Obscure!1.9C59
ccc83f51-22ea-40af-bc9c-59dd095b74fb-11.exe (MD5: 87cccebfbfa4ca2b21ce23d8b0a34808) has been flagged by 21 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28285
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Trojan.Win32.Crossrider.dduony
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.342
Avira AntiVir Adware/Kazy.433849
Fortinet FortiGate W32/GoogUpdate.AK!tr
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Qihoo-360 Win32/Trojan.a2d
Tencent Nsis.Trojan.Googupdate.Lndw
McAfee Artemis!DEF7BDBB143E
K7GW Adware ( 0049f20e1 )
Rising Antivirus PE:Malware.Obscure!1.9C59

Startup Entries

Startup tasks:
  • ec4c6412-f445-4bcc-88e1-71a9a5d0d06f.exe is automatically launched at startup through a scheduled task named ec4c6412-f445-4bcc-88e1-71a9a5d0d06f.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-7.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-1.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-5.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-5_user.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-4.exe is automatically launched at startup through a scheduled task named e724675a-8fea-435b-be57-ef8d4e2b6d55.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-11.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-3.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-2.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-2.

Software Details

URL:
https://crossrider.com/install/58356-plus-hd-v1-1
Support:
–
Installation path:
C:\Program Files\cinemadpv2
Uninstaller:
C:\Program Files\CinemaDPV2\Uninstall.exe /fcp=1
Size:
15.00 MB
Language:
English

CinemaDPV2 Executable Details

Primary executable:
utils.exe
Name:
CinemaDPV2
Path:
C:\Program Files\cinemadpv2\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by CinemaDPV2
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
723297dbe65ef5428ad8097fd22e8e06
DLL
1c1098a6af2f0a3310c9376325ffa5ad
DLL
47dfb9bcc2466a64b378d39a7f89279b
EXE
a0bdc8051a740904d9e5f24d697f6875
DLL
20dc099efcc421d72bb4bc7c10c1c3a9
DLL
3950fefa3a4d6a7327112eac4f169fcb
DLL
fcdd56877d13caf9933c3f2ce85c1b6f
EXE
db05652b9ea0c411b70bd4b20286dabf
EXE
e53c5680c16b154b5dac8903ca6e3521