CinemaDPV2

CinemaDPV2

Known Toolbar

by Robokid Technologies

What is CinemaDPV2?

CinemaDPV2 is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 42.86% of installations running this operating system. CinemaDPV2's installer is typically 15.00 MB in size and installs around 73 files.

CinemaDPV2 is most popular in United Kingdom with 41.67% of installations residing in this country.

About CinemaDPV2?

Cinema DPV / Plus HD is an adware Internet toolbar/extension designed to deliver ads to the browser on web pages that are not affiliated with the ads or the extension. The software injects ads as new pop-ups that are not typically present or on top of the existing ads on websites. Clicking on these offers can lead to redirects, potentially leading to unwanted software downloads or affiliate product purchases. Furthermore, the adware communicates with a remote server to track user habits, including visited domains, viewed pages, and interactions with advertisements. This information is then used for targeted ad delivery.

Multiple virus scanners have detected malware in CinemaDPV2.

CinemaDPV2-codedownloader.exe (MD5: e53c5680c16b154b5dac8903ca6e3521) has been flagged by 19 scanners:
Scanner Software Result
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28286
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Trojan.Win32.Crossrider.ddurda
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.329
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
McAfee Artemis!DEF7BDBB143E
Qihoo-360 HEUR/Malware.QVM10.Gen
Tencent Nsis.Trojan.Googupdate.Wxhv
Fortinet FortiGate W32/GoogUpdate.AG!tr
K7GW Adware ( 0049f20e1 )
Rising Antivirus PE:Malware.Obscure!1.9C59
CinemaDPV2-bho.dll (MD5: 063cade70fe68586a12a9485ad873cf7) has been flagged by 24 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.BHO
AVG Generic.332
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAF
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AF
IKARUS anti.virus not-a-virus:WebToolbar.CroRi
K7 AntiVirus Trojan ( 0049b8981 )
K7GW Trojan ( 0049b8981 )
McAfee Artemis!063CADE70FE6
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0814
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/Kazy.374109.595
Dr.Web Trojan.Crossrider.29496
NANO AntiVirus Trojan.Win32.GoogUpdate.debbyh
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM10.Gen
Zillya Trojan.GoogUpdate.Win32.572
Fortinet FortiGate W32/GoogUpdate.AK!tr
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Tencent Nsis.Trojan.Googupdate.Lndw
ccc83f51-22ea-40af-bc9c-59dd095b74fb-5.exe (MD5: ede80095651d587982d5bbc84cc87900) has been flagged by 24 scanners:
Scanner Software Result
Avira AntiVir Adware/Kazy.374109.487
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28289
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
K7GW Adware ( 0049f20e1 )
NANO AntiVirus Trojan.Win32.Crossrider.dduofb
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.303
Baidu-International PUA.Win32.CrossRider.BAK
Fortinet FortiGate Riskware/CrossRider
K7 AntiVirus Trojan ( 0049c2a41 )
McAfee Artemis!B1EF5BB9ED07
TrendMicro-HouseCall Suspicious_GEN.F47V0814
AhnLab-V3 PUP/Win32.BHO
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Tencent Nsis.Trojan.Googupdate.Lndw
ccc83f51-22ea-40af-bc9c-59dd095b74fb-4.exe (MD5: a14e19987a842cc0fb05101fd7ca8b6d) has been flagged by 20 scanners:
Scanner Software Result
Avira AntiVir Adware/Kazy.433849
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28282
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Trojan.Win32.GoogUpdate.ddyjss
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.282
Fortinet FortiGate W32/GoogUpdate.AK!tr
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Qihoo-360 Win32/Trojan.a2d
Tencent Nsis.Trojan.Googupdate.Lndw
McAfee Artemis!DEF7BDBB143E
K7GW Adware ( 0049f20e1 )
Rising Antivirus PE:Malware.Obscure!1.9C59
ccc83f51-22ea-40af-bc9c-59dd095b74fb-11.exe (MD5: 87cccebfbfa4ca2b21ce23d8b0a34808) has been flagged by 21 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.332
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.28285
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
IKARUS anti.virus AdWare.Adload
NANO AntiVirus Trojan.Win32.Crossrider.dduony
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec WS.Reputation.1
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.342
Avira AntiVir Adware/Kazy.433849
Fortinet FortiGate W32/GoogUpdate.AK!tr
Kaspersky Trojan.NSIS.GoogUpdate.ct
Kingsoft AntiVirus Win32.Troj.NSIS.ct.(kcloud)
Qihoo-360 Win32/Trojan.a2d
Tencent Nsis.Trojan.Googupdate.Lndw
McAfee Artemis!DEF7BDBB143E
K7GW Adware ( 0049f20e1 )
Rising Antivirus PE:Malware.Obscure!1.9C59

Startup Entries

Startup tasks:
  • ec4c6412-f445-4bcc-88e1-71a9a5d0d06f.exe is automatically launched at startup through a scheduled task named ec4c6412-f445-4bcc-88e1-71a9a5d0d06f.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-7.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-1.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-5.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-5_user.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-4.exe is automatically launched at startup through a scheduled task named e724675a-8fea-435b-be57-ef8d4e2b6d55.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-11.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-3.
  • 8e402feb-eb29-4627-8817-d0cb9c46dbd0-2.exe is automatically launched at startup through a scheduled task named 8e402feb-eb29-4627-8817-d0cb9c46dbd0-2.

Software Details

URL:
https://crossrider.com/install/58356-plus-hd-v1-1
Support:
–
Installation path:
C:\Program Files\cinemadpv2
Uninstaller:
C:\Program Files\CinemaDPV2\Uninstall.exe /fcp=1
Size:
15.00 MB
Language:
English

CinemaDPV2 Executable Details

Primary executable:
utils.exe
Name:
CinemaDPV2
Path:
C:\Program Files\cinemadpv2\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by CinemaDPV2
File Type Filename MD5
EXE
2a06a743671f8ebaf82c84cb39f6a9fd
EXE
ec997b5aa9873303fbf0475da287b3a2
EXE
e43f952264a1c0f59ea5dcdd3dfd5f31
EXE
2da824c6a855e1087de11e56f0078139
EXE
6020f5bba24a22637931537cb50ba1bb
EXE
588ff714e4c945ece6b2de581ab53765
EXE
7d97e727cc201336e731cc7d78521688
EXE
def7bdbb143e29adfad8a7407cadb7fc
EXE
8a9c76bc6e66a287ee207296815c5e57
EXE
c0bf4929561174c4851d3d64b344f4c6