77,019,263 programs installed

Should I remove Cinema-DPlus3?

What percent of users and experts removed it?
80% remove it20% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Reach 0.0002%

Versions

VersionDistribution
1.34.7.1 100.00%

Other programs by Motoko Group

Cinema-DPlus3

What is Cinema-DPlus3?

Cinema-DPlus is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page. The ads are injected by the web browser plugin (IE, FF and Chrome) and will display on any web site, even those not associated or affiliated with the publisher. On web pages there may be up to 10 intext ads and/or 4 banner ad and/or a transitional ad. The application is usually bundled by 3rd-party download managers that utilize deceptive advertising techniques in order to install the software. In addition to ads, the program will also modify the browser settings which could include lowering the normal security settings of the browser as well as changing the home page and search provider (known as web browser hijacking). The extension will also report back to the controlling server analytics which may include the behavior of the user on the Internet and reports back URLs and domains visited as well as what advertisements are displayed and clicked on. This adware is mostly bundled with 3rd party download managers that include a number of additional offers, all potentially unwanted programs.

Overview

During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a Browser Helper Object (BHO) to Internet Explorer. The primary executable is named utils.exe. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 15 files and is usually about 13.3 MB (13,951,178 bytes).

This browser extension utilizes Crossrider framework, a cross-browser toolbar/plugin platform used to develop, deploy and monetize web browser toolbars for Internet Explorer, Chrome and Firefox. Crossrider extension provide monetization options, mostly potentially unwanted apps, for toolbars including coupons, search assistant (home page and search hijacking) and in-text contextual advertising. Many adware programs (defined by a number of anti-virus vendors) are built using Crossrider as it provides a quick an easy way to deploy ad-supported features that will assist in browser search hijacking.
  • Malware detected in the program
  • Automatically starts with Windows
  • Integrates into the web browser
  • Uses the Crossrider toolbar framework
  • During install it may hijack/modify the browser's homepage and search provider
  • Runs disconnected from the browser as a background process
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • Hijacks the web browser's home page
  • Hijacks the browser's default search provider
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Cinema-DPlus3.
Cinema-DPlus3-bho.dll (ecdce2963828c5872235ebd80a8740ea) has been flagged by the following 18 scanners:
Anti-Virus softwareVersionDetection
Avira AntiVir 7.11.164.150 ADWARE/CrossRider.Gen2
AVG 2015.0.3284 Generic5
AVware 1.5.0.16 Crossrider (fs)
Comodo Security 19033 ApplicUnwnt
ESET-NOD32 8.10180 a variant of Win32/Toolbar.CrossRider.AF
Fortinet FortiGate 11/21/2014 Riskware/Toolbar_CrossRider
F-Prot v6.4.7.1.166 W32/A-eb9ef301
K7 AntiVirus 13.181.12898 Trojan
K7GW 13.181.12898 Trojan ( 0049c7291 )
Kaspersky 14.0.0.2914 Trojan.NSIS.GoogUpdate
Malwarebytes v2014.11.21.04 PUP.Optional.CinemaHD.A
McAfee 5600.6940 Artemis!ECDCE2963828
McAfee-GW-Edition 7.6940 Artemis!ECDCE2963828
Panda Antivirus 14.11.21.04 Trj/Chgt.C
Sophos 4.98 AppRider
Symantec 11/21/2014 rev. 6 WS.Reputation
TrendMicro-HouseCall 7.2.325 Suspicious_GEN.F47V0724
VIPRE Antivirus 31770 Crossrider (fs)
0951cbef-abc4-4758-8fa6-0ef37977b8fd-4.exe (594319ce9fcdf3cc4924928252a2df96) has been flagged by the following 17 scanners:
Anti-Virus softwareSoftware versionDetection
Avira AntiVir 7.11.164.150 ADWARE/CrossRider.Gen2
Antiy-AVL 1.0.0.1 RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG 14.0.0.3986 Generic.CA6
AVware 1.5.0.16 Crossrider (fs)
Comodo Security 19026 ApplicUnwnt
ESET-NOD32 10177 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate 5.1.152.0 Riskware/Toolbar_CrossRider
IKARUS anti.virus T3.1.6.1.0 AdWare.Adload
Kaspersky 12.0.0.1225 Trojan.NSIS.GoogUpdate.br
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
McAfee 6.0.4.564 Artemis!594319CE9FCD
McAfee-GW-Edition 2013 Artemis!594319CE9FCD
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Symantec 20131.1.5.61 Trojan.ADH.2
Tencent 1.0.0.1 Nsis.Trojan.Googupdate.Svrf
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0723
VIPRE Antivirus 31752 Crossrider (fs)
Cinema-DPlus3-codedownloader.exe (7d3d5bdfe7c4d89f5f7eb24094b3dcc7) has been flagged by the following 16 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Adware.Kazy.374109
Avira AntiVir 7.11.163.226 ADWARE/CrossRider.Gen2
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
Bitdefender 7.2 Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Adware.Kazy.374109 (B)
ESET-NOD32 10148 a variant of Win32/Toolbar.CrossRider.AK
F-Secure 11.0.19100.45 Gen:Variant.Adware.Kazy.374109
G Data 24 Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus T3.1.6.1.0 AdWare.Adload
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
MicroWorld-eScan 12.0.250.0 Gen:Variant.Adware.Kazy.374109
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 HEUR/Malware.QVM10.Gen
Sophos 4.98.0 Generic PUA AH
VIPRE Antivirus 31564 Crossrider (fs)
a79f2a3c-84a6-4602-9c35-7691b9097eff-5.exe (9d331f5050a0ee436503bdaa7a9696bf) has been flagged by the following 16 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Adware.Kazy.374109
AhnLab-V3 2014.07.25.00 PUP/Win32.CrossRider
Avira AntiVir 7.11.163.230 ADWARE/CrossRider.Gen2
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
Bitdefender 7.2 Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Adware.Kazy.374109 (B)
ESET-NOD32 10148 a variant of Win32/Toolbar.CrossRider.AH
F-Secure 11.0.19100.45 Gen:Variant.Adware.Kazy.374109
G Data 24 Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus T3.1.6.1.0 AdWare.Adload
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
MicroWorld-eScan 12.0.250.0 Gen:Variant.Adware.Kazy.374109
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Sophos 4.98.0 Generic PUA MB
VIPRE Antivirus 31568 Crossrider (fs)
a79f2a3c-84a6-4602-9c35-7691b9097eff-11.exe (d7d244ad0bc90ff874b2f07352688b41) has been flagged by the following 16 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Adware.Kazy.374062
Avira AntiVir 7.11.163.246 ADWARE/CrossRider.Gen2
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
Bitdefender 7.2 Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Adware.Kazy.374062 (B)
ESET-NOD32 10153 a variant of Win32/Toolbar.CrossRider.AK
F-Secure 11.0.19100.45 Gen:Variant.Adware.Kazy.374062
G Data 24 Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus T3.1.6.1.0 not-a-virus:WebToolbar.CrossRider
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
McAfee 6.0.4.564 Artemis!D7D244AD0BC9
McAfee-GW-Edition 2013 Artemis!D7D244AD0BC9
MicroWorld-eScan 12.0.250.0 Gen:Variant.Adware.Kazy.374062
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Sophos 4.98.0 Generic PUA KK
VIPRE Antivirus 31594 Crossrider (fs)
0951cbef-abc4-4758-8fa6-0ef37977b8fd-11.exe (c1fe300d1698d487bf80441a811e8e71) has been flagged by the following 12 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Adware.Kazy.374062
Avira AntiVir 7.11.163.164 ADWARE/CrossRider.Gen2
Bitdefender 7.2 Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Adware.Kazy.374062 (B)
ESET-NOD32 10142 a variant of Win32/Toolbar.CrossRider.AK
F-Secure 11.0.19100.45 Gen:Variant.Adware.Kazy.374062
G Data 24 Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus T3.1.6.1.0 AdWare.Adload
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
MicroWorld-eScan 12.0.250.0 Gen:Variant.Adware.Kazy.374062
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
VIPRE Antivirus 31530 Crossrider (fs)
0951cbef-abc4-4758-8fa6-0ef37977b8fd-2.exe (5c081d5ecd7fdf24af1d2b792d4b9099) has been flagged by the following 9 scanners:
Anti-Virus softwareSoftware versionDetection
Avira AntiVir 7.11.163.164 ADWARE/CrossRider.Gen2
ESET-NOD32 10142 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot 4.7.1.166 W32/A-eb9ef301!Eldorado
IKARUS anti.virus T3.1.6.1.0 AdWare.Adload
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Sophos 4.98.0 AppRider
VIPRE Antivirus 31530 Crossrider (fs)
Cinema-DPlus3-nova.exe (d72d3a671f8bb13cc63cb240f08f5c48) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.07.23.00 PUP/Win32.Toolbar
Avira AntiVir 7.11.163.92 ADWARE/CrossRider.Gen2
ESET-NOD32 10136 a variant of Win32/Toolbar.CrossRider.AE
F-Prot 4.7.1.166 W32/A-7d811582!Eldorado
Malwarebytes 1.75.0.1 PUP.Optional.CinemaHD.A
NANO AntiVirus 0.28.2.60990 Riskware.Win32.AdLoad.dcdvje
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
VIPRE Antivirus 31498 Crossrider (fs)
       View all 112 all detections
Cinema-DPlus3 has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.
Find out how to remove Cinema-DPlus3.

Program detailsProgram details

Displayed publisher: CinemaD3
Installation folder: C:\Program Files\cinema-dplus3
Uninstaller: C:\Program Files\Cinema-DPlus3\Uninstall.exe /fcp=1
Estimated size: 13.3 MB

Program filesFiles installed by Cinema-DPlus3

Program executable:utils.exe
Path:C:\Program Files\cinema-dplus3\utils.exe
MD5:51505df11b0c41302df2adbd089f256e
Additional files:
  • (Malware detected) 0951cbef-abc4-4758-8fa6-0ef37977b8fd-11.exe (by CinemaD3) - Cinema-DPlus3 (Cinema-DPlus3 exe)
  • (Malware detected) 0951cbef-abc4-4758-8fa6-0ef37977b8fd-2.exe (by CinemaD3)
  • (Malware detected) 0951cbef-abc4-4758-8fa6-0ef37977b8fd-4.exe
  • (Malware detected) a79f2a3c-84a6-4602-9c35-7691b9097eff-11.exe
  • a79f2a3c-84a6-4602-9c35-7691b9097eff-2.exe
  • a79f2a3c-84a6-4602-9c35-7691b9097eff-4.exe
  • (Malware detected) a79f2a3c-84a6-4602-9c35-7691b9097eff-5.exe
  • Cinema-DPlus3-bg.exe
  • (Malware detected) Cinema-DPlus3-bho.dll - Cinema-DPlus3 BHO
  • Cinema-DPlus3-bho64.dll
  • (Malware detected) Cinema-DPlus3-codedownloader.exe
  • (Malware detected) Cinema-DPlus3-nova.exe
  • Uninstall.exe

Program behaviorsBehaviors exhibited

Internet Explorer BHO
  • Cinema-DPlus3-bho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Cinema-DPlus3' with the class of {11111111-1111-1111-1111-110611051148} (CrossriderApp0060548).
9 Scheduled Tasks (Boot/Login)
  • Cinema-DPlus3-codedownloader.exe is automatically launched at startup through a scheduled task named 0951cbef-abc4-4758-8fa6-0ef37977b8fd-1.
  • 0951cbef-abc4-4758-8fa6-0ef37977b8fd-4.exe is automatically launched at startup through a scheduled task named 0951cbef-abc4-4758-8fa6-0ef37977b8fd-4.
  • 0951cbef-abc4-4758-8fa6-0ef37977b8fd-11.exe is automatically launched at startup through a scheduled task named 0951cbef-abc4-4758-8fa6-0ef37977b8fd-3.
  • 0951cbef-abc4-4758-8fa6-0ef37977b8fd-2.exe is automatically launched at startup through a scheduled task named 0951cbef-abc4-4758-8fa6-0ef37977b8fd-2.
  • Cinema-DPlus3-nova.exe is automatically launched at startup through a scheduled task named a79f2a3c-84a6-4602-9c35-7691b9097eff-7.
  • a79f2a3c-84a6-4602-9c35-7691b9097eff-5.exe is automatically launched at startup through a scheduled task named a79f2a3c-84a6-4602-9c35-7691b9097eff-5_user.
  • Plus 3 more

How do I remove Cinema-DPlus3?

Quickly and completely remove Cinema-DPlus3 from your computer by downloading "Should I Remove It?", its 100% FREE and installs in seconds (click the button below).
Download "Should I Remove It?", it's FREE!Remove Cinema-DPlus3 from your computer.
Or, you can uninstall Cinema-DPlus3 from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Cinema-DPlus3, click it, and then do one of the following:
    • Windows Vista/7/8: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Cinema-DPlus3.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Cinema-DPlus3 you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome
Scan your PC for malware
If you do not have a good anti-virus program, please consider installing one. Below are some we highly recommend.

HOW IT STARTS
Scheduled task? Yes
(Runs on Windows boot)
 
USER ACTIONS
Uninstall it 80%
Keep it 20%
 
MOST USED OS
~99%
Windows 8

Distribution by countryGeography

100.00% of installs come from the United States
Which countries install it?
  United States 100.00%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
ASUS 66.67%
Hewlett-Packard 33.33%

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.