84,488,480 programs installed

Should I remove Auto Cinema?

What percent of users and experts removed it?
81% remove it19% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Reach 0.0001%

Versions

VersionDistribution
1.35.9.29 100.00%

Auto Cinema

What is Auto Cinema?

This is a WinCheck adware/browser hijacker variant that injects code into the user's web browser (IE, Chrome and Firefox). It is known as an ad-injector, a malicious process that once inside the web browser will hijack existing advertisements of underlying web sites (not associated with the website itself). It will also inject new ads in white space on the site or images that have standard banner sizes. These ads are typically for promoting shopping discount coupons, ads for PC optimizers or bundled PUP offers, or malvertising since it runs on sketchy ad networks.This runs as a startup process called WinCheck in the user's startup registry (Run key) and will execute each time the computer is restarted and the user logs in.

How do you know if you are infected? First, if you have this program installed then this adware is most likely still running. Next, you see ads in the browser that say something like "Ads by WinCheck".

Overview

During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a Browser Helper Object (BHO) to Internet Explorer. The main program executable is utils.exe. Typically most users end up uninstalling this just after a few days. The software installer includes 21 files and is usually about 11.13 MB (11,672,889 bytes).
  • Possible malware installed by this program
  • Automatically starts with Windows
  • Loads into the web browser
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Auto Cinema.
9ffab01e-ff33-4444-858f-62b1528c0f20-4.exe (2a277b2f4ef6a0d855252a4ae24a44c5) has been flagged by the following 29 scanners:
Anti-Virus softwareVersionDetection
Lavasoft Ad-Aware 663 Gen:Application.Heur.Cv1@keTsmZhO
AhnLab-V3 2014.11.27 PUP/Win32.CrossRider
Antiy-AVL 1.0.0.1 GrayWare[WebToolbar:not-a-virus]/NSIS.Adwapper.df
avast! 2014.9-150413 Win32:Crossrider-AP [PUP]
AVG 2016.0.3141 Generic
Avira 7.11.189.28 Adware/CrossRider.KB
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 4.0.3.15413 PUA.Win32.CrossRider.BAX
Bitdefender 1.0.20.515 Gen:Application.Heur.Cv1@keTsmZhO
Clam AntiVirus 0.98/21511 Win.Adware.Crossrider-140
Dr.Web 9.0.0.0103 Trojan.Crossrider.43222
ESET-NOD32 9.10788 a variant of Win32/Toolbar.CrossRider.AX
Fortinet FortiGate 4/13/2015 Adware/Adwapper
F-Prot v6.4.7.1.166 W32/A-73a7935c
F-Secure 11.2015-13-04_2 Gen:Application.Heur.Cv1@keTsmZhO
G Data 15.4.24 Gen:Application.Heur.Cv1@keTsmZhO
IKARUS anti.virus t3scan.1.8.3.0 Trojan.GoogUpdate
K7GW 13.186.14148 Unwanted-Program ( 004afadd1 )
Kaspersky 14.0.0.2199 not-a-virus:AdWare.NSIS.Adwapper
Malwarebytes v2015.04.13.05 PUP.Optional.AutoCinema.A
McAfee 5600.6797 Artemis!2A277B2F4EF6
McAfee-GW-Edition 7.6797 BehavesLike.Win32.BadFile.th
MicroWorld-eScan 16.0.0.309 Gen:Application.Heur.Cv1@keTsmZhO
NANO AntiVirus 0.28.6.63726 Riskware.Win32.Crossrider.djfjew
Panda Antivirus 15.04.13.05 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 HEUR/QVM10.1.Malware.Gen
Sophos 4.98 Generic PUA EH
Symantec 4/13/2015 rev. 2 PUA.Gen
VIPRE Antivirus 35166 Crossrider (fs)
9ffab01e-ff33-4444-858f-62b1528c0f20-11.exe (6e7b928630bb96e298533c8750b870dd) has been flagged by the following 28 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.5v1@kuEThypO
AhnLab-V3 2014.11.27.00 PUP/Win32.CrossRider
Antiy-AVL 1.0.0.1 GrayWare[WebToolbar:not-a-virus]/NSIS.Adwapper.df
avast! 8.0.1489.320 Win32:Crossrider-AP [PUP]
AVG 15.0.0.4189 Generic.A9C
Avira 7.11.189.36 Adware/CrossRider.KB
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 3.5.1.41473 PUA.Win32.CrossRider.BAX
Bitdefender 7.2 Gen:Application.Heur.5v1@kuEThypO
Comodo Security 20205 Application.Win32.Plush.GRI
Dr.Web 7.0.10.8210 Trojan.Crossrider.43230
ESET-NOD32 10789 a variant of Win32/Toolbar.CrossRider.AX
Fortinet FortiGate 5.0.999.0 Adware/Adwapper
F-Secure 11.0.19100.45 Gen:Application.Heur.5v1@kuEThypO
G Data 24 Gen:Application.Heur.5v1@kuEThypO
IKARUS anti.virus T3.1.8.3.0 Trojan.GoogUpdate
K7GW 9.186.14148 Unwanted-Program ( 004afadd1 )
Kaspersky 15.0.1.10 not-a-virus:AdWare.NSIS.Adwapper.df
Malwarebytes 1.75.0.1 PUP.Optional.AutoCinema.A
McAfee 6.0.5.614 Artemis!6E7B928630BB
McAfee-GW-Edition v2014.2 BehavesLike.Win32.BadFile.th
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.5v1@kuEThypO
NANO AntiVirus 0.28.6.63726 Riskware.Win32.Crossrider.djgnhe
Panda Antivirus 4.6.4.2 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 Win32/Application.0aa
Sophos 4.98.0 Generic PUA DP
Symantec 20141.1.0.330 PUA.Gen.2
VIPRE Antivirus 35170 Crossrider (fs)
9ffab01e-ff33-4444-858f-62b1528c0f20-2.exe (b06d3682f94af4049c6b462a0470c8e3) has been flagged by the following 25 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.4u1@kO5UtagO
Antiy-AVL 1.0.0.1 GrayWare[WebToolbar:not-a-virus]/NSIS.Adwapper.df
AVG 15.0.0.4189 Generic.A9C
Avira 7.11.189.28 Adware/CrossRider.KB
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 3.5.1.41473 PUA.Win32.CrossRider.BAY
Bitdefender 7.2 Gen:Application.Heur.4u1@kO5UtagO
Dr.Web 7.0.10.8210 Trojan.Crossrider.43225
ESET-NOD32 10787 a variant of Win32/Toolbar.CrossRider.AY
Fortinet FortiGate 5.0.999.0 Adware/Adwapper
F-Secure 11.0.19100.45 Gen:Application.Heur.4u1@kO5UtagO
G Data 24 Gen:Application.Heur.4u1@kO5UtagO
IKARUS anti.virus T3.1.8.3.0 Trojan.GoogUpdate
Kaspersky 15.0.1.10 not-a-virus:AdWare.NSIS.Adwapper.df
Malwarebytes 1.75.0.1 PUP.Optional.AutoCinema.A
McAfee 6.0.5.614 Artemis!B06D3682F94A
McAfee-GW-Edition v2014.2 Artemis
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.4u1@kO5UtagO
NANO AntiVirus 0.28.6.63726 Riskware.Win32.Crossrider.djfpkk
Panda Antivirus 4.6.4.2 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 Win32/Virus.Adware.7a9
Rising Antivirus 25.0.0.11 PE:Malware.Obscure!1.9C59
Sophos 4.98.0 Generic PUA KL
Symantec 20141.1.0.330 PUA.Gen.2
VIPRE Antivirus 35160 Crossrider (fs)
Auto Cinema-codedownloader.exe (deba23cf801b0ad58209b91e2c2e2851) has been flagged by the following 24 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.9u1@kW6hXNiO
Antiy-AVL 1.0.0.1 GrayWare[WebToolbar:not-a-virus]/NSIS.Adwapper.df
avast! 8.0.1489.320 Win32:Crossrider-AH [PUP]
AVG 15.0.0.4189 Generic.A9C
Avira 7.11.189.28 Adware/CrossRider.KB
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 3.5.1.41473 PUA.Win32.CrossRider.bAY
Bitdefender 7.2 Gen:Application.Heur.9u1@kW6hXNiO
Clam AntiVirus 0.98.5.0 Win.Adware.Crossrider-141
ESET-NOD32 10788 a variant of Win32/Toolbar.CrossRider.AY
Fortinet FortiGate 5.0.999.0 Adware/Adwapper
F-Secure 11.0.19100.45 Gen:Application.Heur.9u1@kW6hXNiO
G Data 24 Gen:Application.Heur.9u1@kW6hXNiO
IKARUS anti.virus T3.1.8.3.0 Trojan.GoogUpdate
Kaspersky 15.0.1.10 not-a-virus:AdWare.NSIS.Adwapper.df
Malwarebytes 1.75.0.1 PUP.Optional.AutoCinema.A
McAfee 6.0.5.614 Artemis!DEBA23CF801B
McAfee-GW-Edition v2014.2 Artemis
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.9u1@kW6hXNiO
Panda Antivirus 4.6.4.2 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 HEUR/QVM10.1.Malware.Gen
Sophos 4.98.0 Generic PUA HA
Symantec 20141.1.0.330 Trojan.Gen.2
VIPRE Antivirus 35166 Crossrider (fs)
9ffab01e-ff33-4444-858f-62b1528c0f20-5.exe (91ec1e202b2c47dfb47ba0880acd641d) has been flagged by the following 20 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.@u1@kiR2MrkO
Antiy-AVL 1.0.0.1 GrayWare[WebToolbar:not-a-virus]/NSIS.Adwapper.df
avast! 8.0.1489.320 Win32:Crossrider-AO [PUP]
AVG 15.0.0.4189 Generic.A9C
Avira 7.11.189.28 Adware/CrossRider.KB
Baidu-International 3.5.1.41473 PUA.Win32.CrossRider.bAY
Bitdefender 7.2 Gen:Application.Heur.@u1@kiR2MrkO
ESET-NOD32 10787 a variant of Win32/Toolbar.CrossRider.AY
Fortinet FortiGate 5.0.999.0 Adware/Adwapper
F-Secure 11.0.19100.45 Gen:Application.Heur.@u1@kiR2MrkO
G Data 24 Gen:Application.Heur.@u1@kiR2MrkO
IKARUS anti.virus T3.1.8.3.0 Trojan.GoogUpdate
Kaspersky 15.0.1.10 not-a-virus:AdWare.NSIS.Adwapper.df
Malwarebytes 1.75.0.1 PUP.Optional.AutoCinema.A
McAfee 6.0.5.614 Artemis!91EC1E202B2C
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.@u1@kiR2MrkO
Panda Antivirus 4.6.4.2 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 Win32/Application.e3d
Sophos 4.98.0 Generic PUA LG
Symantec 20141.1.0.330 Trojan.Gen.2
545e6e24-f236-4f95-b8cf-640801f94839-11.exe (8fb9e8bddbc757f5379bbc1d42250497) has been flagged by the following 16 scanners:
Anti-Virus softwareSoftware versionDetection
AegisLab 1.5 Troj.W32.Gen
Avira 7.11.181.132 ADWARE/CrossRider.Gen7
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 3.5.1.41473 PUA.Win32.CrossRider.BAX
Clam AntiVirus 0.98.4.0 Win.Adware.Agent-26461
Comodo Security 19910 Application.Win32.Plush.GRI
Dr.Web 7.0.10.8210 Trojan.Crossrider.36626
ESET-NOD32 10622 a variant of Win32/Toolbar.CrossRider.AX
G Data 24 Win32.Adware.Crossrider.R
Malwarebytes 1.75.0.1 PUP.Optional.AutoCinema.A
McAfee-GW-Edition v2014.2 BehavesLike.Win32.AdwareCross.th
NANO AntiVirus 0.28.2.62841 Trojan.Win32.Crossrider.dgzjsr
Qihoo-360 1.0.0.1015 Win32/Virus.Adware.a87
Symantec 20141.1.0.330 Adware.Crossid
VIPRE Antivirus 34258 Crossrider (fs)
Zillya 2.0.0.1967 Adware.Adwapper.Win32.791
545e6e24-f236-4f95-b8cf-640801f94839-4.exe (0d5208d8481540b37d06260bcfdcd3fd) has been flagged by the following 14 scanners:
Anti-Virus softwareSoftware versionDetection
AegisLab 1.5 Troj.W32.Gen
Avira 7.11.181.132 ADWARE/CrossRider.Gen4
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 3.5.1.41473 PUA.Win32.CrossRider.BAX
Dr.Web 7.0.10.8210 Trojan.Crossrider.36627
ESET-NOD32 10622 a variant of Win32/Toolbar.CrossRider.AX
G Data 24 Win32.Adware.Crossrider.R
IKARUS anti.virus T3.1.7.8.0 PUA.Toolbar.CrossRider
Malwarebytes 1.75.0.1 PUP.Optional.AutoCinema.A
McAfee-GW-Edition v2014.2 BehavesLike.Win32.AdwareCross.th
NANO AntiVirus 0.28.2.62841 Trojan.Win32.Crossrider.dgzpak
Symantec 20141.1.0.330 Adware.Crossid
VIPRE Antivirus 34258 Crossrider (fs)
Zillya 2.0.0.1967 Adware.Adwapper.Win32.770
       View all 156 all detections
Auto Cinema has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Installation folder: C:\Program Files\auto cinema
Uninstaller: C:\Program Files\Auto Cinema\Uninstall.exe /fcp=1
Estimated size: 11.13 MB

Program filesFiles installed by Auto Cinema

Program executable:utils.exe
${randomstring4}
Path:C:\Program Files\auto cinema\utils.exe
MD5:f82359ed55bd91df033cc25e001cebb1
Additional files:
  • (Malware detected) 545e6e24-f236-4f95-b8cf-640801f94839-11.exe - Auto Cinema (Auto Cinema exe)
  • 545e6e24-f236-4f95-b8cf-640801f94839-2.exe
  • (Malware detected) 545e6e24-f236-4f95-b8cf-640801f94839-4.exe
  • 545e6e24-f236-4f95-b8cf-640801f94839-5.exe
  • (Malware detected) 9ffab01e-ff33-4444-858f-62b1528c0f20-11.exe
  • (Malware detected) 9ffab01e-ff33-4444-858f-62b1528c0f20-2.exe
  • (Malware detected) 9ffab01e-ff33-4444-858f-62b1528c0f20-4.exe
  • (Malware detected) 9ffab01e-ff33-4444-858f-62b1528c0f20-5.exe
  • Auto Cinema-bg.exe
  • Auto Cinema-bho.dll - Auto Cinema BHO
  • Auto Cinema-bho64.dll
  • Auto Cinema-buttonutil.exe
  • Auto Cinema-buttonutil64.exe
  • Auto Cinema-codedownloader.exe
  • Auto Cinema-buttonutil.dll
  • Uninstall.exe

Program behaviorsBehaviors exhibited

Internet Explorer BHO
  • Auto Cinema-bho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Auto Cinema' with the class of {11111111-1111-1111-1111-110611551111} (06745198e5254a388b0fe939902b12260065511).
9 Scheduled Tasks (Boot/Login)
  • Auto Cinema-codedownloader.exe is automatically launched at startup through a scheduled task named 9ffab01e-ff33-4444-858f-62b1528c0f20-1.
  • 9ffab01e-ff33-4444-858f-62b1528c0f20-5.exe is automatically launched at startup through a scheduled task named 9ffab01e-ff33-4444-858f-62b1528c0f20-5_user.
  • 9ffab01e-ff33-4444-858f-62b1528c0f20-4.exe is automatically launched at startup through a scheduled task named 9ffab01e-ff33-4444-858f-62b1528c0f20-4.
  • 9ffab01e-ff33-4444-858f-62b1528c0f20-2.exe is automatically launched at startup through a scheduled task named 9ffab01e-ff33-4444-858f-62b1528c0f20-2.
  • 9ffab01e-ff33-4444-858f-62b1528c0f20-11.exe is automatically launched at startup through a scheduled task named 9ffab01e-ff33-4444-858f-62b1528c0f20-11.
  • 545e6e24-f236-4f95-b8cf-640801f94839-5.exe is automatically launched at startup through a scheduled task named 545e6e24-f236-4f95-b8cf-640801f94839-5_user.
  • Plus 3 more

How do I remove Auto Cinema?

You can uninstall Auto Cinema from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Auto Cinema, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Auto Cinema.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Auto Cinema you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

PC BRAND OF CHOICE
100%
Acer
 
OS VERSIONS
Win Vista (SP2) 50%
Win 7 (SP1) 50%
 
HOW IT STARTS
Scheduled task? Yes
(Runs on Windows boot)

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows Vista 50.00%
Windows 7 50.00%
Which OS releases does it run on?
Windows Vista Home Premiu... 50.00%
Windows 7 Professional 50.00%

Distribution by countryGeography

71.43% of installs come from the United States
Which countries install it?
  United States 71.43%
  Canada 28.57%

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.