11.exe

CinemaPlus-3.2cV03.04

Cinema PlusV03.04

The application 11.exe, “CinemaPlus-3.2cV03.04 Installer” has been detected as a potentially unwanted program by 23 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Cinema PlusV03.04

Product:
CinemaPlus-3.2cV03.04

Description:
CinemaPlus-3.2cV03.04 Installer

Version:
1.36.01.22

MD5:
4811f0229eeeb73e83c1c813fa7323e3

SHA-1:
9311613ca0da8c65e7adbcaa1d6f6c4ac40c3466

SHA-256:
c07110f2511f0812308a7d88e0c74d3cfcdc08760d1b11b45e46d59b59c81dc5

Scanner detections:
23 / 68

Status:
Potentially unwanted

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/25/2024 12:23:50 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.ScrambleWrapper
7.1.1

AhnLab V3 Security
PUP/Win32.CrossRider
2015.05.14

Avira AntiVirus
ADWARE/CrossRider.12661632
8.3.1.6

avast!
Win32:Adware-gen [Adw]
2014.9-150830

AVG
Toolbar.Crossrider
2016.0.3001

Clam AntiVirus
Win.Trojan.Crossrider-36
0.98/21511

Dr.Web
Trojan.Crossrider1.28205
9.0.1.0242

ESET NOD32
Win32/Packed.ScrambleWrapper.O potentially unwanted (variant)
9.11623

Fortinet FortiGate
PossibleThreat
8/30/2015

G Data
Win32.Application.Agent.T1DXW2
15.8.25

IKARUS anti.virus
PUA.ScrambleWrapper
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15903

Kaspersky
not-a-virus:HEUR:AdWare.NSIS.Adwapper
14.0.0.1501

Malwarebytes
PUP.Optional.CrossRider
v2015.08.30.08

McAfee
Artemis!4811F0229EEE
5600.6657

NANO AntiVirus
Trojan.Win32.MLW.dpnylv
0.30.24.1357

Panda Antivirus
Generic Suspicious
15.08.30.08

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Crossrider.CinemaPlusV0304.Installer.Meta (M)
15.8.30.20

Rising Antivirus
PE:Malware.Adload!6.1D9D
23.00.65.15828

Trend Micro House Call
TROJ_GEN.R03EC0OE715
7.2.242

Trend Micro
TROJ_GEN.R03EC0OE715
10.465.30

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

File size:
12.1 MB (12,661,632 bytes)

Copyright:
Copyright Cinema PlusV03.04

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

File PE Metadata
Compilation timestamp:
12/4/2012 3:55:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:VDc54bOEkMvH7eIpry63Xo26F/gZaf4ecnK3RaEUDGhTKHW5FLdCeg3WLWj:mQPRyaC/O+4ecnhE8+KHWLLdXyv

Entry address:
0x412D

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 73, 45, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 74, 45, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 74, 45, 00, 56, A3, F4, E7, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 50, E8, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 74, 45, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
33.5 KB (34,304 bytes)

Remove 11.exe - Powered by Reason Core Security