MovieModeService.exe

Movie Mode Service

GenTechnologies Apps, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application MovieModeService.exe by GenTechnologies Apps has been detected as adware by 25 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Movie Mode”. This file is typically installed with the program Movie Mode by GenTechnologies Apps, LLC which is a potentially unwanted software program.
Publisher:
GenTechnologies Apps, LLC  (signed and verified)

Product:
Movie Mode Service

Version:
1.0.0.0

MD5:
181ac56b762ef25690b9c90b233a8b4b

SHA-1:
5a55b570cd3f9f14903a070946263ee3e14a1e8f

SHA-256:
81194062fb0cba71f0a11be55fd4f32ba6563474936e1f40fc26e1b784add470

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 5:18:36 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.380518
623

Agnitum Outpost
PUA.PullUpdate
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
7.11.212.220

avast!
Win32:Adware-gen [Adw]
2014.9-150522

AVG
MalSign.GenTec
2016.0.3101

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.15522

Bitdefender
Gen:Variant.Kazy.380518
1.0.20.710

Comodo Security
ApplicUnwnt
18075

Dr.Web
Adware.Plugin.175
9.0.1.0142

Emsisoft Anti-Malware
Android.Trojan.Boqx
8.15.05.22.01

ESET NOD32
MSIL/Adware.PullUpdate (variant)
9.9656

Fortinet FortiGate
Adware/PullUpdate
5/22/2015

F-Secure
Gen:Variant.Kazy.380518
11.2015-22-05_6

G Data
Gen:Variant.Kazy.380518
15.5.24

IKARUS anti.virus
AdWare.Agent
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.178.12292

Malwarebytes
Adware.MovieMode
v2015.05.22.01

MicroWorld eScan
Gen:Variant.Kazy.380518
16.0.0.426

Qihoo 360 Security
Win32/Trojan.Adware.988
1.0.0.1015

Reason Heuristics
PUP.Injekt.GenTechnologiesApps
15.5.22.13

Sophos
Pull Update
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9860

Trend Micro House Call
TROJ_GEN.F47V0323
7.2.142

VIPRE Antivirus
Threat.4872425
29800

XVirus List
Win.Detected
2.3.31

File size:
51.6 KB (52,880 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © GenTechnologies Apps, LLC 2014

Original file name:
MovieModeService.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\moviemode\moviemodeservice.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/30/2013 1:00:00 AM

Valid to:
5/31/2014 12:59:59 AM

Subject:
CN="GenTechnologies Apps, LLC", O="GenTechnologies Apps, LLC", STREET=640 Grand Avenue, STREET=Suite E, L=Carlsbad, S=California, PostalCode=92008, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
06D4A5EDA561071FC293924D6DFC6300

File PE Metadata
Compilation timestamp:
2/6/2014 7:22:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:Tjf1CzQIMERaSlL4OynwdqhP+9tYD7vIB7+eZCACoGhZoW8YGobMEh:HYL86qP+vYYB7+eTCoGhZniQh

Entry address:
0xC52E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9603

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
41.5 KB (42,496 bytes)

Service
Display name:
Movie Mode

Service name:
MovieMode

Description:
Provides system level support for Movie Mode.

Type:
Win32OwnProcess


The file MovieModeService.exe has been discovered within the following program.

Movie Mode  by GenTechnologies Apps, LLC
Run by Creative Island Media, LLC, this is an adware (ad-supported) web browser extension that is difficult to remove and will hijack the user's web browser search page as well as inject advertisements.
www.moviemodeapp.com
88% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-52-32-118-15.us-west-2.compute.amazonaws.com  (52.32.118.15:80)

Remove MovieModeService.exe - Powered by Reason Core Security