cinema-plus-1.2-bho.dll

Cinema-Plus-1.2

Bright circle investments Ltd.

This adware utilizes the Crossrider extension platform and will inject advertisiments in the Internet browser and may modify core browser settings. Ads will be delivered as banners and contextual text-links and may promote other potentially unwanted software. The module cinema-plus-1.2-bho.dll, “Cinema-Plus-1.2 BHO” by Bright circle investments has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the Browser Helper Object (BHO) for the Crossrider web browser platform for Internet Explorer. Instead of utilizing a traditional IE Toolbar, it installs a BHO in the browser in order to manage the functionality of the addon. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Cinema Plus  (signed by Bright circle investments Ltd.)

Product:
Cinema-Plus-1.2

Description:
Cinema-Plus-1.2 BHO

Version:
1.1.153.49

MD5:
b813569d849979a88d8ec40d067349b4

SHA-1:
672ceb66e228365cb5299cda099eeb9c5ea8c4d1

SHA-256:
b1f3d3192de14b22c381e99cec584e41c2d382e42dcbdf0ec38a2c6a255ae3e6

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Bright circle investments Ltd..

Analysis date:
11/23/2024 7:46:46 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider (M)
17.2.26.10

File size:
508.6 KB (520,760 bytes)

Product version:
1.1.153.49

Copyright:
Copyright 2011

Original file name:
Cinema-Plus-1.2.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\cinema-plus-1.2\cinema-plus-1.2-bho.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/20/2014 2:00:00 AM

Valid to:
6/21/2015 1:59:59 AM

Subject:
CN=Bright circle investments Ltd., O=Bright circle investments Ltd., STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4347D0F2AD67F1767C932B3BFBEA7713

File PE Metadata
Compilation timestamp:
7/16/2014 12:07:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x39D17

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 4A, B3, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 60, E5, 06, 10, E8, BA, 30, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 08, 3F, 07, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 00, F7, 05, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
341.5 KB (349,696 bytes)

Remove cinema-plus-1.2-bho.dll - Powered by Reason Core Security