Home Malware Programs Potentially Unwanted Programs (PUPs) Air Globe Ads

Air Globe Ads

Posted: March 16, 2015

Threat Metric

Ranking: 9,647
Threat Level: 2/10
Infected PCs: 4,797
First Seen: March 12, 2015
Last Seen: October 16, 2023
OS(es) Affected: Windows

Air Globe is a Potentially Unwanted Program (PUP) that is responsible for displaying a lot of advertisements. This application is primarily distributed as a bundle towards a legitimate freeware. In addition, the browser extension is hosted on its own domain - airglobeapp.com. Its creators describe it as a useful tool that enhances the browsing experience by showing the best deals and in turn saving money. In fact, the majority of people are not happy with Air Globe because its ads start appearing on almost every visited site and become annoying. Users start witnessing popping up messages, banners, coupons, inline text ads and transitional ads. Even if the offers seem good, they provided links should not be followed because they may lead to a potentially harmful page. People should be careful when installing cost-free programs and should carefully read all information in order to avoid installing undesired additions to the main application. If Air Globe is already present, experts encourage its removal in order to keep the system safe.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{231022F1-BDDF-4AA9-B01F-87A7D6FB6CAF}{29C6C884-0342-499A-803C-66DC6BB9D646}{4c54ce3d-6b7d-4f21-9e69-200632a98540}{692F6862-1B0C-4C25-85BB-ADADE34051F4}{FE4718C0-078E-409B-80AF-2CA69ACD8B7C}HKEY..\..\..\..{RegistryKeys}Software\Air GlobeSoftware\Microsoft\Internet Explorer\Approved Extensions\{4e8bf48a-e271-46a9-aed9-f6cce14e7d2e}Software\Microsoft\Internet Explorer\DOMStorage\airglobeapp.comSoftware\Microsoft\Internet Explorer\DOMStorage\api.airglobeapp.comSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{4e8bf48a-e271-46a9-aed9-f6cce14e7d2e}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e8bf48a-e271-46a9-aed9-f6cce14e7d2e}SOFTWARE\Wow6432Node\Air GlobeSOFTWARE\Wow6432Node\Microsoft\Tracing\updateAirGlobe_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateAirGlobe_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilAirGlobe_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilAirGlobe_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{4c54ce3d-6b7d-4f21-9e69-200632a98540}SYSTEM\ControlSet001\services\eventlog\Application\Update Air GlobeSYSTEM\ControlSet001\services\eventlog\Application\Util Air GlobeSYSTEM\ControlSet001\services\Update Air GlobeSYSTEM\ControlSet001\services\Util Air GlobeSYSTEM\ControlSet002\services\eventlog\Application\Update Air GlobeSYSTEM\ControlSet002\services\Update Air GlobeSYSTEM\CurrentControlSet\services\eventlog\Application\Update Air GlobeSYSTEM\CurrentControlSet\services\eventlog\Application\Util Air GlobeSYSTEM\CurrentControlSet\services\Update Air GlobeSYSTEM\CurrentControlSet\services\Util Air GlobeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Air Globe

Additional Information

The following directories were created:
%PROGRAMFILES%\Air Globe%PROGRAMFILES(x86)%\Air Globe%TEMP%\Air Globe
Loading...