Home Malware Programs Adware GlobalWeather

GlobalWeather

Posted: April 27, 2017

Threat Metric

Ranking: 19,983
Threat Level: 1/10
Infected PCs: 7,272
First Seen: April 27, 2017
Last Seen: December 18, 2024
OS(es) Affected: Windows

GlobalWeather is an adware application which may be found in software bundles being promoted as a utility that can provide users with weather forecast information. However, the installation of GlobalWeather may not be recommended because the presence of this application on the computer may lead to the appearance of numerous Russian advertisements that may impair the user's ability to browse the Web completely. The Russian ads linked to GlobalWeather may appear on top of every website the user browses, and they may often end up covering entire sections of the page, therefore, making it impossible to access certain content, buttons and menus.

The quality and reliability of the ads that GlobalWeather may display may be very poor, considering that they are meant to be viewed by Russian-speaking users especially. However, it is very likely that the GlobalWeather adware may end up being installed on computers in other countries, and this may result in the ads being viewed by users who will not have a clue what the advertisements are meant to say.

Unlike many other adware pieces, GlobalWeather is not installed as a browser extension and, instead, it may create a Windows service titled 'Weather Service' whose purpose is to carry out the aggressive ad-promotion operation. This may allow GlobalWeather to display its ads in every active Web browser on the system simultaneously, regardless if it is Google Chrome, Mozilla Firefox, Opera or Microsoft Edge.

If your Web browsers are overrun by Russian ads, then you should know that GlobalWeather might be the reason for this. Unfortunately, the manual removal of this program can be rather tricky, so the recommended course of action is to use an automated malware removal tool.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\GlobalWeatherHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{F772C08D-9F61-45c6-0407-ADDEEE0D92C6}

Additional Information

The following directories were created:
%APPDATA%\GlobalWeather%PROGRAMFILES%\GlobalWeather%PROGRAMFILES(x86)%\GlobalWeather
Loading...