Forecaster.exe

Forecaster Weather Prediction Tool

Core Systems

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application Forecaster.exe, “Forecaster Weather Prediction Tool” by Core Systems has been detected as adware by 4 anti-malware scanners.
Publisher:
Local Temperature  (signed by Core Systems)

Product:
Forecaster (R) Weather Prediction Tool

Description:
Forecaster Weather Prediction Tool

Version:
1.1.0.11

MD5:
1c4f19335879da2c7898fd95a0b4e967

SHA-1:
91d5acef7183d28abf9fa077a757264150384c71

SHA-256:
6c1909bba7a815be6978d10357ada2676b0a6786b0559f626fb3b0b9256a762f

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
1/24/2025 7:37:15 AM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.LocalTemperature.C
v2015.07.20.08

Reason Heuristics
PUP.Weather.CoreSystems (M)
15.7.20.8

Trend Micro House Call
Suspicious_GEN.F47V0329
7.2.201

VIPRE Antivirus
Bonzuna
39964

File size:
159.9 KB (163,752 bytes)

Product version:
1.1.0.11

Copyright:
© Local Temperature. All rights reserved.

Original file name:
Forecaster.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\localtemperature\forecaster.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/17/2014 3:26:02 PM

Valid to:
6/17/2015 3:26:02 PM

Subject:
CN=Core Systems, O=Core Systems, L=Austin, S=Texas, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B1F1B2C0AF57F

File PE Metadata
Compilation timestamp:
6/18/2010 5:47:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
3072:JT96QCrt0BHn9NbopVSmKxiZHF8s7MtlVTnS:J8TGHn3UpVSmrNcl5S

Entry address:
0xD4E9

Entry point:
E8, 97, 6A, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 56, E8, CF, 14, 00, 00, 50, E8, 18, 6B, 00, 00, 59, 59, 85, C0, 74, 7C, E8, EB, C3, FF, FF, 83, C0, 20, 3B, F0, 75, 04, 33, C0, EB, 0F, E8, DB, C3, FF, FF, 83, C0, 40, 3B, F0, 75, 60, 33, C0, 40, FF, 05, 20, 6F, 42, 00, F7, 46, 0C, 0C, 01, 00, 00, 75, 4E, 53, 57, 8D, 3C, 85, 30, 6F, 42, 00, 83, 3F, 00, BB, 00, 10, 00, 00, 75, 20, 53, E8, A5, 16, 00, 00, 59, 89, 07, 85, C0, 75, 13, 8D, 46, 14, 6A, 02, 89, 46, 08, 89, 06, 58, 89, 46...
 
[+]

Entropy:
6.5507

Code size:
118 KB (120,832 bytes)

Remove Forecaster.exe - Powered by Reason Core Security