LocalTemperature.exe

Local Temperature

Core Systems

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application LocalTemperature.exe by Core Systems has been detected as adware by 11 anti-malware scanners.
Publisher:
Local Temperature, LLC  (signed by Core Systems)

Product:
Local Temperature

Version:
1.0.0.1

MD5:
b55894b58f0132ceb35d53e59e461425

SHA-1:
878f7878fec3290a04a477895d470345a42b8d43

SHA-256:
3cdc9097f287cad926b69c62c14c6d8566d33d5fd811de4caa6262531e759b9d

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
11/23/2024 8:19:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.PMA
567

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

Bitdefender
Adware.Agent.PMA
1.0.20.990

Emsisoft Anti-Malware
Adware.Agent.PMA
8.15.07.17.11

F-Secure
Adware.Agent.PMA
11.2015-17-07_6

G Data
Adware.Agent.PMA
15.7.25

Malwarebytes
PUP.Optional.LocalTemperature.C
v2015.07.17.11

MicroWorld eScan
Adware.Agent.PMA
16.0.0.594

Reason Heuristics
PUP.Weather.CoreSystems (M)
15.7.17.23

Trend Micro House Call
Suspicious_GEN.F47V0328
7.2.198

VIPRE Antivirus
Bonzuna
39598

File size:
118.9 KB (121,768 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2015

Trademarks:
Local Temperature, LLC

Original file name:
LocalTemperature.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\localtemperature\localtemperature.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/17/2014 3:26:02 PM

Valid to:
6/17/2015 3:26:02 PM

Subject:
CN=Core Systems, O=Core Systems, L=Austin, S=Texas, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B1F1B2C0AF57F

File PE Metadata
Compilation timestamp:
3/12/2015 5:38:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:TEp+L304LIF8COXwS3xIW4LIF8COXwS3xIMCg5hxb8/MDFIXgixcewBbZx4LIF83:T1b04LyymW4Lyymtk+Mbx4Lyym8CS

Entry address:
0x1646E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5990

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
81.5 KB (83,456 bytes)

Remove LocalTemperature.exe - Powered by Reason Core Security