Weather It Up

Weather It Up

Known Malware

by Phoenix Media

What is Weather It Up?

Weather It Up is software application developed by Phoenix Media. It is most commonly found on computers running Windows 7 with nearly 81.90% of installations running this operating system. Weather It Up's installer is typically 9.00 MB in size and installs around 36 files. The most common release is 1.34.3.6 with 54.29% of all installations currently using this version.

Weather It Up is most popular in the United States with 56.62% of installations residing in this country.

Weather It Up adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Weather It Up?

This software is designed to seamlessly integrate advertising into the user's web browsing experience by displaying ads on web pages where they would not typically appear. The software may be distributed through platforms such as OpenCandy.

Multiple virus scanners have detected malware in Weather It Up.

utils.exe (MD5: 7f44d95a3983d98f793820ebdf19c3f4) has been flagged by 37 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.Adware
Baidu-International Trojan.Win32.VMDetector.E
Bkav FE HW32.CDB
Dr.Web Trojan.Crossrider.4794
ESET-NOD32 Win32/Toolbar.CrossRider.AB
G Data Win32.Trojan.Agent.WUBV2L
Malwarebytes PUP.Optional.WeatherItUp.A
TrendMicro-HouseCall TROJ_GEN.F47V0316
Lavasoft Ad-Aware Trojan.Generic.11030524
Agnitum Outpost PUA.Toolbar.CrossRider!
AVG Generic5.APHA
Bitdefender Trojan.Generic.11030524
Emsisoft Anti-Malware Trojan.Generic.11030524 (B)
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11030524
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004965ab1 )
K7GW Trojan ( 004965ab1 )
MicroWorld-eScan Trojan.Generic.11030524
NANO AntiVirus Trojan.Win32.Crossrider.cwhmph
Norman Troj_Generic.TEZJT
nProtect Trojan.Generic.11030524
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.SGeneric
McAfee Artemis!979FD2706F4D
McAfee-GW-Edition Artemis!979FD2706F4D
Symantec Adware.Crossid
Avira AntiVir Adware/CrossRider.A.1708
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
AVware Trojan.Win32.Generic!BT
Clam AntiVirus Win.Trojan.Agent-839129
SUPERAntiSpyware Trojan.Agent/Gen-Downloader
Zillya Adware.CroRi.Win32.439
avast! Win32:Adware-gen [Adw]
Panda Antivirus Trj/Genetic.gen
Weather It Up-updater.exe (MD5: 403a07d6eb6e7120f07a765a0d7940f7) has been flagged by 14 scanners:
Scanner Software Result
AVG Generic5.ANJA
Baidu-International Adware.Win32.CrossRider.40
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
Malwarebytes PUP.Optional.WeatherItUp.A
McAfee Crossrider-FAJ!403A07D6EB6E
McAfee-GW-Edition Artemis!403A07D6EB6E
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R0C1H05BP14
VIPRE Antivirus Crossrider (fs)
Avira AntiVir ADWARE/CrossRider.Gen2
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Panda Antivirus Trj/Genetic.gen
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Bkav FE W32.CrossRider.Trojan
Weather It Up-firefoxinstaller.exe (MD5: daaa0c143b5074534f2d3c37311f1901) has been flagged by 30 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11165073
Agnitum Outpost Trojan.Crossrider!
AVG MultiBundle.V
Baidu-International Adware.Win32.Lyrics.71
Bitdefender Trojan.Generic.11165073
Dr.Web Trojan.Crossrider.8337
Emsisoft Anti-Malware Trojan.Generic.11165073 (B)
F-Secure Trojan.Generic.11165073
G Data Trojan.Generic.11165073
Malwarebytes PUP.Optional.WeatherItUp.A
MicroWorld-eScan Trojan.Generic.11165073
Norman Suspicious_Gen2.VVXJK
nProtect Trojan.Generic.11165073
TrendMicro-HouseCall TROJ_GEN.F47V0314
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.A.488
avast! Win32:Adware-gen [Adw]
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
Qihoo-360 Win32/Virus.Adware.ae5
Fortinet FortiGate Riskware/Toolbar_CrossRider
McAfee Artemis!64865CC00315
McAfee-GW-Edition Artemis!64865CC00315
Symantec WS.Reputation.1
K7 AntiVirus Trojan ( 004984e91 )
K7GW Trojan ( 004984e91 )
Sophos AppRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Panda Antivirus Trj/Genetic.gen
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Bkav FE W32.CrossRider.Trojan
Weather It Up-enabler.exe (MD5: 979fd2706f4d50c57fe1908872663863) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.910337
Antiy-AVL Trojan/Win32.SGeneric
AVG Generic5.ANCJ
Baidu-International Adware.Win32.CrossRider.40
Bitdefender Adware.Generic.910337
Dr.Web Trojan.Crossrider.7519
Emsisoft Anti-Malware Adware.Generic.910337 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.910337
G Data Adware.Generic.910337
IKARUS anti.virus AdWare.SuspectCRC
K7 AntiVirus Trojan ( 00495b741 )
K7GW Trojan ( 00495b741 )
Malwarebytes PUP.Optional.WeatherItUp.A
McAfee Artemis!979FD2706F4D
McAfee-GW-Edition Artemis!979FD2706F4D
MicroWorld-eScan Adware.Generic.910337
NANO AntiVirus Trojan.Win32.Crossrider.cwggpx
Symantec Adware.Crossid
VIPRE Antivirus Crossrider (fs)
Avira AntiVir Adware/CrossRider.A.1708
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
nProtect Trojan.Generic.11250844
Qihoo-360 HEUR/Malware.QVM10.Gen
TrendMicro-HouseCall TROJ_GEN.F47V0427
Sophos AppRider
Agnitum Outpost PUA.Toolbar.CrossRider!
AVware Trojan.Win32.Generic!BT
Clam AntiVirus Win.Trojan.Agent-839129
SUPERAntiSpyware Trojan.Agent/Gen-Downloader
Zillya Adware.CroRi.Win32.439
Norman Suspicious_Gen2.VVXJK
avast! Win32:Adware-gen [Adw]
Panda Antivirus Trj/Genetic.gen
Bkav FE W32.CrossRider.Trojan
Weather It Up-codedownloader.exe (MD5: 03129871f0bfb98cc31fbeb013a6d711) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11030524
Agnitum Outpost PUA.Toolbar.CrossRider!
AVG Generic5.APHA
Baidu-International Adware.Win32.CrossRider.40
Bitdefender Trojan.Generic.11030524
Dr.Web Trojan.Crossrider.7193
Emsisoft Anti-Malware Trojan.Generic.11030524 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AA
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11030524
G Data Trojan.Generic.11030524
IKARUS anti.virus Trojan.SuspectCRC
K7 AntiVirus Trojan ( 004965ab1 )
K7GW Trojan ( 004965ab1 )
Malwarebytes PUP.Optional.WeatherItUp.A
MicroWorld-eScan Trojan.Generic.11030524
NANO AntiVirus Trojan.Win32.Crossrider.cwhmph
Norman Troj_Generic.TEZJT
nProtect Trojan.Generic.11030524
TrendMicro-HouseCall TROJ_GEN.F47V0315
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/Win32.SGeneric
McAfee Artemis!979FD2706F4D
McAfee-GW-Edition Artemis!979FD2706F4D
Symantec Adware.Crossid
Avira AntiVir Adware/CrossRider.A.1708
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
AVware Trojan.Win32.Generic!BT
Clam AntiVirus Win.Trojan.Agent-839129
SUPERAntiSpyware Trojan.Agent/Gen-Downloader
Zillya Adware.CroRi.Win32.439
avast! Win32:Adware-gen [Adw]
Panda Antivirus Trj/Genetic.gen
Bkav FE W32.CrossRider.Trojan

Software Behaviors

Scheduled tasks:
  • Uninstall.exe is scheduled as a task with the class '{D73EFAF1-A52C-425B-8333-F71F1A3EC26B}' (runs on registration).

Startup Entries

Startup tasks:
  • Weather It Up-codedownloader.exe is automatically launched at startup through a scheduled task named cb607470-d07a-4f06-a139-46cad63fe159-1.
  • cb607470-d07a-4f06-a139-46cad63fe159-5.exe is automatically launched at startup through a scheduled task named cb607470-d07a-4f06-a139-46cad63fe159-5_user.
  • cb607470-d07a-4f06-a139-46cad63fe159-4.exe is automatically launched at startup through a scheduled task named cb607470-d07a-4f06-a139-46cad63fe159-4.
  • cb607470-d07a-4f06-a139-46cad63fe159-2.exe is automatically launched at startup through a scheduled task named cb607470-d07a-4f06-a139-46cad63fe159-2.
  • def30c52-fe80-4b26-8d43-62b3a67cc537-5.exe is automatically launched at startup through a scheduled task named def30c52-fe80-4b26-8d43-62b3a67cc537-5.
  • def30c52-fe80-4b26-8d43-62b3a67cc537-4.exe is automatically launched at startup through a scheduled task named def30c52-fe80-4b26-8d43-62b3a67cc537-4.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\weather it up
Uninstaller:
C:\Program Files\Weather It Up\Uninstall.exe /fromcontrolpanel=1
Size:
9.00 MB
Language:
English

Weather It Up Executable Details

Primary executable:
utils.exe
Name:
Weather It Up
Path:
C:\Program Files\weather it up\utils.exe
MD5:
7f44d95a3983d98f793820ebdf19c3f4
SHA-1:
–
SHA-256:
–
Files installed by Weather It Up
File Type Filename MD5
EXE
339aa29983ca634fb361ff95494bb67e
EXE
dfdda14bf42094ebf515e2e4e6a1e68d
EXE
1da53a7d9d3f23a225a2b8b9c8ff084e
EXE
40beb59b6a1af4035cba812e3e56652f
EXE
28f300d3c7ed654010761da6995c7031
EXE
8c058b53b896c0e6b509185ff49b6627
EXE
853b9b7dcece448fbe69b25d88e741c7
EXE
07ef7ae31562cf8c736771a012acb33a
EXE
00af96b574774a20f7493feb30a37844
EXE
1cca1df14b96965bfd16f89e092ea9bf