st_rsser64.exe

Spyware Terminator 2015

Crawler Group, LLC

The application st_rsser64.exe, “Spyware Terminator 2015 Realtime Shield Service” by Crawler Group has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Spyware Terminator 2012 Realtime Shield Service”. This file is typically installed with the program Spyware Terminator 2015 by Crawler Group, LLC which is a potentially unwanted software program.
Publisher:
Crawler Group, LLC  (signed and verified)

Product:
Spyware Terminator 2015

Description:
Spyware Terminator 2015 Realtime Shield Service

Version:
3.0.1.109

MD5:
df224a495a86ebfd97b70e4e81f7dfa6

SHA-1:
2a5e8f3cb5960912dabba8bd7e3a71a1f3905e29

SHA-256:
3032602631b03d3018e8db2e78fbb425f6d759af261d996be1ab15a42c23f07a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
1/12/2025 5:03:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Crawler (M)
17.3.16.12

File size:
3.1 MB (3,292,424 bytes)

Product version:
3.0.0.0

Copyright:
© Crawler Group, LLC

Original file name:
st_rsser.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\spyware terminator\st_rsser64.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
4/4/2016 9:00:00 PM

Valid to:
8/20/2017 8:59:59 PM

Subject:
CN="Crawler Group, LLC", O="Crawler Group, LLC", L=Wilmington, S=Delaware, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
533225A4195C349EB2DE67B04D02A0C4

File PE Metadata
Compilation timestamp:
3/14/2017 7:28:57 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

Entry address:
0x2934E0

Entry point:
55, 48, 83, EC, 30, 48, 8B, EC, 48, 89, 6D, 28, 48, 8B, 05, C5, 0D, 04, 00, C6, 00, 01, 90, 48, 8D, 0D, DA, 1B, FF, FF, E8, 0D, 30, D8, FF, 90, E8, C7, E6, FE, FF, EB, 08, 90, 90, E8, 5E, A6, D7, FF, 90, E8, E8, AE, D7, FF, EB, 08, 90, 90, E8, CF, B0, D7, FF, 90, 48, 8D, 65, 30, 5D, C3, 48, 8D, 04, 05, 00, 00, 00, 00, 48, 83, EC, 28, E8, 67, A5, D7, FF, 48, 83, C4, 28, C3, 48, 90, 48, 83, EC, 28, E8, 57, A5, D7, FF, 48, 83, C4, 28, C3, CC, CC, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
2.6 MB (2,696,704 bytes)

Service
Display name:
Spyware Terminator 2012 Realtime Shield Service

Service name:
ST2012_Svc

Type:
Win32OwnProcess


The file st_rsser64.exe has been discovered within the following programs.

Spyware Terminator 2015  by Crawler Group, LLC
Publisher's description - “Free real-time protection that effectively detects, removes and prevents spyware, adware, trojans, keyloggers, home page hijackers and other malware threats that may harm your computer.”
www.spywareterminator.com
61% remove it
 
Powered by Should I Remove It?

Remove st_rsser64.exe - Powered by Reason Core Security