stormwatchapp.exe

Weather Protector LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application stormwatchapp.exe by Weather Protector has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program StormWatch by Local Weather LLC which is a potentially unwanted software program.
Publisher:
Weather Protector LLC  (signed and verified)

Version:
1.0.1.36

MD5:
163a52b95746396568d1ad6fb94e8344

SHA-1:
cd19ed002c144b38cb3dc88084d46211c6d3ab8a

SHA-256:
18ef8ffc77a176736129c4bdb384ef8aa089e3bb9e081915f73c4b46837ace5d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 12:30:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Weather.WeatherProtector (M)
16.2.9.7

File size:
1.4 MB (1,465,880 bytes)

Product version:
1.0.1.36

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\stormwatch\stormwatchapp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/12/2014 7:00:00 PM

Valid to:
6/13/2015 6:59:59 PM

Subject:
CN=Weather Protector LLC, O=Weather Protector LLC, STREET="101 Colorado St #2309", L=Austin, S=TX, PostalCode=78701, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00833BECDB30CAD96C0E0AC4DF14A0329F

File PE Metadata
Compilation timestamp:
11/25/2014 1:47:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:4RWKabEiIM1tj3RKmSeuXZiacQn9v5WcChdY5DzmEeZtpfKk5OAH3hRfDXzzjTDR:vPbJF/ChfIezm/8anD06z

Entry address:
0x4A393

Entry point:
E8, 50, C7, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, E0, 81, 52, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 29, A2, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, A9, C3, FF, FF, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
5.9280

Code size:
896 KB (917,504 bytes)

The file stormwatchapp.exe has been discovered within the following programs.

StormWatch  by Local Weather LLC
StormWatch is a potentially unwanted adware program that injects ads into the user's browser. This includes inserting into web pages or displaying ads over parts of existing web page advertisements, banners, coupons or text links that would not otherwise appear.
84% remove it
 
Powered by Should I Remove It?

Remove stormwatchapp.exe - Powered by Reason Core Security