stormwatchsrv.exe

Weather Protector LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application stormwatchsrv.exe by Weather Protector has been detected as adware by 3 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “StormWatch Update Service”. This file is typically installed with the program StormWatch by Local Weather LLC which is a potentially unwanted software program.
Publisher:
Weather Protector LLC  (signed and verified)

Version:
1.0.2.55

MD5:
f5aea5c2d683a3b5c92e1911886e9ac9

SHA-1:
9559e5088ce7a52f465c8be49948538da828f734

SHA-256:
b0a368997cc9250473045b6c452a5bf13ae8b9558fc72a0d304779031e7ba003

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
11/23/2024 7:57:49 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Reason Heuristics
PUP.Service.Weather
15.4.10.17

VIPRE Antivirus
Threat.4793388
38882

File size:
572.5 KB (586,264 bytes)

Product version:
1.0.2.55

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\stormwatch\stormwatchsrv.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/12/2014 8:00:00 PM

Valid to:
6/13/2015 7:59:59 PM

Subject:
CN=Weather Protector LLC, O=Weather Protector LLC, STREET="101 Colorado St #2309", L=Austin, S=TX, PostalCode=78701, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00833BECDB30CAD96C0E0AC4DF14A0329F

File PE Metadata
Compilation timestamp:
4/10/2015 9:49:53 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:ejYUP0O4lAhOc2eJ18vZ3v8Tie8rTOPRAOnAOYGjl0tUx5fNnzquw:q0O4+0c2eJ18vZf8mbrTEhmG5T5ZqN

Entry address:
0x1B494

Entry point:
E8, 0C, A6, 00, 00, E9, 7F, FE, FF, FF, E8, 4F, 14, 00, 00, 85, C0, 75, 06, B8, EC, 43, 48, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 1B, 14, 00, 00, 85, C0, 75, 06, B8, E8, 43, 48, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, 80, 42, 48, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.2930

Code size:
377 KB (386,048 bytes)

Service
Display name:
StormWatch Update Service

Description:
Keep your StormWatch software up to date.

Type:
Win32OwnProcess

Depends on:
RPCSS


The file stormwatchsrv.exe has been discovered within the following program.

StormWatch  by Local Weather LLC
StormWatch is a potentially unwanted adware program that injects ads into the user's browser. This includes inserting into web pages or displaying ads over parts of existing web page advertisements, banners, coupons or text links that would not otherwise appear.
84% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to server-54-230-15-149.ams1.r.cloudfront.net  (54.230.15.149:443)

TCP (HTTP SSL):
Connects to server-54-192-129-185.ams50.r.cloudfront.net  (54.192.129.185:443)

TCP (HTTP SSL):
Connects to server-54-192-217-115.mrs50.r.cloudfront.net  (54.192.217.115:443)

TCP (HTTP SSL):
Connects to server-52-85-69-48.lhr5.r.cloudfront.net  (52.85.69.48:443)

TCP (HTTP SSL):
Connects to server-54-230-202-34.fra50.r.cloudfront.net  (54.230.202.34:443)

TCP (HTTP SSL):
Connects to server-54-230-202-10.fra50.r.cloudfront.net  (54.230.202.10:443)

TCP (HTTP SSL):
Connects to server-54-192-217-87.mrs50.r.cloudfront.net  (54.192.217.87:443)

TCP (HTTP SSL):
Connects to server-54-192-217-187.mrs50.r.cloudfront.net  (54.192.217.187:443)

TCP (HTTP SSL):
Connects to server-54-192-217-136.mrs50.r.cloudfront.net  (54.192.217.136:443)

TCP (HTTP SSL):
Connects to server-54-192-193-159.iad53.r.cloudfront.net  (54.192.193.159:443)

TCP (HTTP SSL):
Connects to server-54-192-192-163.iad53.r.cloudfront.net  (54.192.192.163:443)

TCP (HTTP SSL):
Connects to server-54-192-119-87.sfo9.r.cloudfront.net  (54.192.119.87:443)

TCP (HTTP SSL):
Connects to server-52-84-144-66.yto50.r.cloudfront.net  (52.84.144.66:443)

TCP (HTTP SSL):
Connects to server-205-251-219-125.arn1.r.cloudfront.net  (205.251.219.125:443)

Remove stormwatchsrv.exe - Powered by Reason Core Security