stormwatchsrv.exe

Weather Warnings LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application stormwatchsrv.exe by Weather Warnings has been detected as adware by 2 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “StormWatch Update Service”. This file is typically installed with the program StormWatch by Local Weather LLC which is a potentially unwanted software program.
Publisher:
Weather Warnings LLC  (signed and verified)

Version:
1.1.0.21

MD5:
f367cc1c2ce8567578cb4806f129f250

SHA-1:
aea65a492c6ee0191a0c7c0466d3c76a2c03e6d1

SHA-256:
ddcfa2bd7cc07e142a4345a0eafd421c7c9e7f00d90803a159532c1bb4ad063b

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
11/23/2024 3:55:57 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3040

Reason Heuristics
PUP.Weather.WeatherWarnings (M)
15.7.22.15

File size:
617.2 KB (631,992 bytes)

Product version:
1.1.0.21

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\stormwatch\stormwatchsrv.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/24/2015 8:00:00 PM

Valid to:
5/24/2016 7:59:59 PM

Subject:
CN=Weather Warnings LLC, O=Weather Warnings LLC, L=Austin, S=Texas, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
079CB9C1FFEB0CA9C428CBBE65D2EEE9

File PE Metadata
Compilation timestamp:
7/20/2015 3:57:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:bx1cDAJ7EwxxZGIGMgBGgAO8AOe8tDLkC8wDYC9zdJE2:7mwxxZGvpBGgGw8tDI3CPJE2

Entry address:
0x1BFA0

Entry point:
E8, 1B, A6, 00, 00, E9, 7F, FE, FF, FF, E8, 4F, 14, 00, 00, 85, C0, 75, 06, B8, FC, E3, 48, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 1B, 14, 00, 00, 85, C0, 75, 06, B8, F8, E3, 48, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, 90, E2, 48, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.2719

Code size:
408 KB (417,792 bytes)

Service
Display name:
StormWatch Update Service

Description:
Keep your StormWatch software up to date.

Type:
Win32OwnProcess

Depends on:
RPCSS


The file stormwatchsrv.exe has been discovered within the following program.

StormWatch  by Local Weather LLC
StormWatch is a potentially unwanted adware program that injects ads into the user's browser. This includes inserting into web pages or displaying ads over parts of existing web page advertisements, banners, coupons or text links that would not otherwise appear.
84% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to server-54-230-16-50.iad12.r.cloudfront.net  (54.230.16.50:443)

TCP (HTTP SSL):
Connects to server-54-192-119-49.sfo9.r.cloudfront.net  (54.192.119.49:443)

Remove stormwatchsrv.exe - Powered by Reason Core Security