stormwatchsrv.exe

Weather Protector LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application stormwatchsrv.exe by Weather Protector has been detected as adware by 3 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “StormWatch Update Service”. This file is typically installed with the program StormWatch by Local Weather LLC which is a potentially unwanted software program.
Publisher:
Weather Protector LLC  (signed and verified)

Version:
1.0.2.52

MD5:
5cb386f21b0e69cfab36a3da35a52ee4

SHA-1:
d1dc0c54ad454142e644a4ec143196715f95672e

SHA-256:
8a4bb0cb4eb253fde520a76a0d25ab6aca8cd5cfa5d18e72d8c6b5595912ac44

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
12/24/2024 2:08:33 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Sality.AT
7.11.30.172

Bkav FE
W32.HfsAdware
1.3.0.6379

Reason Heuristics
PUP.Service.Weather
15.4.9.19

File size:
572.5 KB (586,264 bytes)

Product version:
1.0.2.52

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\stormwatch\stormwatchsrv.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/12/2014 8:00:00 PM

Valid to:
6/13/2015 7:59:59 PM

Subject:
CN=Weather Protector LLC, O=Weather Protector LLC, STREET="101 Colorado St #2309", L=Austin, S=TX, PostalCode=78701, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00833BECDB30CAD96C0E0AC4DF14A0329F

File PE Metadata
Compilation timestamp:
4/9/2015 11:58:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:xwgqExKIFU1Gv2CdMg7MFxHCHNYs6oYIcXZGD:xwSFqUvbdM+yZGD

Entry address:
0x1B484

Entry point:
E8, 0C, A6, 00, 00, E9, 7F, FE, FF, FF, E8, 4F, 14, 00, 00, 85, C0, 75, 06, B8, EC, 43, 48, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 1B, 14, 00, 00, 85, C0, 75, 06, B8, E8, 43, 48, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, 80, 42, 48, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.2908

Code size:
377 KB (386,048 bytes)

Service
Display name:
StormWatch Update Service

Description:
Keep your StormWatch software up to date.

Type:
Win32OwnProcess

Depends on:
RPCSS


The file stormwatchsrv.exe has been discovered within the following program.

StormWatch  by Local Weather LLC
StormWatch is a potentially unwanted adware program that injects ads into the user's browser. This includes inserting into web pages or displaying ads over parts of existing web page advertisements, banners, coupons or text links that would not otherwise appear.
84% remove it
 
Powered by Should I Remove It?

Remove stormwatchsrv.exe - Powered by Reason Core Security