Home Malware Programs Adware StormWatch

StormWatch

Posted: September 18, 2014

Threat Metric

Ranking: 8,906
Threat Level: 2/10
Infected PCs: 36,031
First Seen: September 18, 2014
Last Seen: March 8, 2025
OS(es) Affected: Windows


StormWatch is a program that appears to be developed for displaying weather information or storm alerts on a Windows desktop. Usually StormWatch will be loaded automatically on a system by means of the use downloading and installing random freeware programs or bundled software applications obtained from the internet or a downloads site. In some situations removal of the StormWatch program may prove to be difficult or leaves other components loaded where the ads from StormWatch keep loading. It is best to take an approach to remove StormWatch and its components completely through use of an antispyware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\StormWatch\StormWatch.exe File name: StormWatch.exe
Size: 160.93 KB (160936 bytes)
MD5: 4a733a67a57aabc854435c8537a62a8a
Detection count: 6,937
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\StormWatch\StormWatch.exe
Group: Malware file
Last Updated: January 23, 2024
C:\System Volume Information\_restore{8EACE45B-C48E-4A37-A55C-C32F4F7B3227}\RP15\A0008450.exe File name: A0008450.exe
Size: 1.46 MB (1465880 bytes)
MD5: 163a52b95746396568d1ad6fb94e8344
Detection count: 3,675
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{8EACE45B-C48E-4A37-A55C-C32F4F7B3227}\RP15\A0008450.exe
Group: Malware file
Last Updated: January 12, 2024
C:\TDSSKiller_Quarantine\30.06.2015_15.25.41\susp0019\file0000\tsk0001.dta File name: tsk0001.dta
Size: 1.55 MB (1556504 bytes)
MD5: 8e1d5b57d86384027dbb7b73cab42552
Detection count: 33
Mime Type: unknown/dta
Path: C:\TDSSKiller_Quarantine\30.06.2015_15.25.41\susp0019\file0000\tsk0001.dta
Group: Malware file
Last Updated: February 26, 2021
%PROGRAMFILES%\StormWatch\StormWatchApp.exe File name: StormWatchApp.exe
Size: 1.73 MB (1730232 bytes)
MD5: 2ef98441d03c9312c2ee02daa19ff446
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\StormWatch
Group: Malware file
Last Updated: April 22, 2020
C:\Program Files\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir File name: StormWatchApp.exe.vir
Size: 1.55 MB (1555992 bytes)
MD5: 767d3a61548ec4099c4b93d10329b144
Detection count: 7
Mime Type: unknown/vir
Path: C:\Program Files\AdwCleaner\Quarantine\C\Program Files (x86)\StormWatch\StormWatchApp.exe.vir
Group: Malware file
Last Updated: January 28, 2024

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{4D6A5312-AB4D-41AA-8BED-0E019B87CA11}File name without pathUninstall StormWatch.lnkHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exeSOFTWARE\Microsoft\Tracing\StormUpdater_RASAPI32SOFTWARE\Microsoft\Tracing\StormUpdater_RASMANCSSOFTWARE\Microsoft\Tracing\StormWatch_RASAPI32SOFTWARE\Microsoft\Tracing\StormWatch_RASMANCSSoftware\StormWatchSoftware\StormWatchAppSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\StormUpdater_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\StormUpdater_RASMANCSSOFTWARE\Wow6432Node\StormWatchSOFTWARE\Wow6432Node\StormWatchAppSYSTEM\ControlSet001\services\StormWatch Update ServiceSYSTEM\ControlSet002\services\StormWatch Update ServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}StormWatch

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\StormWatch%APPDATA%\Microsoft\Windows\Start Menu\Programs\StormWatch%LOCALAPPDATA%\StormWatch%LOCALAPPDATA%\Weather_Protector_LLC%PROGRAMFILES%\StormWatch%PROGRAMFILES(x86)%\StormWatch%UserProfile%\Local Settings\Application Data\StormWatch%UserProfile%\Local Settings\Application Data\Weather_Protector_LLC%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\StormWatch%WINDIR%\System32\config\systemprofile\AppData\Local\StormWatch
Loading...