SpywareStormer

Description: Rogue Security Program
Risk Level: High
Date of First Occurence: Tuesday, April 15, 2008
Software Developer: (unknown)
Brief Info: Rogue/Suspect Anti-Spyware Product "Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
Removal: This threat can be removed using "Spyware Terminator"

SCAN & REMOVE NOW »

Geographical Distribution of Threat "SpywareStormer"

Threat Info

View All

Detected Items

  1. Detected Files: %PROGRAMFILES%\Spyware Stormer\Setup.exe MD5: 8EC03A7814652152C7AFAD15F3E4BD18 Size:1088293 MD5: B4FD6907CC76F883F132532633B9C7EF Size:1010052 MD5: 3D5B0E786D5F48A01F258C6DF23D6165 Size:1110625 MD5: E1FF41FCAFA1DAD781B61C50B6EA42EB Size:1620217 MD5: 5F511010F4AD5EF34876B5EA95D2612C Size:1083235 MD5: 94B89F2E449BE1397DDD1C8921D26603 Size:1131080 MD5: D49C8362F422FBCFD7E6BF35C1CAD32B Size:1087977 MD5: 5C000CCC37764A2ED240FEACAF63D7C4 Size:1062573 MD5: AF143944DFA4ED59B0FA1F27C71BE92A Size:1136022 MD5: E4E370BB33046E2EBACD382574BBF914 Size:1059196 MD5: EE6BF3B5EA91C0320C9E69DF88103705 Size:1310700 MD5: EBE87DC06DAA8EA7BD29FA910BF4215F Size:1374367 and more.... %PROGRAMFILES%\Spyware Stormer\uninst.exe MD5: E0644222058D129713B497893DA52F42 Size:47305 MD5: 4776978051E8745A9E3D9FF3544EF77B Size:48316 MD5: 54F8BC2DBA59B37416A6B7940978C3B7 Size:48849 MD5: 7578F1F867F2D722B8C7823480251672 Size:47305 %PROGRAMFILES%\Spyware Stormer\SpywareStormer.exe MD5: 8535DFC693D9163BD5718F3ECE85736D Size:929792 MD5: 0357E7E87AEF6D631B1AFF182A03FEF8 Size:929792 %PROGRAMFILES%\Spyware Stormer\SpywareStormer.Exe MD5: 4C8E2CA5972B273EF2BA27FD97E4E7BD Size:901120 %PROGRAMFILES%\Spyware Stormer\Setup.exe MD5: 9611FA242F88C5303B419F3C9C0B48D1 Size:1106521 MD5: 45797B7E62BCE39BC6930056CB3820FA Size:1083210 MD5: 28E75ECFE880096CF301D80C65AC6713 Size:1086800 MD5: CA4F41E3F7770E725C4FB3A83B5961A6 Size:1550585
  2. Detected Files with variable Filenames: MD5: B4FD6907CC76F883F132532633B9C7EF Size: 1010052 %PROGRAMFILES%\Spyware Stormer\Setup.exe %PROGRAMFILES%\Spyware Stormer\setup.exe.ren MD5: 4776978051E8745A9E3D9FF3544EF77B Size: 48316 %PROGRAMFILES%\Spyware Stormer\uninst.exe %PROGRAMFILES%\Spyware Stormer\uninst.exe.ren MD5: 7BC6CA66B6CCBA77D9DF772B11C74236 Size: 901120 %PROGRAMFILES%\Spyware Stormer\SpywareStormer.Exe %PROGRAMFILES%\Spyware Stormer\spywarestormer.exe.ren MD5: E4E370BB33046E2EBACD382574BBF914 Size: 1059196 %PROGRAMFILES%\Spyware Stormer\Setup.exe %PROGRAMFILES%\Spyware Stormer\setup.exe.ren MD5: 0357E7E87AEF6D631B1AFF182A03FEF8 Size: 929792 %PROGRAMFILES%\Spyware Stormer\SpywareStormer.exe %PROGRAMFILES%\Spyware Stormer\spywarestormer.exe.ren

Detecting items list:

  1. Files by Name %ProgramFiles%\Spyware Stormer\Install.log %ProgramFiles%\Spyware Stormer\Setup.exe %ProgramFiles%\Spyware Stormer\SpyLog.txt %ProgramFiles%\Spyware Stormer\DataBase.ref %ProgramFiles%\Spyware Stormer\Spyware Stormer.url %ProgramFiles%\Spyware Stormer\SpywareStormer.exe %ProgramFiles%\Spyware Stormer\uninst.exe %ProgramFiles%\Spyware Stormer\Settings\CustomScan.stg %ProgramFiles%\Spyware Stormer\Settings\IgnoreList.stg %ProgramFiles%\Spyware Stormer\Settings\PrevHandle.stg %ProgramFiles%\Spyware Stormer\Settings\ScanInfo.stg %ProgramFiles%\Spyware Stormer\Settings\SelectedFolders.stg %ProgramFiles%\Spyware Stormer\Settings\Settings.stg %ProgramFiles%\Spyware Stormer\Settings\ListItems.stg %DESKTOP%\Spyware Stormer.lnk %START_PROGRAMS%\Spyware Stormer\Spyware Stormer.lnk %START_PROGRAMS%\Spyware Stormer\Uninstall.lnk %START_PROGRAMS%\Spyware Stormer\Website.lnk
  2. Files by Directories %ProgramFiles%\Spyware Stormer %START_PROGRAMS%\Spyware Stormer
  3. Files by CLSID or Name CLSID=205FF73B-CA67-11D5-99DD-444553540000
  4. Registry Keys HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Stormer HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SpywareStormer.exe HKLM\Software\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540000} HKCR\Interface\{205FF73A-CA67-11D5-99DD-444553540000}
  5. Registry Values HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=Spyware Stormer

« Go to Software Database