SpywareStormer
|
Description:
|
Rogue Security Program
|
|
Risk Level:
|
High
|
|
Date of First Occurence:
|
Tuesday, April 15, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Rogue/Suspect Anti-Spyware Product
"Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
REMOVER SPYWARE »
Geographical Distribution of Threat "SpywareStormer"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\Spyware Stormer\Setup.exe
MD5: 8EC03A7814652152C7AFAD15F3E4BD18 Size:1088293
MD5: B4FD6907CC76F883F132532633B9C7EF Size:1010052
MD5: 3D5B0E786D5F48A01F258C6DF23D6165 Size:1110625
MD5: E1FF41FCAFA1DAD781B61C50B6EA42EB Size:1620217
MD5: 5F511010F4AD5EF34876B5EA95D2612C Size:1083235
MD5: 94B89F2E449BE1397DDD1C8921D26603 Size:1131080
MD5: D49C8362F422FBCFD7E6BF35C1CAD32B Size:1087977
MD5: 5C000CCC37764A2ED240FEACAF63D7C4 Size:1062573
MD5: AF143944DFA4ED59B0FA1F27C71BE92A Size:1136022
MD5: E4E370BB33046E2EBACD382574BBF914 Size:1059196
MD5: EE6BF3B5EA91C0320C9E69DF88103705 Size:1310700
MD5: EBE87DC06DAA8EA7BD29FA910BF4215F Size:1374367
and more....
%PROGRAMFILES%\Spyware Stormer\uninst.exe
MD5: E0644222058D129713B497893DA52F42 Size:47305
MD5: 4776978051E8745A9E3D9FF3544EF77B Size:48316
MD5: 54F8BC2DBA59B37416A6B7940978C3B7 Size:48849
MD5: 7578F1F867F2D722B8C7823480251672 Size:47305
%PROGRAMFILES%\Spyware Stormer\SpywareStormer.exe
MD5: 8535DFC693D9163BD5718F3ECE85736D Size:929792
MD5: 0357E7E87AEF6D631B1AFF182A03FEF8 Size:929792
%PROGRAMFILES%\Spyware Stormer\SpywareStormer.Exe
MD5: 4C8E2CA5972B273EF2BA27FD97E4E7BD Size:901120
%PROGRAMFILES%\Spyware Stormer\Setup.exe
MD5: 9611FA242F88C5303B419F3C9C0B48D1 Size:1106521
MD5: 45797B7E62BCE39BC6930056CB3820FA Size:1083210
MD5: 28E75ECFE880096CF301D80C65AC6713 Size:1086800
MD5: CA4F41E3F7770E725C4FB3A83B5961A6 Size:1550585
- Detected Files with variable Filenames:
MD5: B4FD6907CC76F883F132532633B9C7EF Size: 1010052
%PROGRAMFILES%\Spyware Stormer\Setup.exe
%PROGRAMFILES%\Spyware Stormer\setup.exe.ren
MD5: 4776978051E8745A9E3D9FF3544EF77B Size: 48316
%PROGRAMFILES%\Spyware Stormer\uninst.exe
%PROGRAMFILES%\Spyware Stormer\uninst.exe.ren
MD5: 7BC6CA66B6CCBA77D9DF772B11C74236 Size: 901120
%PROGRAMFILES%\Spyware Stormer\SpywareStormer.Exe
%PROGRAMFILES%\Spyware Stormer\spywarestormer.exe.ren
MD5: E4E370BB33046E2EBACD382574BBF914 Size: 1059196
%PROGRAMFILES%\Spyware Stormer\Setup.exe
%PROGRAMFILES%\Spyware Stormer\setup.exe.ren
MD5: 0357E7E87AEF6D631B1AFF182A03FEF8 Size: 929792
%PROGRAMFILES%\Spyware Stormer\SpywareStormer.exe
%PROGRAMFILES%\Spyware Stormer\spywarestormer.exe.ren
Detecting items list:
- Files by Name
%ProgramFiles%\Spyware Stormer\Install.log
%ProgramFiles%\Spyware Stormer\Setup.exe
%ProgramFiles%\Spyware Stormer\SpyLog.txt
%ProgramFiles%\Spyware Stormer\DataBase.ref
%ProgramFiles%\Spyware Stormer\Spyware Stormer.url
%ProgramFiles%\Spyware Stormer\SpywareStormer.exe
%ProgramFiles%\Spyware Stormer\uninst.exe
%ProgramFiles%\Spyware Stormer\Settings\CustomScan.stg
%ProgramFiles%\Spyware Stormer\Settings\IgnoreList.stg
%ProgramFiles%\Spyware Stormer\Settings\PrevHandle.stg
%ProgramFiles%\Spyware Stormer\Settings\ScanInfo.stg
%ProgramFiles%\Spyware Stormer\Settings\SelectedFolders.stg
%ProgramFiles%\Spyware Stormer\Settings\Settings.stg
%ProgramFiles%\Spyware Stormer\Settings\ListItems.stg
%DESKTOP%\Spyware Stormer.lnk
%START_PROGRAMS%\Spyware Stormer\Spyware Stormer.lnk
%START_PROGRAMS%\Spyware Stormer\Uninstall.lnk
%START_PROGRAMS%\Spyware Stormer\Website.lnk
- Files by Directories
%ProgramFiles%\Spyware Stormer
%START_PROGRAMS%\Spyware Stormer
- Files by CLSID or Name
CLSID=205FF73B-CA67-11D5-99DD-444553540000
- Registry Keys
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Stormer
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SpywareStormer.exe
HKLM\Software\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540000}
HKCR\Interface\{205FF73A-CA67-11D5-99DD-444553540000}
- Registry Values
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=Spyware Stormer
«
Go to Software Database