iobitappstoolbarff.dll

WidgiFF Dynamic Link Library

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The module iobitappstoolbarff.dll by Spigot has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
WidgiFF Dynamic Link Library

Description:
Widgi Toolbar

Version:
8, 3, 0, 1

MD5:
2179f4220eb2d2feec2059190d358915

SHA-1:
6868496c6e591a1aec167726bf79ef96f87750f1

SHA-256:
f439defb7197513ff49d403dfc436272710f43839d5e633894acd16c214964cd

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
12/8/2021 3:48:17 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Toolbar.Widgi (variant)
7.9371

Reason Heuristics
PUP.Toolbar.Spigot.S
14.8.7.21

Trend Micro House Call
TROJ_GEN.F47V1110
7.2.219

File size:
1.1 MB (1,204,544 bytes)

Product version:
8, 3, 0, 1

Copyright:
Copyright © 2005-2013 Spigot, Inc.

Original file name:
WidgiFF.dll

File type:
Dynamic link library (Win32 DLL)

Installer:
Spigot Setup

Language:
English (United States)

Common path:
C:\Program Files\iobit apps toolbar\ff\components\iobitappstoolbarff.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2012 1:00:00 AM

Valid to:
3/29/2015 12:59:59 AM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
494FF8E91607158CD480B23C615CFF8B

File PE Metadata
Compilation timestamp:
11/26/2013 11:44:10 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:9C1u0O3+TMorAmvmzZALb02HCvq9kvd2mja:9lCr/oG02HAvd2mja

Entry address:
0x83633

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, E1, 9A, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 51, 53, 56, 57, FF, 35, 88, F6, 0C, 10, E8, 43, 68, 00, 00, FF, 35, 84, F6, 0C, 10, 8B, F8, 89, 7D, FC, E8, 33, 68, 00, 00, 8B, F0, 59, 59, 3B, F7, 0F, 82, 83, 00, 00, 00, 8B, DE, 2B, DF, 8D, 43, 04, 83, F8, 04, 72, 77, 57, E8, 22, 9B, 00, 00, 8B, F8, 8D, 43, 04, 59, 3B, F8, 73, 48, B8, 00, 08, 00, 00, 3B, F8, 73, 02, 8B, C7, 03, C7, 3B, C7, 72, 0F...
 
[+]

Code size:
663 KB (678,912 bytes)

Remove iobitappstoolbarff.dll - Powered by Reason Core Security