SearchSettings.exe

Widgi Toolbar

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application SearchSettings.exe has been detected as adware by 3 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SearchSettings’. While running, it connects to the Internet address 14.d7.24ae.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Spigot, Inc.

Product:
Widgi Toolbar

Description:
Search Settings

Version:
4, 1, 7

MD5:
2d5966e168ad595193f4a1c4dd76b20e

SHA-1:
107f463ae7a8a0ece6f5e6ae516c957400c665e5

SHA-256:
88701930ccd021b9b9cd25b022aaff410a5ec9785e0b08aa889204f092d2983d

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/25/2024 7:43:01 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
UnneededApp.Spigot.O
187346

ESET NOD32
Win32/Toolbar.Widgi
8.9388

Reason Heuristics
Adware.Toolbar.Spigot.O
14.2.6.11

File size:
512 KB (524,288 bytes)

Product version:
4, 1, 7

Copyright:
Copyright © 2005-2010 Spigot, Inc.

Original file name:
SearchSettings.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\spigot\search settings\searchsettings.exe

File PE Metadata
Compilation timestamp:
10/22/2010 4:47:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:AHAQzrxXrgegf5/agdapKK+G7qRsG0COgNVOiYSi2:kHzrxXi5zYpK8Cp1

Entry address:
0x24089

Entry point:
E8, AA, 03, 00, 00, E9, 37, FD, FF, FF, CC, FF, 25, 0C, A3, 42, 00, FF, 25, 10, A3, 42, 00, FF, 25, 2C, A3, 42, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 0A, FB, FF, FF, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, F4, FA, FF, FF, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B8, B7, 43, 00, 89, 0D, B4, B7, 43, 00, 89, 15, B0, B7, 43, 00, 89, 1D, AC, B7, 43, 00, 89, 35, A8, B7, 43, 00, 89...
 
[+]

Entropy:
4.7352

Code size:
162 KB (165,888 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchSettings

Command:
"C:\Program Files\common files\spigot\search settings\searchsettings.exe"


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 14.d7.24ae.ip4.static.sl-reverse.com  (174.36.215.20:80)

TCP (HTTP):
Connects to ir1.fp.vip.ir2.yahoo.com  (46.228.47.115:80)

Remove SearchSettings.exe - Powered by Reason Core Security