SearchSettings.exe

Widgi Toolbar

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application SearchSettings.exe by Spigot has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SearchSettings’.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
Widgi Toolbar

Description:
Search Settings

Version:
8, 5, 0, 2

MD5:
414eacbc851e7fa68f1402ebb639c493

SHA-1:
3384310df78e9e59105f27cf75fafb0699266f0e

SHA-256:
74e5890ada1622dc6102498140f31a2bff4c6b5f9d80e672b75b9afd60f7f928

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
5/11/2024 2:13:19 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.30.172

Baidu Antivirus
Adware.Win32.Widgi
4.0.3.1487

Boost by Reason
Optional.Startup.Spigot.O
188838

Dr.Web
Trojan.Damaged.1
9.0.1.0219

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Widgi.AMN
8.13.12.18.09

ESET NOD32
Win32/Toolbar.Widgi (variant)
7.9155

Reason Heuristics
PUP.Startup.Spigot.O
14.8.7.21

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10435

Trend Micro House Call
TROJ_GEN.F47V0716
7.2.352

File size:
1.3 MB (1,383,232 bytes)

Product version:
8, 5, 0, 2

Copyright:
Copyright © 2005-2013 Spigot, Inc.

Original file name:
SearchSettings.exe

File type:
Executable application (Win32 EXE)

Installer:
Spigot Setup

Language:
English (United States)

Common path:
C:\Program Files\common files\spigot\search settings\searchsettings.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/25/2012 9:00:00 AM

Valid to:
3/28/2015 8:59:59 AM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
494FF8E91607158CD480B23C615CFF8B

File PE Metadata
Compilation timestamp:
12/13/2013 7:33:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:/CFFsuWL0fi5K1BbI9DRwnZGKrMTwUiqpHmT:JJ0fis1CdR2ZGlTwUiqpHmT

Entry address:
0x987A1

Entry point:
E8, CB, 98, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 70, AC, 4D, 00, E8, C5, E8, FF, FF, 33, F6, 89, 75, E4, 33, C0, 8B, 5D, 08, 3B, DE, 0F, 95, C0, 3B, C6, 75, 1C, E8, 19, 56, 00, 00, C7, 00, 16, 00, 00, 00, 56, 56, 56, 56, 56, E8, 32, F5, FF, FF, 83, C4, 14, 33, C0, EB, 7B, 33, C0, 8B, 7D, 0C, 3B, FE, 0F, 95, C0, 3B, C6, 74, D6, 33, C0, 66, 39, 37, 0F, 95, C0, 3B, C6, 74, CA, E8, 6B, 9D, 00, 00, 89, 45, 08, 3B, C6, 75, 0D, E8, D7, 55, 00, 00, C7, 00, 18, 00, 00, 00, EB, C9, 89, 75, FC, 66, 39, 33, 75, 20...
 
[+]

Code size:
761 KB (779,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchSettings

Command:
"C:\Program Files\common files\spigot\search settings\searchsettings.exe"


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 174.36.215.20-static.reverse.softlayer.com  (174.36.215.20:80)

TCP (HTTP):
Connects to internetschutz.aon.at  (213.33.98.117:80)

Remove SearchSettings.exe - Powered by Reason Core Security