SearchSettings.exe

Widgi Toolbar

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application SearchSettings.exe by Spigot has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SearchSettings’.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
Widgi Toolbar

Description:
Search Settings

Version:
8, 6, 0, 3

MD5:
992c5a2e411301161ebf777e059f817c

SHA-1:
799a49fc30b1e30a3ac8c29ad721efc1bf49721f

SHA-256:
d6d4357b7d4a04b8acd99cc19bd9ad9f6792158f06a415f188dca76247baaaee

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
4/25/2024 12:04:01 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.30.172

Baidu Antivirus
Adware.Win32.Widgi
4.0.3.1487

Boost by Reason
Optional.Startup.Spigot.O
188838

Dr.Web
Trojan.Damaged.1
9.0.1.0219

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Widgi.AMN
8.14.01.18.02

ESET NOD32
Win32/Toolbar.Widgi (variant)
8.9307

Reason Heuristics
PUP.Startup.Spigot.O
14.8.7.21

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10435

Trend Micro House Call
TROJ_GEN.F47V0716
7.2.18

File size:
1.3 MB (1,384,256 bytes)

Product version:
8, 6, 0, 3

Copyright:
Copyright © 2005-2013 Spigot, Inc.

Original file name:
SearchSettings.exe

File type:
Executable application (Win32 EXE)

Installer:
Spigot Setup

Language:
English (United States)

Common path:
C:\Program Files\common files\spigot\search settings\searchsettings.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2012 1:00:00 AM

Valid to:
3/29/2015 12:59:59 AM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
494FF8E91607158CD480B23C615CFF8B

File PE Metadata
Compilation timestamp:
1/16/2014 4:53:11 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:vK3Yyp+JZq1BI38bjxUvGekgXTwN3Ujgihy:CnEq1BI38btiGeDTwZWgihy

Entry address:
0x98B91

Entry point:
E8, C9, 98, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, A8, AC, 4D, 00, E8, C5, E8, FF, FF, 33, F6, 89, 75, E4, 33, C0, 8B, 5D, 08, 3B, DE, 0F, 95, C0, 3B, C6, 75, 1C, E8, 19, 56, 00, 00, C7, 00, 16, 00, 00, 00, 56, 56, 56, 56, 56, E8, 32, F5, FF, FF, 83, C4, 14, 33, C0, EB, 7B, 33, C0, 8B, 7D, 0C, 3B, FE, 0F, 95, C0, 3B, C6, 74, D6, 33, C0, 66, 39, 37, 0F, 95, C0, 3B, C6, 74, CA, E8, 69, 9D, 00, 00, 89, 45, 08, 3B, C6, 75, 0D, E8, D7, 55, 00, 00, C7, 00, 18, 00, 00, 00, EB, C9, 89, 75, FC, 66, 39, 33, 75, 20...
 
[+]

Code size:
762 KB (780,288 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchSettings

Command:
"C:\Program Files\common files\spigot\search settings\searchsettings.exe"


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 174.36.215.20-static.reverse.softlayer.com  (174.36.215.20:80)

Remove SearchSettings.exe - Powered by Reason Core Security