SearchSettings.exe

Widgi Toolbar

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application SearchSettings.exe by Spigot has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SearchSettings’.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
Widgi Toolbar

Description:
Search Settings

Version:
8, 6, 0, 1

MD5:
b7c6f474a2b4135a8ac34b2f068ea577

SHA-1:
7c5ab9f60143cb277aa423e3c55787d636328f29

SHA-256:
51ab978d46a86a47f0271d2d87e7ef1e31e176f93e4e6467121e4a4c5901337a

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
4/26/2024 6:25:00 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.30.172

Baidu Antivirus
Adware.Win32.Widgi
4.0.3.1487

Boost by Reason
Optional.Startup.Spigot.O
188838

Dr.Web
Trojan.Damaged.1
9.0.1.0219

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Widgi.AMN
8.14.01.10.01

ESET NOD32
Win32/Toolbar.Widgi (variant)
8.9155

Reason Heuristics
PUP.Startup.Spigot.O
14.8.7.21

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10435

Trend Micro House Call
TROJ_GEN.F47V0716
7.2.10

File size:
1.3 MB (1,383,232 bytes)

Product version:
8, 6, 0, 1

Copyright:
Copyright © 2005-2013 Spigot, Inc.

Original file name:
SearchSettings.exe

File type:
Executable application (Win32 EXE)

Installer:
Spigot Setup

Language:
English (United States)

Common path:
C:\Program Files\common files\spigot\search settings\searchsettings.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2012 1:00:00 AM

Valid to:
3/29/2015 12:59:59 AM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
494FF8E91607158CD480B23C615CFF8B

File PE Metadata
Compilation timestamp:
12/27/2013 4:02:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:6P8jT9juiuTGqlXA6drxBA0WSLfbvTwHSTupHmd:fxuxTNXAYr3AHSLDTwyTupHmd

Entry address:
0x987C1

Entry point:
E8, C9, 98, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 70, AC, 4D, 00, E8, C5, E8, FF, FF, 33, F6, 89, 75, E4, 33, C0, 8B, 5D, 08, 3B, DE, 0F, 95, C0, 3B, C6, 75, 1C, E8, 19, 56, 00, 00, C7, 00, 16, 00, 00, 00, 56, 56, 56, 56, 56, E8, 32, F5, FF, FF, 83, C4, 14, 33, C0, EB, 7B, 33, C0, 8B, 7D, 0C, 3B, FE, 0F, 95, C0, 3B, C6, 74, D6, 33, C0, 66, 39, 37, 0F, 95, C0, 3B, C6, 74, CA, E8, 69, 9D, 00, 00, 89, 45, 08, 3B, C6, 75, 0D, E8, D7, 55, 00, 00, C7, 00, 18, 00, 00, 00, EB, C9, 89, 75, FC, 66, 39, 33, 75, 20...
 
[+]

Code size:
761 KB (779,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchSettings

Command:
"C:\Program Files\common files\spigot\search settings\searchsettings.exe"


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 174.36.215.20-static.reverse.softlayer.com  (174.36.215.20:80)

Remove SearchSettings.exe - Powered by Reason Core Security