SearchSettings.exe

Widgi Toolbar

CBS Interactive

The application SearchSettings.exe by CBS Interactive has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the DownloadCom Spot Install installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SearchSettings’. While running, it connects to the Internet address 14.d7.24ae.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
CBS Interactive  (signed and verified)

Product:
Widgi Toolbar

Description:
Search Settings

Version:
6, 9, 0, 1

MD5:
77a6135ca783d714c90be034edce5dc5

SHA-1:
de5bcd9c1221fdf0ef273f143afbd4e1841529b5

SHA-256:
440e44f9f6fd3a60f94c2d669bf4c751324c7358ae4d05276814b564b168261a

Scanner detections:
8 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 7:17:16 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.30.172

Baidu Antivirus
Adware.Win32.Widgi
4.0.3.141222

Dr.Web
Trojan.Damaged.1
9.0.1.0356

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Widgi.AMN
8.14.01.05.06

ESET NOD32
Win32/Toolbar.Widgi (variant)
7.9090

Reason Heuristics
PUP.Startup.CBSInteractive.O
14.8.1.0

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10163

Trend Micro House Call
TROJ_GEN.F47V0716
7.2.5

File size:
1.3 MB (1,318,120 bytes)

Product version:
6, 9, 0, 1

Copyright:
Copyright © 2005-2013 CBS Interactive

Original file name:
SearchSettings.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
DownloadCom Spot Install

Language:
English (United States)

Common path:
C:\Program Files\common files\spigot\search settings\searchsettings.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/5/2011 2:00:00 AM

Valid to:
8/5/2013 1:59:59 AM

Subject:
CN=CBS Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CBS Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
071A760107B4DE793CD48C0EDA1DF0B5

File PE Metadata
Compilation timestamp:
2/8/2013 9:40:58 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:m0S+l40XLw5vjOxzMilsLmwstZ2Y2AYsg+:m0/dLw5vyyAsLmwsuY2AYsg+

Entry address:
0x90521

Entry point:
E8, D9, 8F, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, E8, E4, 4D, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 98, A3, 4D, 00, 33, C5, 89, 45, FC, 83, A5, D8, FC, FF, FF, 00, 53, 6A, 4C, 8D, 85, DC, FC, FF, FF, 6A, 00, 50, E8, B9, EA, FF, FF, 8D, 85, D8, FC, FF, FF, 89, 85, 28, FD, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, 2C, FD, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89...
 
[+]

Code size:
723.5 KB (740,864 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SearchSettings

Command:
"C:\Program Files\common files\spigot\search settings\searchsettings.exe"


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 14.d7.24ae.ip4.static.sl-reverse.com  (174.36.215.20:80)

Remove SearchSettings.exe - Powered by Reason Core Security