WidgiHelper.exe

Widgi Toolbar

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application WidgiHelper.exe, “WidgiHelper Application” by Spigot has been detected as adware by 9 anti-malware scanners.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
Widgi Toolbar

Description:
WidgiHelper Application

Version:
4, 8, 0, 2

MD5:
10c1f44022695b018cf6bd8a2da2da71

SHA-1:
2faa1e6c56fd0e0574ab2d78e3809af819ac87fc

SHA-256:
dc7c716f405cd0be158ee582b70369266c03926cb23342aed542ea622fa08377

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
5/10/2024 6:50:15 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.30.172

Dr.Web
Trojan.Damaged.1
9.0.1.037

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Widgi.AMN
8.16.02.06.12

ESET NOD32
Win32/Toolbar.Widgi
10.9882

Malwarebytes
PUP.Optional.Spigot.A
v2016.02.06.12

Reason Heuristics
PUP.Spigot.Toolbar (M)
16.2.6.12

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9340

Trend Micro House Call
ADW_TOOLBAR
7.2.37

Trend Micro
ADW_TOOLBAR
10.465.06

File size:
67.3 KB (68,960 bytes)

Product version:
4, 8, 0, 2

Copyright:
Copyright © 2005-2011 Spigot, Inc.

Original file name:
WidgiHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\youtube downloader toolbar\widgihelper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/29/2011 5:30:00 AM

Valid to:
3/29/2012 5:29:59 AM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
205AA0CBA0AA4891C4AF524CA2EE072C

File PE Metadata
Compilation timestamp:
11/15/2011 5:54:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
384:qsK3mU/nut8uq4eoZfTiqwcwiCIFwOUVuHnCt1xq3UZU9w1xq3UZU92p88aLYJLB:qdSWuq4/2qN/fwOeuHCdZU9qZU9DkL62

Entry address:
0x2147

Entry point:
E8, 4C, 05, 00, 00, E9, 37, FD, FF, FF, 6A, 14, 68, 80, 33, 40, 00, E8, BF, 00, 00, 00, FF, 35, 28, 44, 40, 00, 8B, 35, 98, 30, 40, 00, FF, D6, 59, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 94, 30, 40, 00, 59, EB, 67, 6A, 08, E8, B3, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, 28, 44, 40, 00, FF, D6, 89, 45, E4, FF, 35, 24, 44, 40, 00, FF, D6, 59, 59, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35, 0C, 31, 40, 00, FF, D6, 59, 50, E8, 76, 05, 00, 00, 89, 45, DC, FF, 75, E4, FF, D6, A3...
 
[+]

Entropy:
5.2041

Code size:
6.5 KB (6,656 bytes)

Remove WidgiHelper.exe - Powered by Reason Core Security