WidgiHelper.exe

Widgi Toolbar

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application WidgiHelper.exe, “WidgiHelper Application” by Spigot has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer.
Publisher:
Spigot, Inc.  (signed and verified)

Product:
Widgi Toolbar

Description:
WidgiHelper Application

Version:
4, 4, 0, 1

MD5:
77f87d68843413f2d649ec337bce89da

SHA-1:
7debf2381a233f49cc3cdfb77c6b9d96fa9ef680

SHA-256:
129a63a332091d7eb30c24d8cf85765e372fd5724c05ec1d48aebe590b699581

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
5/7/2024 3:43:57 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Softomat.AN
7.11.30.172

Dr.Web
Trojan.Damaged.1
9.0.1.016

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.Widgi.AMN
8.16.01.16.04

ESET NOD32
Win32/Toolbar.Widgi
10.9882

Malwarebytes
PUP.Optional.Spigot.A
v2016.01.16.04

Reason Heuristics
PUP.Spigot.Installer (M)
16.1.16.4

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9383

Trend Micro House Call
ADW_TOOLBAR
7.2.16

Trend Micro
ADW_TOOLBAR
10.465.16

File size:
67.3 KB (68,960 bytes)

Product version:
4, 4, 0, 1

Copyright:
Copyright © 2005-2011 Spigot, Inc.

Original file name:
WidgiHelper.exe

File type:
Executable application (Win32 EXE)

Installer:
Spigot Setup

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/28/2011 9:00:00 PM

Valid to:
3/28/2012 8:59:59 PM

Subject:
CN="Spigot, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spigot, Inc.", L=El Granada, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
205AA0CBA0AA4891C4AF524CA2EE072C

File PE Metadata
Compilation timestamp:
4/27/2011 6:53:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:ddSWuq4/2ANwfwOeuHCdZU9qZU9qhL6S2:dUqjDYOVHCdpJhOF

Entry address:
0x2147

Entry point:
E8, 4C, 05, 00, 00, E9, 37, FD, FF, FF, 6A, 14, 68, 80, 33, 40, 00, E8, BF, 00, 00, 00, FF, 35, 28, 44, 40, 00, 8B, 35, 98, 30, 40, 00, FF, D6, 59, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 94, 30, 40, 00, 59, EB, 67, 6A, 08, E8, B3, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, 28, 44, 40, 00, FF, D6, 89, 45, E4, FF, 35, 24, 44, 40, 00, FF, D6, 59, 59, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35, 0C, 31, 40, 00, FF, D6, 59, 50, E8, 76, 05, 00, 00, 89, 45, DC, FF, 75, E4, FF, D6, A3...
 
[+]

Code size:
6.5 KB (6,656 bytes)

Remove WidgiHelper.exe - Powered by Reason Core Security