nsispluginw.dll

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The module nsispluginw.dll by Spigot has been detected as adware by 10 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Spigot, Inc.  (signed and verified)

Version:
2,5,0,1

MD5:
d9ad5abd2acd94b9a17e61dfebf5711c

SHA-1:
a778543ed64b68e2404be67252abcd1781e3265b

SHA-256:
62b1828293cd2202c43ca409ab00f02381f4b354ee15a87530f5cabe3a289f0f

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
5/26/2024 12:53:08 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160327-1

Dr.Web
Adware.Spigot.114, Win32.FloodFix.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Floxif
11.5.0.6191

ESET NOD32
Win32/Floxif.H virus
8.0.319.0

F-Prot
W32/Floxif.B
4.6.5.141

Kaspersky
Virus.Win32.Pioneer
15.0.0.562

McAfee
Trojan.Dropper-FIY!D9AD5ABD2ACD
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.1716.0

Norman
Win32.Floxif.A
02.04.2016 17:35:19

Reason Heuristics
PUP.Spigot (M)
16.5.14.12

File size:
604.5 KB (618,975 bytes)

Product version:
2,5,0,1

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nsispluginw.dll

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/2/2016 12:00:00 AM

Valid to:
1/26/2017 11:59:59 PM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Village, S=Nevada, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
221614C10303CE3BC337E773011A5C2B

File PE Metadata
Compilation timestamp:
4/25/2016 11:55:11 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:TnJxbJLubIaeEe7VnU14bLM4CH3rYa+2mxKQ4AK8opc/XBjvrEH7O:3vR84b/7xZxK8R/1rEH7O

Entry address:
0x48A31

Entry point:
E9, BF, EE, 00, 00, 83, 7D, 0C, 01, 75, 05, E8, 3F, 3B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 56, 0E, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 6D, 03, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 31, 0E, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, 78, 3B, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3...
 
[+]

Entropy:
6.3373

Packer / compiler:
Xtreme-Protector v1.05

Code size:
355 KB (363,520 bytes)

Remove nsispluginw.dll - Powered by Reason Core Security