ProgramManager.exe

Program Manager

GMGP, LLC

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application ProgramManager.exe by GMGP has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer. It runs as a scheduled task under the Windows Task Scheduler triggered to automatically run when the computer boots.
Publisher:
Spigot, Inc.  (signed by GMGP, LLC)

Product:
Program Manager

Version:
21, 4, 0, 2

MD5:
f0aed9eaea4b22c92277f1aec13bf5a1

SHA-1:
077d3f65227ece2a45798fa3d3235f6bbac82755

SHA-256:
be4d452faee53f006a5e9fed1a83f634ced0a5483bf223b4594f934b2ab5916a

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
5/2/2024 6:26:58 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Spigot.Gen
8.3.1.6

Dr.Web
DLOADER.Trojan
9.0.1.0149

ESET NOD32
Win32/Toolbar.Widgi.G potentially unwanted (variant)
9.11701

Reason Heuristics
PUP.Task.Spigot
15.5.29.20

File size:
930.6 KB (952,984 bytes)

Product version:
21, 4, 0, 2

Copyright:
Copyright © 2005-2015 Spigot, Inc.

Original file name:
ProgramManager.exe

File type:
Executable application (Win32 EXE)

Installer:
Spigot Setup

Language:
Engleski (Sjedinjene Države)

Common path:
C:\Program Files\common files\programmanager\programmanager.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/23/2014 8:24:09 PM

Valid to:
12/23/2017 8:24:09 PM

Subject:
CN="GMGP, LLC", O="GMGP, LLC", L=INCLINE VILLAGE, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00C74D94A2E778

File PE Metadata
Compilation timestamp:
5/28/2015 9:01:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:q/vuJJDShQ4pe+97FJTLHLiBtsAPjR5UNKyghnwO+u/JKsNS9YVU0eALA:KuJJOhTpr/JTLH0sMR5TyghnwO+u/JKr

Entry address:
0x86BB3

Entry point:
E8, 1C, 84, 00, 00, E9, A5, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 00, 0F, 00, 00, 3B, 0D, 30, 11, 4D, 00, 75, 02, F3, C3, E9, 93, 84, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 9A, 63, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 6D, 0E, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 1F, 5B, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 9E, 36, 00, 00, 83...
 
[+]

Code size:
694.5 KB (711,168 bytes)

Scheduled Task
Task name:
Program Manager

Trigger:
Boot (Runs on boot)


Remove ProgramManager.exe - Powered by Reason Core Security