myvirtualhomesetup.exe

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application myvirtualhomesetup.exe by Spigot has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Spigot Setup installer. While running, it connects to the Internet address www.reporting-download.com on port 80 using the HTTP protocol.
Publisher:
Spigot, Inc.  (signed and verified)

MD5:
6eeecc05e94aace48dca281b21cb67fb

SHA-1:
72eb1036acc7a45b2f2a8754f6301a0f83e10b13

SHA-256:
2f3effe340525109a3e47dee88ab7bb312676e1862bd5cc3455055f7dc7b4545

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
12/23/2024 10:38:32 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/WinWrapper.Gen
8.3.1.6

avast!
Adware-RW [PUP]
150602-1

AVG
Generic
2016.0.3090

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Genome-10383
0.98/20543

Dr.Web
Trojan.DownLoader12.18011
9.0.1.05190

ESET NOD32
Win32/Spigot.A potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.Spigot.SID
v2015.06.03.01

NANO AntiVirus
Trojan.Nsis.Downloader.dnpqiz
0.30.24.1636

Reason Heuristics
PUP.Spigot.Installer
15.6.3.1

VIPRE Antivirus
Threat.4150696
40786

Zillya! Antivirus
Downloader.Genome.Win32.53003
2.0.0.2202

File size:
225.3 KB (230,744 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Spigot Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\myvirtualhomesetup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/1/2014 6:00:00 PM

Valid to:
11/30/2015 6:00:00 AM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Village, S=Nevada, C=US, PostalCode=89451, STREET="774 Mays Blvd. #10-456", SERIALNUMBER=E0212222011-9, OID.1.3.6.1.4.1.311.60.2.1.2=Nevada, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B1416CEF5FC0B6BC571376D2D93F5C4

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:YQIURTXJqIHVY2BNjcjcLJ2C4Qr5iQVuTJdD29vogm:YsVVYe3dvP5i1b29vogm

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.0407

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to www.reporting-download.com  (174.37.241.116:80)

Remove myvirtualhomesetup.exe - Powered by Reason Core Security