nsispluginw.dll

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The module nsispluginw.dll by Spigot has been detected as adware by 10 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Spigot, Inc.  (signed and verified)

Version:
2,5,0,1

MD5:
f10246a260483f712094e6150c78f0cd

SHA-1:
b93b42ea5b0fd403da6901e87edb6efdafabe628

SHA-256:
483e3dc9ee61e9e2b9ac189e49b9982d6866b574c8be993cd186403684c9d9f7

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
12/29/2024 8:28:10 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160414-2

AVG
Win32/Floxif.A
2015.0.4568

Dr.Web
Adware.Spigot.114, Win32.FloodFix.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Floxif
9.0.0.4157

ESET NOD32
Win32/Floxif.H virus
8.0.319.0

F-Prot
W32/Floxif.B
4.6.5.141

McAfee
Trojan.Dropper-FIY!F10246A26048
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.555.0

Norman
Win32.Floxif.A
28.05.2016 15:32:18

Reason Heuristics
PUP.Spigot (M)
16.6.3.18

File size:
604.5 KB (618,975 bytes)

Product version:
2,5,0,1

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nsispluginw.dll

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/2/2016 12:00:00 AM

Valid to:
1/26/2017 11:59:59 PM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Village, S=Nevada, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
221614C10303CE3BC337E773011A5C2B

File PE Metadata
Compilation timestamp:
4/24/2016 11:55:11 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:TnJxbJLubIaC9e7VnU14bLM4CH3rYa+DmxKQPgK8opc/XBjvrEH7D:3YR84b/SxZPgK8R/1rEH7D

Entry address:
0x48A31

Entry point:
E9, 88, 4A, FD, FF, 83, 7D, 0C, 01, 75, 05, E8, 3F, 3B, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 56, 0E, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 6D, 03, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 31, 0E, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, 78, 3B, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3...
 
[+]

Entropy:
6.3433

Packer / compiler:
Xtreme-Protector v1.05

Code size:
355 KB (363,520 bytes)

Remove nsispluginw.dll - Powered by Reason Core Security