settingsmanager.exe

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application settingsmanager.exe by Spigot has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Settings Manager’.
Publisher:
Spigot, Inc.  (signed and verified)

Description:
Settings Manager

Version:
24,3,0,5

MD5:
61df7901f9814af0cf0e66d7bba7438d

SHA-1:
4cd3d4f5108bd99bf0ef4c2bdbb47f817d352762

SHA-256:
cec8df4911c5ea930b10eef88adf002088b0f7dff9250274296de5af96bf1fca

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 2:50:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Spigot (M)
16.6.29.18

File size:
796.2 KB (815,344 bytes)

Product version:
24,3,0,5

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\settings manager\settingsmanager.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
1/27/2016 3:36:38 PM

Valid to:
1/16/2017 7:16:38 AM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Village, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07322820879EF483

File PE Metadata
Compilation timestamp:
2/16/2016 10:54:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:rrImfXIm4gmqxQ/nrk7ALC3l246eu1Vb8zJ6z3hSiIodwv+L+0HwTs:rrIFm8qxIreA212d1eJw3hShcZHwTs

Entry address:
0x7AA1D

Entry point:
E8, D0, 8A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 56, 8D, 45, FC, 50, FF, 75, 0C, FF, 75, 08, E8, 47, 8B, 00, 00, 8B, F0, 83, C4, 0C, 85, F6, 75, 18, 39, 45, FC, 74, 13, E8, 5D, 31, 00, 00, 85, C0, 74, 0A, E8, 54, 31, 00, 00, 8B, 4D, FC, 89, 08, 8B, C6, 5E, C9, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7, C2, 03, 00...
 
[+]

Entropy:
6.6190

Code size:
612 KB (626,688 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Settings Manager

Command:
"C:\users\{user}\appdata\roaming\settings manager\settingsmanager.exe" \autostart \restart


Remove settingsmanager.exe - Powered by Reason Core Security