settingsmanager.exe

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application settingsmanager.exe by Spigot has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Settings Manager’.
Publisher:
Spigot, Inc.  (signed and verified)

Description:
Settings Manager

Version:
24,4,0,6

MD5:
1198f1be7e80658bc3079c73e7f70327

SHA-1:
61d8fb37ad9718b380d89de9038e8c17bb10fcf5

SHA-256:
7ac2d26ec7d91acc01b6d1e10f4af837c312150c4b5796ef37fb9213b4f3e7c6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 6:33:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Spigot (M)
16.8.2.19

File size:
965.7 KB (988,912 bytes)

Product version:
24,4,0,6

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\settings manager\settingsmanager.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
1/27/2016 3:36:38 PM

Valid to:
1/16/2017 7:16:38 AM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Village, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07322820879EF483

File PE Metadata
Compilation timestamp:
3/9/2016 7:45:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:oMID8fd2uR57EXK9jJNQnU5W1MN52YySqHv:oMFfY07EXKNJNL5W1MT2YySqHv

Entry address:
0x904CD

Entry point:
E8, CD, 8A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 56, 8D, 45, FC, 50, FF, 75, 0C, FF, 75, 08, E8, 44, 8B, 00, 00, 8B, F0, 83, C4, 0C, 85, F6, 75, 18, 39, 45, FC, 74, 13, E8, 5D, 31, 00, 00, 85, C0, 74, 0A, E8, 54, 31, 00, 00, 8B, 4D, FC, 89, 08, 8B, C6, 5E, C9, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7, C2, 03, 00...
 
[+]

Entropy:
6.6124

Code size:
720.5 KB (737,792 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Settings Manager

Command:
"C:\users\{user}\appdata\roaming\settings manager\settingsmanager.exe" \autostart \restart


Remove settingsmanager.exe - Powered by Reason Core Security