settingsmanager.exe

Spigot, Inc.

This component is part of the Spigot browser add-on, a web browser addition that is designed to modify the core search provider in order to redirect search queries through partner portals. The application settingsmanager.exe by Spigot has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Settings Manager’.
Publisher:
Spigot, Inc.  (signed and verified)

Description:
Settings Manager

Version:
24,4,0,6

MD5:
6f798bbfd755743c6c579afec0efafb6

SHA-1:
ff538f1546fb4b4c1b102b606ad0267693f7e4a8

SHA-256:
6f650338714bcb203fffb43378ae15df1b7695d7c667f14c516ab363ca1259c0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 2:44:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Spigot (M)
16.5.2.10

File size:
965.7 KB (988,912 bytes)

Product version:
24,4,0,6

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\settings manager\settingsmanager.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
1/27/2016 3:36:38 PM

Valid to:
1/16/2017 7:16:38 AM

Subject:
CN="Spigot, Inc.", O="Spigot, Inc.", L=Incline Village, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07322820879EF483

File PE Metadata
Compilation timestamp:
3/9/2016 7:45:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ZMID8fd2uR57EXK9jJNQnU5W1MN52YySqHv:ZMFfY07EXKNJNL5W1MT2YySqHv

Entry address:
0x904CD

Entry point:
E8, CD, 8A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 56, 8D, 45, FC, 50, FF, 75, 0C, FF, 75, 08, E8, 44, 8B, 00, 00, 8B, F0, 83, C4, 0C, 85, F6, 75, 18, 39, 45, FC, 74, 13, E8, 5D, 31, 00, 00, 85, C0, 74, 0A, E8, 54, 31, 00, 00, 8B, 4D, FC, 89, 08, 8B, C6, 5E, C9, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7, C2, 03, 00...
 
[+]

Entropy:
6.6125

Code size:
720.5 KB (737,792 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Settings Manager

Command:
"C:\users\{user}\appdata\roaming\settings manager\settingsmanager.exe" \autostart \restart


Remove settingsmanager.exe - Powered by Reason Core Security