First Offer LTD

Publisher Information

First Offer LTD is a brand of publishers/developers run by WebPick Internet Holdings Ltd. located in Ramat Ha'Chayal Tel Aviv, Israel. The company is a primary distributor of unwanted software. First Offer LTD is a developer of WebPick Internet Holdings and publishes a number of adware web browser plugins designed to monitor web browser behavior and inject advertisements (banner, popups, text-links, etc.) in the browser by using the WebPick InstalleRex monetization delivery platform. These programs from First Offer LTD are typiclaly installed on a variety of names and misspellings and are very difficult to remove. According to WebPick, they use developers to sign their adware in order to "throw off competitors". There is one additional code signing certificate issued to this publisher.
Remove First Offer LTD Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
10/8/2013 2:00:00 AM

Valid to:
10/9/2014 1:59:59 AM

Subject:
CN=First Offer LTD, O=First Offer LTD, STREET=Habarzel 21 Tel Aviv, L=Tel aviv, S=Israel, PostalCode=69710, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
49900242461d96cb7b045be0a258338e

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.K, Adware.WebPick.Installer.J, PUP.Task.FirstOffer.W, PUP.Task.FirstOffer.O, PUP.BHO.FirstOffer.N, PUP.Toolbar.FirstOffer.I, PUP.FirstOffer.N, PUP.FirstOffer.I, PUP.ResignedInterop.FirstOffer.Z, Common.PUP.FirstOffer.BB, PUP.FirstOffer.O, PUP.FirstOffer.U, PUP.FirstOffer.J, PUP.Toolbar.FirstOffer.Q, PUP.Installer.FirstOffer.N, Common.PUP.FirstOffer.N, Common.PUP.FirstOffer.Q, PUP.FirstOffer.L, PUP.WebPick.FirstOffer.Bundler (M), Common.PartOf.PUP.WebPick.FirstOffer (M)
98.00%

avast!
Win32:InstalleRex-BF [PUP], Win32:InstalleRex-AE [PUP], Win32:Installer-AP [PUP]
88.00%

AVG
MalSign.Generic, MalSign.Skodna.Pick, Onefloorap
80.00%

Dr.Web
Adware.Downware.2108, Adware.Plugin.364, Trojan.WebPick.7388
28.00%

Avira AntiVirus
Adware/InstallRex.V, TR/Trash.Gen, APPL/Downloader.Gen4
14.00%

herdProtect (fuzzy)
a variant of 1d2d3c2b82581af6772c2e48f31cc0830d8e00f5, a variant of 170e2669b8ff00e3c3d93ef2180843d429444b89, a variant of 625738d77ddd2bbed526e40acdd525f5c509139f
10.00%

Panda Antivirus
PUP/TSUploader
10.00%

Sophos
InstallRex
8.00%

Comodo Security
Application.Win32.InstalleRex.KG
8.00%

ESET NOD32
Win32/InstalleRex
8.00%

8 / 68      (Adware)
InstallHelper.dll (ToolbarInnoSetupHelper)  (94eebe6ec52a748fcfcb08841addc603)

1 / 68      (Adware)
cinshlpr.dll (Widdit by One Floor App)  (a07d672bf1be0aa314fd43831a05f43c)

1 / 68      (inconclusive)

1 / 68      (inconclusive)

1 / 68      (Adware)
tbua93b.exe (PriceCongress by SimplyTech)  (3e54d400925526d15afe9db13b532a3c)

6 / 68      (Adware)
wconnectorproductivity.exe (AsyncSystemSockets)  (59f44b3136068e3afc7e842d8d47417e)

4 / 68      (Adware)
wbrowserupdate.exe (TBUpdater)  (ec41f0b6eac093bce50b544d3b0efb10)

3 / 68      (Adware)
Launcher.exe (Toolbar_Exe_Launcher_Form)  (028272bdd16f90a7e0670abe8abef86a)

4 / 68      (Adware)
pricecongress_64.dll (Simply Tech LTD by Simply Tech)  (90c019c21939834bd89e4951c3e83349)

4 / 68      (Adware)
pricecongress.dll (Simply Tech LTD by Simply Tech)  (b86f22bc7f479aa613f213b87b7aaf7a)

4 / 68      (Adware)
TBUpdater.dll (Widdit by One Floor App)  (7d0ace77455c4680e7c2aae5d086f92b)

3 / 68      (Adware)

4 / 68      (Adware)
wdapimng_64.exe (Widdit by One Floor App)  (e5bfbbc0998bcabe827e791af5b843bc)

4 / 68      (Adware)
wdapimng.exe (Widdit by One Floor App)  (cb04806e24927740816f9ada6b4911a8)

6 / 68      (Adware)
unins000.exe  (747b1f38ea1ffab24123bca13aeaadc4)

3 / 68      (Adware)
ToolbarUninstall.exe (ToolbarUninstall)  (89c2941ff8ddd667abe5a00292bdb45b)

3 / 68      (Adware)

4 / 68      (Adware)
InstallHelper.dll (ToolbarInnoSetupHelper)  (dea44952068c0f582b4e98010cb55e20)

4 / 68      (Adware)
cinshlpr.dll (Widdit by One Floor App)  (136942c23b4314c49edc1c0ba729eaad)

2 / 68      (inconclusive)

3 / 68      (Adware)

3 / 68      (Adware)

2 / 68      (Adware)

7 / 68      (Adware)
offer0.exe (PriceCongress by SimplyTech)  (a68a9b41d4c872cc1a372d192dcf01b8)

3 / 68      (Adware)
wpackageupdate.exe (TBUpdater)  (8a9547f7246c6cf88e4af8047ee1f2e2)

3 / 68      (Adware)
wconnectordirect.exe (AsyncSystemSockets)  (0addfeeedd776940cff227937a1e6ed0)

2 / 68      (inconclusive)

3 / 68      (Adware)

6 / 68      (Adware)
InstallHelper.dll (ToolbarInnoSetupHelper)  (5898fd194aa81790755c3b57501ea468)

4 / 68      (Adware)
cinshlpr.dll (Widdit by One Floor App)  (6c641f63de9358d3a0b57def4ff6391a)

 
Latest 30 of 50 files

Downloads URLs for files signed by First Offer LTD.

12 / 68    (Adware)

13 / 68    (Adware)

8 / 68      (Adware)

29 / 68    (Adware)
http://addoncommon.info/v1648  (firstoffer.exe)

2 / 68      (Adware)
http://firstoffertravel.com/1stOffer.exe  (349e2d8660c1a20f6542eacebc4643a5)

The following websites host and distribute files published by First Offer LTD.

The following certificate is also signed by First Offer LTD.

4A3C8068106AF46772F0E970DB0B000D  (Dec 03, 2014 to Dec 03, 2017)

The following publishers (by Authenticode signature organization name) are related.

Remove First Offer LTD Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to First Offer LTD by COMODO CA Limited on October 08, 2013 with the serial number '49900242461d96cb7b045be0a258338e'.