System.Data.SQLite.dll

System.Data.SQLite

First Offer LTD

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. System.Data.SQLite.dll is the .NET interop wrapper for the native SQLite library to connect to and manage a SQLite database and is recompiled by First Offer LTD. The library System.Data.SQLite.dll, “System.Data.SQLite Core” by First Offer has been known to be a potentially unwanted program that has been detected by 2 anti-malware scanners.
Publisher:
http://system.data.sqlite.org/  (signed by First Offer LTD)

Product:
System.Data.SQLite

Description:
System.Data.SQLite Core

Version:
1.0.93.0

MD5:
a0ab64d44ec88de1576c3e894af2c009

SHA-1:
78adc86f71267a59ea0a63720c625ae59f5ed5fa

SHA-256:
7215c0b7a539d43ae5676fa2d95df08d4eaea52ea230629a4fa21e53371a630d

Scanner detections:
2 / 68

Status:
Inconclusive but possibly unwanted  (It is part of a common redistributable library)

Analysis date:
5/10/2024 1:02:11 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:InstalleRex-BF [PUP]
150602-1

Reason Heuristics
Common.PUP.FirstOffer.Q
14.11.1.8

File size:
282.1 KB (288,840 bytes)

Product version:
1.0.93.0

Copyright:
Public Domain

Original file name:
System.Data.SQLite.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Swedish (Sweden)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\system.data.sqlite.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/8/2013 2:00:00 AM

Valid to:
10/9/2014 1:59:59 AM

Subject:
CN=First Offer LTD, O=First Offer LTD, STREET=Habarzel 21 Tel Aviv, L=Tel aviv, S=Israel, PostalCode=69710, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
49900242461D96CB7B045BE0A258338E

File PE Metadata
Compilation timestamp:
6/23/2014 6:56:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:5JJD5G5D6hkLL9BGC5tDOkYvP3oKYY31fDuyTn2IWBzG6IKmtbBp0Z621oKQMi0e:DJD5G5D6hkLL9BGC5tDOkYvP3oKYY31N

Entry address:
0x438CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
264 KB (270,336 bytes)

Scan System.Data.SQLite.dll - Powered by Reason Core Security