Information about sqlite3.dll

sqlite3.dll

sqlite3.dll is a Windows file recorded in the ThreatInfo database. It is associated with SQLite. The reported company name is SQLite Development Team. The current detection status is Undefined, based on the latest analysis from 2021-01-15 11:53:25 (5 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: SQLite
Company Name: SQLite Development Team
MD5: 2bdb09ac06a97f1da25adb8bc5bc7b9a
Size: 658 KB
First Published: 2017-05-22 11:17:42 (8 years ago)
Latest Published: 2021-01-15 11:53:25 (5 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2021-01-15 11:53:25 (5 years ago)
Signed By: Auslogics Labs Pty Ltd
Status: Valid

The signature on sqlite3.dll is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%\auslogics\driver updater
%programfiles%\auslogics\driver updater\app\driverupdater
%programfiles%\auslogics
%programfiles%\auslogics\driver updater\app
%sysdrive%\portable soft windows 10\driverupdater-1.9.4.0\portable driver updater\app
%sysdrive%\download\auslogics driver updater v1.9.4 repack+portable by dodakaedr\auslogics driver updater v1.9.4 portable\app
%profile%\downloads\auslogics driver updater v1.9.4.0 repack+portable by dodakaedr\auslogics driver updater v1.9.4 portable\app
%programfiles%\utorrent\downloads\auslogics driver updater v1.9.4.0 repack+portable by dodakaedr\auslogics driver updater v1.9.4 portable\app
%programfiles%
%sysdrive%

ThreatInfo has observed sqlite3.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

35.4%
11.8%
9.6%
3.4%
2.8%
2.8%
2.8%
2.2%
2.2%
2.2%
1.7%
1.7%
1.7%
1.7%
1.7%
1.7%
1.7%
1.1%
1.1%
1.1%
1.1%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%

The strongest geographic signal for this file is Russian Federation with 35.4% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 64.8%
Windows 7 25.7%
Windows 8.1 8.4%
Windows XP 1.1%

The most common operating system signal for sqlite3.dll is Windows 10 with 64.8% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

sqlite3.dll is identified as pe for 32 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x61c00000
Entry Address: 0x00001058

PE Sections:

Name Size of data MD5
.text 456704 bedbda29fdf46d18b2269113689a8867
.data 4096 232e7d27742abb403dcfb108a95e9992
.rdata 48128 8ed3cbb12ca1baa8bc8bb84b8fcde91f
.bss 0 00000000000000000000000000000000
.edata 7168 407233d76c5d807a9c4d7343849a47ff
.idata 3072 ae8af166fc19d929e13d22f166792e44
.CRT 512 b98685e75fd3764099a2f9a2b0f9b6b9
.tls 512 45cc7ebbfe165ef1980b9fccde17a0f1
.rsrc 1536 4227f6824c37d100a6b3b246b7670bd7
.reloc 10240 6f66609b316e6e147ecf0f5afc6ceb2f
/4 512 ff1e81f37a2a45eb8b0d229fc3658824
/19 1024 011ac81319e8d4a8a17886fed659576c
/35 2048 b675590ee7158a8e32bf18ce78fa9343
/51 17408 ef36cd5ac7bf6698ebb261088cae5222
/63 3584 7b8b671d1139883ee08bf4575c139022
/77 3072 2aa7d63d8fb58370df4f434db08602b0
/89 1536 f1f46cd55b653423d6bd109a102d7775
/102 512 14f8eb767d485e23c1afdee4dcb14cef
/113 6656 0047139b3c4e22dbf6a6b509ee8d1dc4
/124 512 60ad4279e64e3057e9da309bc9e4a413

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: