aapt.exe

Wandou Technology Ltd

This is installed with SnapPea.
Publisher:
Wandou Technology Ltd  (signed and verified)

MD5:
4dde37ffbc4ba034d17c768145f2987a

SHA-1:
c615c280e8cb999831b6b6df5becdcbfbc687906

SHA-256:
c87f24bb7ea2c15b48d7fa42a413a3006300dc0b455c5c898343f11e69e19263

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 9:38:23 PM UTC  (today)

File size:
810.9 KB (830,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\wandoulabs\aapt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/25/2011 5:30:00 AM

Valid to:
4/25/2013 5:29:59 AM

Subject:
CN=Wandou Technology Ltd, OU=Wandou Technology Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wandou Technology Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
76015B1273AEA325800AA3D536CCB13D

File PE Metadata
Compilation timestamp:
10/25/2011 3:13:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.56

CTPH (ssdeep):
24576:6GLjAYoLIX8KHm9K//SzAHDXi7hXtyTI39:hLEYZm9MHDwyT

Entry address:
0x1130

Entry point:
55, 89, E5, 83, EC, 14, 6A, 01, FF, 15, 54, C3, 4C, 00, E8, DD, FE, FF, FF, 8D, B6, 00, 00, 00, 00, 8D, BC, 27, 00, 00, 00, 00, 55, 89, E5, 53, 83, EC, 04, 8B, 45, 08, 8B, 00, 8B, 00, 3D, 91, 00, 00, C0, 77, 3B, 3D, 8D, 00, 00, C0, 72, 4B, BB, 01, 00, 00, 00, 50, 50, 6A, 00, 6A, 08, E8, 4C, E9, 08, 00, 83, C4, 10, 83, F8, 01, 0F, 84, D6, 00, 00, 00, 85, C0, 0F, 85, 90, 00, 00, 00, 31, C0, 8B, 5D, FC, C9, C2, 04, 00, 8D, B4, 26, 00, 00, 00, 00, 3D, 94, 00, 00, C0, 74, 49, 3D, 96, 00, 00, C0, 74, 17, 3D, 93...
 
[+]

Entropy:
6.5886

Packer / compiler:
Dev-C++ v5

Code size:
662 KB (677,888 bytes)

The file aapt.exe has been discovered within the following program.

SnapPea  by Wandou Labs
The software currently distributes the app through the OpenCandy monetization platform which is known to distribute adware.
snappea.com
25% remove it
 
Powered by Should I Remove It?

Scan aapt.exe - Powered by Reason Core Security