wandoujia2.exe

Wandou Technology Ltd

This is installed with SnapPea.
Publisher:
Wandou Technology Ltd  (signed and verified)

MD5:
a5a5c07ad8a687422e532b5d265d93f7

SHA-1:
47bb7068b891c1b01a5f601ec71d9bf463d4f645

SHA-256:
7977ba93a28cb63fb633e761750ff97c83ee0b2fbe33207341b11adc099e9d5d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:59:05 PM UTC  (today)

File size:
104.9 KB (107,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\wandoulabs\wandoujia2.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/25/2011 5:30:00 AM

Valid to:
4/25/2013 5:29:59 AM

Subject:
CN=Wandou Technology Ltd, OU=Wandou Technology Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wandou Technology Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
76015B1273AEA325800AA3D536CCB13D

File PE Metadata
Compilation timestamp:
8/15/2012 1:41:08 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:eLwkObFKS9BicAYj7BQGOTfdySHcgqgDgP2Tn1hncQDygMAyyjrhrEAhMrQ3nCmQ:WwlKaMc7SGofcSHc1gDgP2Tz5rEA6Q

Entry address:
0x1C5C

Entry point:
E8, 77, 03, 00, 00, E9, 37, FD, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, CC, 03, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 66, 1C, 40, 00, FF, 15, 38, 30, 40, 00, 33, C0, C3, FF, 25, BC, 30, 40, 00, 6A, 14, 68, E0, 33, 40, 00, E8, 64, 02, 00, 00, FF, 35, 84, 53, 40, 00, 8B, 35, 9C, 30, 40, 00, FF, D6, 59, 89, 45, E4, 83, F8...
 
[+]

Entropy:
7.6525

Code size:
5 KB (5,120 bytes)

The file wandoujia2.exe has been discovered within the following program.

SnapPea  by Wandou Labs
The software currently distributes the app through the OpenCandy monetization platform which is known to distribute adware.
snappea.com
25% remove it
 
Powered by Should I Remove It?

Scan wandoujia2.exe - Powered by Reason Core Security