wandoujia_installer.exe

Wandou Technology Ltd

This is installed with SnapPea.
Publisher:
Wandou Technology Ltd  (signed and verified)

MD5:
dbfbf52f411166d6f3ab7dc24b0b81b4

SHA-1:
c56001c82a320acc9519b194dff3973c23ccebcc

SHA-256:
f5d79becad64468e135be195b34d90635c3f00614258d1426f3fd13694688fbd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:27:12 PM UTC  (today)

File size:
1.9 MB (1,970,632 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\wandoulabs\wandoujia_installer.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/25/2011 5:30:00 AM

Valid to:
4/25/2013 5:29:59 AM

Subject:
CN=Wandou Technology Ltd, OU=Wandou Technology Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wandou Technology Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
76015B1273AEA325800AA3D536CCB13D

File PE Metadata
Compilation timestamp:
8/15/2012 1:43:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:d/SlDYBN+nVinMEZrOHCeHl0ZEQ0kf2IiQqsUuyZOja7QHBGajsNJAK2TMrL75wf:c1OxNzWP7WB3uWK2TCymaV9uP

Entry address:
0xC37E2

Entry point:
E8, 41, 04, 00, 00, E9, 37, FD, FF, FF, 6A, 14, 68, 70, E9, 58, 00, E8, 6C, 01, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, 86, 04, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 62, 01, 00, 00, C2, 10, 00, 6A, 0C, 68, 90, E9, 58, 00, E8, 0E, 01, 00, 00, 83, 65, E4, 00, 8B, 75, 0C, 8B, C6, 0F, AF, 45...
 
[+]

Entropy:
6.5637

Code size:
1.4 MB (1,437,184 bytes)

The file wandoujia_installer.exe has been discovered within the following program.

SnapPea  by Wandou Labs
The software currently distributes the app through the OpenCandy monetization platform which is known to distribute adware.
snappea.com
25% remove it
 
Powered by Should I Remove It?

Scan wandoujia_installer.exe - Powered by Reason Core Security