wandoujia_shlext.dll

TODO:

Wandou Technology Ltd

This is installed with SnapPea.
Publisher:
TODO: <Company name>  (signed by Wandou Technology Ltd)

Product:
TODO: <Product name>

Description:
TODO: <File description>

Version:
1.0.0.1

MD5:
18d545724706a9636521a94429c1490e

SHA-1:
eab20a0817bcf7649398a0e5910c77580d4bd97d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:17:44 AM UTC  (today)

File size:
46.4 KB (47,488 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
wandoujia_shlext.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\wandoulabs\wandoujia_shlext.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/25/2011 7:00:00 AM

Valid to:
4/25/2013 6:59:59 AM

Subject:
CN=Wandou Technology Ltd, OU=Wandou Technology Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wandou Technology Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
76015B1273AEA325800AA3D536CCB13D

File PE Metadata
Compilation timestamp:
4/1/2013 11:27:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:VxwVsKPCTUL0xLI6cP5K+kn91gSybN4nOy1+lO1zINAQxovQNb:VxfrLI6YU196Sybut+lO1zQAQxwQJ

Entry address:
0x5813

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 53, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, 68, 42, 52, 00, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, C4, A3, 00, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, FF...
 
[+]

Entropy:
6.3033

Code size:
20.5 KB (20,992 bytes)

The file wandoujia_shlext.dll has been discovered within the following program.

SnapPea  by Wandou Labs
The software currently distributes the app through the OpenCandy monetization platform which is known to distribute adware.
snappea.com
25% remove it
 
Powered by Should I Remove It?

Scan wandoujia_shlext.dll - Powered by Reason Core Security