wdj_tool.exe

Wandou Technology Ltd

This is installed with SnapPea.
Publisher:
Wandou Technology Ltd  (signed and verified)

MD5:
6261bef46c17cb0c6f966995e5b6a529

SHA-1:
dc025f462f608baec9c60c2be29e5a6f94183623

SHA-256:
60fc40cd04ceb1da03cf1da9761f5dc1c558b789943c0a977c23e075dfe569a5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 7:34:07 PM UTC  (today)

File size:
17.9 KB (18,376 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\wandoulabs\wdj_tool.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/25/2011 5:30:00 AM

Valid to:
4/25/2013 5:29:59 AM

Subject:
CN=Wandou Technology Ltd, OU=Wandou Technology Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wandou Technology Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
76015B1273AEA325800AA3D536CCB13D

File PE Metadata
Compilation timestamp:
8/15/2012 1:42:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
192:fqyLBJl1LPO+S+0qV2z8N0VOOJJ/16pYs/v5335/wJirNmL/krhFE+vCJr9ZCspB:iqB7Z0JjW3mirILKF+8eMl

Entry address:
0x1A00

Entry point:
E8, D3, 02, 00, 00, E9, 9F, FD, FF, FF, FF, 25, C0, 30, 40, 00, FF, 25, 58, 30, 40, 00, FF, 25, 60, 30, 40, 00, 68, 75, 1A, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 10, 40, 40, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10...
 
[+]

Entropy:
6.4696

Code size:
4.5 KB (4,608 bytes)

The file wdj_tool.exe has been discovered within the following program.

SnapPea  by Wandou Labs
The software currently distributes the app through the OpenCandy monetization platform which is known to distribute adware.
snappea.com
25% remove it
 
Powered by Should I Remove It?

Scan wdj_tool.exe - Powered by Reason Core Security