gozone_isync.exe

Virgin HealthMiles

Virgin HealthMiles

This is installed with GoZone iSync. The file has been seen being downloaded from www.virginhealthmiles.com and multiple other hosts.
Publisher:
Virgin HealthMiles Inc.  (signed by Virgin HealthMiles)

Product:
Virgin HealthMiles

Description:
Virgin iSync

Version:
2, 0, 1

MD5:
71b0539711f25c5a9fcc50c7290a003f

SHA-1:
21f5da06eb0d753bfac59f8a1cca83b7a3a9bb08

SHA-256:
bff6b47d820c0dbbbcfb9ae437d43f46398bd70232df668effbad0e87e8552e6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:07:22 AM UTC  (today)

File size:
426.6 KB (436,848 bytes)

Product version:
2, 0, 1

Copyright:
(c) 2012 Virgin HealthMiles Inc. All rights reserved.

Trademarks:
Virgin HealthMiles

Original file name:
iSync.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\gozone\gozone_isync.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/5/2012 7:00:00 PM

Valid to:
3/2/2014 6:59:59 PM

Subject:
CN=Virgin HealthMiles, OU=IT, O=Virgin HealthMiles, L=Framingham, S=Massachusetts, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2E4DE9F956322865ED5E9D1E4FE1B103

File PE Metadata
Compilation timestamp:
2/7/2013 11:33:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:lftmaymDpeJzbF/s88iOHgKlDzpu3KiStZbNw3dVGLvATB/tOcl9s1Y9+C3EC:lfgayAeJ9/vq1xZCVyAThtOcXhUC

Entry address:
0x2EA0B

Entry point:
E8, E7, DB, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, 56, 33, F6, 3B, C6, 75, 1C, E8, 11, 03, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, 64, A9, FF, FF, 83, C4, 14, 33, C0, 5E, C3, 8B, 40, 0C, 83, E0, 20, 5E, C3, 55, 8B, EC, 83, EC, 10, 8B, 4D, 08, 53, 8B, 5D, 0C, 56, 57, 33, FF, 39, 7D, 10, 89, 4D, F8, 89, 5D, FC, 74, 21, 39, 7D, 14, 74, 1C, 3B, CF, 75, 1F, E8, C8, 02, 00, 00, 57, 57, 57, 57, C7, 00, 16, 00, 00, 00, 57, E8, 1B, A9, FF, FF, 83, C4, 14, 33, C0, 5F, 5E, 5B, C9, C3, 8B, 75, 18...
 
[+]

Entropy:
6.5656

Code size:
284 KB (290,816 bytes)

User Start Menu Item
Name:
gozone_isync.exe


The file gozone_isync.exe has been discovered within the following program.

GoZone iSync  by Virgin HealthMiles
Publisher's description - “If you remove the GoZone software from your computer, you will not be able to upload your steps from your GoZone. The GoZone software will prompt you to complete a GoZone registration form.”
www.virginhealthmiles.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file gozone_isync.exe has been seen being distributed by the following 19 URLs.

https://www.virginhealthmiles.com/.../GoZone_iSync.aspx?spid=1049788

https://www.virginhealthmiles.com/.../GoZone_iSync.aspx?spid=1383480

https://www.virginhealthmiles.com/.../GoZone_iSync.aspx?spid=1392642

Scan gozone_isync.exe - Powered by Reason Core Security