ZedgeTonesync.exe

ZedgeToneSync

Zedge Europe AS

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ZedgeTonesync’. This is installed with ZedgeTonesync.
Publisher:
Zedge.net  (signed by Zedge Europe AS)

Product:
ZedgeToneSync

Version:
1.0.42.117

MD5:
810297e22ee9da2ee7e9841238ed39ff

SHA-1:
617c9b0223d90fca371dd2cb2438dcf5f14cb8ca

SHA-256:
8ed11e2f97423af56e1b7c4b6acf5cdf989b004f64be8f5bf1c870563b982413

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 11:46:33 PM UTC  (a few moments ago)

File size:
523.3 KB (535,816 bytes)

Product version:
1.0.42.117

Copyright:
Copyright © 2013

Original file name:
ZedgeTonesync.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\apps\2.0\ec5jea0z.66t\hvkdvmzl.1zy\zedg..tion_4cd56dcfd1799009_0001.0000_dc33fadd22c78ec3\zedgetonesync.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/13/2013 7:19:31 AM

Valid to:
9/13/2015 7:19:31 AM

Subject:
CN=Zedge Europe AS, O=Zedge Europe AS, L=Trondheim, C=NO

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
045F1A4DE58D0A

File PE Metadata
Compilation timestamp:
9/25/2013 7:26:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:d2KnWPa4x7+l+4goYTGZrTfDHRQp4DbhzYptYwCW1:dTWPa4x7itZTfDHRQ2Dbhz0YjW1

Entry address:
0x7A9CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 03, 00, 00, 00, 28, 00, 00, 80, 0E, 00, 00, 00, 58, 00, 00, 80, 10, 00, 00, 00, 70, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 02, 00, 00, 00, 88, 00, 00, 80, 03, 00, 00, 00, A0, 00, 00, 80, 04, 00, 00, 00, B8, 00...
 
[+]

Entropy:
7.7403

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
482.5 KB (494,080 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ZedgeTonesync

Command:
C:\users\{user}\appdata\local\apps\2.0\ec5jea0z.66t\hvkdvmzl.1zy\zedg..tion_4cd56dcfd1799009_0001.0000_dc33fadd22c78ec3\zedgetonesync.exe -startup


The file ZedgeTonesync.exe has been discovered within the following program.

ZedgeTonesync  by Zedge
About 9% of users remove it
 
Powered by Should I Remove It?

Scan ZedgeTonesync.exe - Powered by Reason Core Security