tonidosync2.exe

Tonido Sync

CodeLathe, LLC

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘TonidoSync’.
Publisher:
CodeLathe LLC  (signed by CodeLathe, LLC)

Product:
Tonido Sync

Description:
Tonido Sync Client

Version:
14,90,0,34362

MD5:
b7add626ee4b32a1eb3c47e9d95abaa3

SHA-1:
15dadcf27457243e070c3fdc234958432c37c0e5

SHA-256:
61b46ea4da09add8940a95d3fd929d74d9189e34e00051786c7d6e3dd6460b15

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/26/2025 1:04:11 AM UTC  (today)

File size:
6.7 MB (7,073,032 bytes)

Product version:
14,90,0,34362

Copyright:
Copyright (C) 2008-2016 CodeLathe

Original file name:
tonidosync2.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\tonidosync\tonidosync2.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
11/13/2015 1:00:00 AM

Valid to:
12/11/2017 12:59:59 AM

Subject:
CN="CodeLathe, LLC", OU=Secure Application Development, O="CodeLathe, LLC", L=Plano, S=Texas, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2B7010DF5F955A2A1EC41266CD08F159

File PE Metadata
Compilation timestamp:
2/8/2017 8:33:58 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x3924D4

Entry point:
E8, 82, 0B, 00, 00, E9, 8E, FE, FF, FF, 53, 56, 57, 6A, 00, 68, A0, 0F, 00, 00, 68, 10, 3C, B1, 00, E8, 0C, 0D, 00, 00, 83, C4, 0C, 68, 9C, 1D, 9D, 00, FF, 15, 30, C3, 91, 00, 8B, F0, 85, F6, 0F, 84, 8C, 00, 00, 00, 68, 84, 75, A2, 00, 56, FF, 15, 2C, C3, 91, 00, 68, A0, 75, A2, 00, 56, 8B, D8, FF, 15, 2C, C3, 91, 00, 68, BC, 75, A2, 00, 56, 8B, F8, FF, 15, 2C, C3, 91, 00, 8B, F0, 85, DB, 74, 37, 85, FF, 74, 33, 85, F6, 74, 2F, 83, 25, 2C, 3C, B1, 00, 00, 8B, CB, 68, 28, 3C, B1, 00, E8, D2, 07, 00, 00, FF...
 
[+]

Code size:
5.1 MB (5,350,912 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TonidoSync

Command:
"C:\Program Files\tonidosync\tonidosync2.exe"


Scan tonidosync2.exe - Powered by Reason Core Security