EzQ.exe

EzQ Messenger 2009

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Jne Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Messenger 2009

Version:
6.0.6.667

MD5:
d039d8c0f31dc0f9defc13e2935f4d2b

SHA-1:
26c95a48eb092585619bb353184b38ecf2b700fb

SHA-256:
508271aa49c20cb951451bcdd6180d6827d0c4e2288574c4bdd503f1b90b788f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:59:07 PM UTC  (a few moments ago)

File size:
10 MB (10,506,504 bytes)

Product version:
6.0.4.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Messenger 2009

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
12/27/2016 9:00:00 AM

Valid to:
1/27/2019 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Yongin-si, S=Gyeonggi-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
447114A2B08C3610DC7A78646CB00582

File PE Metadata
Compilation timestamp:
2/15/2017 4:10:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x514B5C

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, 00, F8, 90, 00, E8, 74, 35, AF, FF, 33, C0, 55, 68, 51, 4E, 91, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, C1, E8, AE, FF, 8B, 45, EC, BA, 68, 4E, 91, 00, E8, B0, 0F, AF, FF, 75, 5E, A1, 4C, 1E, 93, 00, 8B, 00, E8, EA, 36, B7, FF, A1, 4C, 1E, 93, 00, 8B, 00, BA, 78, 4E, 91, 00, E8, 91, 31, B7, FF, 8B, 0D, 48, 1B, 93, 00, A1, 4C, 1E, 93, 00, 8B, 00, 8B, 15, 18, 43, 89, 00, E8, D9, 36, B7, FF, 8B, 0D, 9C, 1F, 93...
 
[+]

Entropy:
6.3196

Developed / compiled with:
Microsoft Visual C++

Code size:
5.1 MB (5,323,776 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Jne Messenger

Command:
"C:\jne messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security