EzQ.exe

EzQ Messenger 2009

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Gbe Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Messenger 2009

Version:
6.0.6.866

MD5:
c259d829c7e469af9902d817f2b0f707

SHA-1:
47081f12a8c5bf8a27669e08de011d2fa72c36ee

SHA-256:
d66b13cea0cc527057f3ad6cea255d5c457523a0673b83ec9a2ad3f207cc0a0e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:42:16 PM UTC  (a few moments ago)

File size:
10 MB (10,452,624 bytes)

Product version:
6.0.4.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Messenger 2009

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/27/2010 9:00:00 AM

Valid to:
10/27/2012 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Gangnam, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
34E68925D07E3791E1FA5446FAF83CDF

File PE Metadata
Compilation timestamp:
6/21/2012 4:12:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:D6ku6WUoj+MXAXKD/BXzVCpqsjiVDyPkXTwCeAnK0Tqhf0OBQI8S9AKzzzzzzzzV:uUoj+UtD/BjVC0BVN3ef0OBD/

Entry address:
0x50AAC8

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, A8, 52, 90, 00, E8, 08, D6, AF, FF, 33, C0, 55, 68, A5, AD, 90, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 55, 89, AF, FF, 8B, 45, EC, BA, BC, AD, 90, 00, E8, 44, B0, AF, FF, 75, 46, A1, EC, 7D, 92, 00, 8B, 00, E8, 66, D1, B7, FF, A1, EC, 7D, 92, 00, 8B, 00, BA, CC, AD, 90, 00, E8, 0D, CC, B7, FF, 8B, 0D, EC, 7A, 92, 00, A1, EC, 7D, 92, 00, 8B, 00, 8B, 15, E0, BD, 88, 00, E8, 55, D1, B7, FF, A1, EC, 7D, 92, 00...
 
[+]

Entropy:
6.3153

Developed / compiled with:
Microsoft Visual C++

Code size:
5 MB (5,281,280 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Gbe Messenger

Command:
"C:\gbe messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security