EzQ.exe

EzQ Engine 7.0

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DB Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Engine 7.0

Version:
7.0.0.42

MD5:
785b0868e0c36f10ddfc42a549f84ed5

SHA-1:
61dc6b4cc4e16cbc52723b080b3f318a717df0cb

SHA-256:
1a859855a9c8206b95862fa225fd2ad26690cec40a49575c5091dddc4347fa1c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 12:48:51 AM UTC  (today)

File size:
11.3 MB (11,829,320 bytes)

Product version:
7.0.0.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Engine 7.0

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/16/2012 9:00:00 AM

Valid to:
12/10/2014 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73E78017A7BF71B6762A603DC41FB6B5

File PE Metadata
Compilation timestamp:
11/5/2014 8:40:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:XzoQEzygx0XxDuMpVuEVcw6LfRj8cMwdN1tqHNPMHwzCqTD77K9XTwCYAEf0TqlF:6zygx0XZ3z6LfdltWNawzCU3o38Mm

Entry address:
0x6451B8

Entry point:
55, 8B, EC, B9, 19, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, B8, 58, F8, A3, 00, E8, 95, 2F, 9C, FF, 33, C0, 55, 68, 67, 57, A4, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 66, E2, 9B, FF, 8B, 45, EC, BA, 80, 57, A4, 00, E8, 91, 09, 9C, FF, 0F, 85, E7, 00, 00, 00, A1, 2C, 80, A6, 00, 8B, 00, E8, 9B, 5D, A4, FF, A1, 2C, 80, A6, 00, 8B, 00, BA, 90, 57, A4, 00, E8, 42, 58, A4, FF, 8D, 55, E0, A1, 2C, 80, A6, 00, 8B, 00, E8, 3B, 66, A4, FF, 8B, 45, E0, 8D, 55, E4, E8, B4, 78, 9C, FF...
 
[+]

Entropy:
6.5882

Developed / compiled with:
Microsoft Visual C++

Code size:
6.3 MB (6,572,032 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DB Messenger

Command:
"C:\db messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security