ezq.exe

EzQ Messenger ML

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KOTRA Messenger Plus’.
Publisher:
EZNIC., Inc  (signed by EZNIX Inc.)

Product:
EzQ Messenger ML

Description:
EzQ Messenger

Version:
6.0.0.2145

MD5:
8fe31ad2c8d1bfb382b896ddd109a0d0

SHA-1:
b3cdbcbbe03e710d6258f8e25ecf91cfbd9d89c0

SHA-256:
4915501a8076e99968993708d846ca55b38d9bc874697ea0e5afde7319318564

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:35:51 PM UTC  (a few moments ago)

File size:
11.4 MB (11,996,936 bytes)

Product version:
1.0.0.0

Copyright:
2000-2008

Trademarks:
EzQ Messenger ML

Original file name:
EzQ ML.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
12/27/2016 7:00:00 AM

Valid to:
1/27/2019 6:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Yongin-si, S=Gyeonggi-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
447114A2B08C3610DC7A78646CB00582

File PE Metadata
Compilation timestamp:
1/24/2017 11:37:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x535F14

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, C8, 00, 93, 00, E8, D4, 22, AD, FF, 33, C0, 55, 68, F6, 61, 93, 00, 64, FF, 30, 64, 89, 20, E8, 09, 9E, FF, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 30, D5, AC, FF, 8B, 45, EC, BA, 0C, 62, 93, 00, E8, 0B, FD, AC, FF, 75, 46, A1, 68, 4D, 95, 00, 8B, 00, E8, 55, 3C, B5, FF, A1, 68, 4D, 95, 00, 8B, 00, BA, 1C, 62, 93, 00, E8, FC, 36, B5, FF, 8B, 0D, 40, 4A, 95, 00, A1, 68, 4D, 95, 00, 8B, 00, 8B, 15, 4C, 72, 8C, 00, E8, 44, 3C, B5, FF...
 
[+]

Entropy:
6.1915

Developed / compiled with:
Microsoft Visual C++

Code size:
5.2 MB (5,458,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KOTRA Messenger Plus

Command:
"C:\kotra messenger plus\ezq.exe"


Scan ezq.exe - Powered by Reason Core Security