EzQ.exe

EzQ Messenger 2009

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Gen Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Messenger 2009

Version:
6.0.6.1192

MD5:
1028778678e31d988b40abfcd0bfb450

SHA-1:
fcc257ac09e5990c599c2f96bb5ac9afa1dfd84b

SHA-256:
e629bcc8fb55772463772a5b3cb7914de19c622636f4c4a8ff564e53282a32ae

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:20:37 PM UTC  (a few moments ago)

File size:
9.9 MB (10,409,224 bytes)

Product version:
6.0.4.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Messenger 2009

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
12/27/2016 9:00:00 AM

Valid to:
1/27/2019 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Yongin-si, S=Gyeonggi-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
447114A2B08C3610DC7A78646CB00582

File PE Metadata
Compilation timestamp:
2/15/2017 12:31:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x561C70

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, E8, C6, 95, 00, E8, 84, 65, AA, FF, 33, C0, 55, 68, 4D, 1F, 96, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 0D, 18, AA, FF, 8B, 45, EC, BA, 64, 1F, 96, 00, E8, C0, 3F, AA, FF, 75, 46, A1, 38, 11, 98, 00, 8B, 00, E8, D2, 95, B2, FF, A1, 38, 11, 98, 00, 8B, 00, BA, 74, 1F, 96, 00, E8, 79, 90, B2, FF, 8B, 0D, D4, 0D, 98, 00, A1, 38, 11, 98, 00, 8B, 00, 8B, 15, 3C, E1, 90, 00, E8, C1, 95, B2, FF, A1, 38, 11, 98, 00...
 
[+]

Entropy:
6.4347

Developed / compiled with:
Microsoft Visual C++

Code size:
5.4 MB (5,639,168 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Gen Messenger

Command:
"C:\gen messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security