fssmessenger.exe

EzQ Engine 7.0

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FSS Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Engine 7.0

Description:
EzQ Engine 7.0.39066

Version:
3.9.0.66

MD5:
2e191960343a8a5fb3ff9a5e09485f31

SHA-1:
d74b24a8ba1b3a16af3e3d961cba57f9cbfcc582

SHA-256:
1d3206a6ae918e62028f8048a5824bdd852adc6e296742c0dcecb7d49adc0fe0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 12:29:24 AM UTC  (today)

File size:
12.3 MB (12,871,912 bytes)

Product version:
7.0.0.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Engine 7.0

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/17/2016 7:00:00 PM

Valid to:
1/7/2017 6:59:59 PM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
688C2E1EE24C5854B30C3C323C8289AA

File PE Metadata
Compilation timestamp:
12/26/2016 8:42:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x676324

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, D4, 01, A7, 00, E8, A0, 1F, 99, FF, 33, C0, 55, 68, F9, 65, A7, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, F9, D0, 98, FF, 8B, 45, EC, BA, 10, 66, A7, 00, E8, 94, F9, 98, FF, 75, 46, A1, 30, 90, A9, 00, 8B, 00, E8, B2, 4E, A1, FF, A1, 30, 90, A9, 00, 8B, 00, BA, 20, 66, A7, 00, E8, 59, 49, A1, FF, 8B, 0D, E8, 8C, A9, 00, A1, 30, 90, A9, 00, 8B, 00, 8B, 15, D4, 59, 9D, 00, E8, A1, 4E, A1, FF, A1, 30, 90, A9, 00...
 
[+]

Entropy:
6.6260

Developed / compiled with:
Microsoft Visual C++

Code size:
6.5 MB (6,770,688 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FSS Messenger

Command:
"C:\fss messenger\fssmessenger.exe"


Scan fssmessenger.exe - Powered by Reason Core Security