EzQ.exe

EzQ Messenger 2009

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Jne Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Messenger 2009

Version:
6.0.6.642

MD5:
3ca9174d29a5d0efadac46736795dd19

SHA-1:
1a447b0f94e378f93f98d71831aaa7941e5a2346

SHA-256:
944363202a95ab6c592664b691e26bcddcd62541f18eac5e5fe4e2653ca53688

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:13:57 PM UTC  (today)

File size:
10 MB (10,493,512 bytes)

Product version:
6.0.4.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Messenger 2009

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/16/2012 9:00:00 AM

Valid to:
12/10/2014 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73E78017A7BF71B6762A603DC41FB6B5

File PE Metadata
Compilation timestamp:
6/3/2013 7:43:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:1L2/ckyovHsnaumsQTspzk5fh9bZ2N8ZCGgXTwCeAER0Tqzf0OB8YbS9AKzzzzzP:JmvHsnauFUQ6h9zZe3ef0OBed

Entry address:
0x513ADC

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, CC, E4, 90, 00, E8, F4, 45, AF, FF, 33, C0, 55, 68, D1, 3D, 91, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 41, F9, AE, FF, 8B, 45, EC, BA, E8, 3D, 91, 00, E8, 30, 20, AF, FF, 75, 5E, A1, F8, 0D, 93, 00, 8B, 00, E8, 52, 41, B7, FF, A1, F8, 0D, 93, 00, 8B, 00, BA, F8, 3D, 91, 00, E8, F9, 3B, B7, FF, 8B, 0D, F8, 0A, 93, 00, A1, F8, 0D, 93, 00, 8B, 00, 8B, 15, E0, 30, 89, 00, E8, 41, 41, B7, FF, 8B, 0D, 48, 0F, 93...
 
[+]

Entropy:
6.3167

Developed / compiled with:
Microsoft Visual C++

Code size:
5.1 MB (5,318,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Jne Messenger

Command:
"C:\jne messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security