EzQ.exe

EzQ Messenger 2009

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Dje Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Messenger 2009

Version:
6.0.6.1055

MD5:
c10a71e722136a5c48540c386772d2e1

SHA-1:
9305ad714e301cb0d7ef81ac644ce00cc661f4cb

SHA-256:
0082601a64e5c6d4eee54eaec7bd99037bf2f14906f62a473875cf12e4221168

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 10:37:20 AM UTC  (today)

File size:
10.1 MB (10,618,120 bytes)

Product version:
6.0.4.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Messenger 2009

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
12/27/2016 9:00:00 AM

Valid to:
1/27/2019 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Yongin-si, S=Gyeonggi-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
447114A2B08C3610DC7A78646CB00582

File PE Metadata
Compilation timestamp:
1/31/2017 3:06:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x512B78

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, 50, D2, 90, 00, E8, 58, 55, AF, FF, 33, C0, 55, 68, 55, 2E, 91, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, A5, 08, AF, FF, 8B, 45, EC, BA, 6C, 2E, 91, 00, E8, 94, 2F, AF, FF, 75, 46, A1, 60, FE, 92, 00, 8B, 00, E8, 3E, 62, B7, FF, A1, 60, FE, 92, 00, 8B, 00, BA, 7C, 2E, 91, 00, E8, E5, 5C, B7, FF, 8B, 0D, 5C, FB, 92, 00, A1, 60, FE, 92, 00, 8B, 00, 8B, 15, 00, 1F, 89, 00, E8, 2D, 62, B7, FF, A1, 60, FE, 92, 00...
 
[+]

Entropy:
6.3084

Developed / compiled with:
Microsoft Visual C++

Code size:
5.1 MB (5,314,048 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Dje Messenger

Command:
"C:\dje messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security