Threat Database Trojans Trojan.ShellcodeRunner.Gen.OQ

Trojan.ShellcodeRunner.Gen.OQ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,515
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: May 1, 2026
Last Seen: July 12, 2026
OS(es) Affected: Windows

The detection of Trojan.ShellcodeRunner.Gen.OQ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it. In this report, we will provide an overview of Trojan.ShellcodeRunner.Gen.OQ, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.ShellcodeRunner.Gen.OQ?

Trojan.ShellcodeRunner.Gen.OQ is a type of Trojan malware that can infect your computer and allow unauthorized access to your system. The term "Trojan" refers to a type of malware that disguises itself as a legitimate program, but actually contains malicious code. The "ShellcodeRunner" part of the name suggests that this malware is designed to execute shellcode, which is a piece of code that can be used to exploit vulnerabilities in your system.

How Trojan.ShellcodeRunner.Gen.OQ Operates

Trojan.ShellcodeRunner.Gen.OQ operates by infecting your computer and then allowing its creators to access your system remotely. This can be done through various means, such as exploiting vulnerabilities in your operating system or software, or by tricking you into installing the malware yourself. Once installed, the malware can allow its creators to steal sensitive information, install additional malware, or use your computer for malicious activities.

Symptoms of Infection

The symptoms of a Trojan.ShellcodeRunner.Gen.OQ infection can vary, but common signs include slow system performance, unexpected crashes, and unfamiliar programs or icons on your desktop. You may also notice that your browser is being redirected to unfamiliar websites, or that you are receiving pop-up ads or spam emails. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware.

How to Remove Trojan.ShellcodeRunner.Gen.OQ

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your knowledge.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.ShellcodeRunner.Gen.OQ from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure that your system is free from this type of malware and that your personal data and computer are protected. Remember to always be cautious when downloading and installing software, and to regularly scan your system for malware to prevent future infections.

Analysis Report

General information

Family Name: Trojan.ShellcodeRunner.Gen.OQ
Signature status: No Signature

Known Samples

MD5: 103507a6ac9ad0f5689c497264e929c4
SHA1: b7cebebe07d555f7a7e1ae2c6cfd42c1cc2bd517
SHA256: 0820E90F76FA3BF811DF789CF143732CED405DB11AE97D1C5897A49A3638B027
File Size: 88.58 KB, 88576 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.5.0.0
Comments Watermark and overlay adorners for WPF.
Company Name Johan Larsson
File Description Gu.Wpf.Adorners
File Version 1.5.0.0
Internal Name Gu.Wpf.Adorners.dll
Legal Copyright Copyright © 2016
Original Filename Gu.Wpf.Adorners.dll
Product Name Gu.Wpf.Adorners
Product Version 1.5.0.0

File Traits

  • dll
  • x64

Block Information

Total Blocks: 389
Potentially Malicious Blocks: 16
Whitelisted Blocks: 356
Unknown Blocks: 17

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 x ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 x ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? 0 0 0 ? 0 x x 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 x 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...