Threat Database Trojans Trojan.Shiz.Q

Trojan.Shiz.Q

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,408
Threat Level: 80 % (High)
Infected Computers: 15
First Seen: December 21, 2022
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Shiz.Q
Signature status: No Signature

Known Samples

MD5: f25d28f506923036fa8affc87376f47c
SHA1: c7f85ea3909c3a3a25a4c7d374ab9a5379236f34
SHA256: 5C87EC6E76DEA262208464DE5A6D545A6C1C2E75E58736A189B8EFF7281DC58D
File Size: 217.60 KB, 217600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Kingston
File Description Google Update
File Version 1.8.0.5
Internal Name a2scan
Legal Copyright (C) 2003-2010 Emsi Software GmbH
Product Name Emsisoft Anti-Malware
Product Version 1.8.2.7

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 7
Potentially Malicious Blocks: 6
Whitelisted Blocks: 1
Unknown Blocks: 0

Visual Map

x x x 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Shiz.Q

Files Modified

File Attributes
\device\namedpipe\acsipc_server Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\prevxcsi\csidb.csi Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\46a5.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\46a5.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\4dec.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\4dec.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\4dfc.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\4dfc.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\4dfd.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\4dfd.tmp Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\4dfe.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\4dfe.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\4dff.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\4dff.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\4e00.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\4e9e.tmp Synchronize,Write Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8b2b9a00839eed1dfdccc3bfc2f5df12 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\b46811c17859ffb409cf0e904a4aa8f8 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8b2b9a00839eed1dfdccc3bfc2f5df12 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\b46811c17859ffb409cf0e904a4aa8f8 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\apppatch\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\apppatch\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\firewallcontrolpanel.dll,-12122 Windows Defender Firewall RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::be6cf229 &«þãSÒK@‚,Ö¹nŸâÏ ×òÁ_ÇüZ Ô>x< ªJdü'¬¬ôZŠ´ò ¼º4"ˆ2 tà'?xN<Ÿ’<¬îZ¼"‚‚œ(dÔtrºj¦ê ¤T\ˆÚœt2ÜêFJ$äPäâr.Ä'”ÒÒL² RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n/ �v������#�(�+�[,��1`1�1HO1�D9ߔ@V�A��H[uR20_�z`�2b"hk`k�ql(�o�{b�{�=�Jq�P�������������Ǐ�T��T��Dt�T��m�Ù�����=��$�8წ����&M�=�S �YB1_T�Vw��R���%�������A RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::be6cf229 &«þãSÒK@‚,Ö¹nŸâÏ ×òÁ_ÇüZ Ô>x< ªJdü'¬¬ôZŠ´ò ¼º4"ˆ2 tà'?xN<Ÿ’<¬îZ¼"‚‚œ(dÔtrºj¦ê ¤T\ˆÚœt2ÜêFJ$äPäâr.Ä'”ÒÒL² RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Anti Debug
  • NtQuerySystemInformation
Network Winhttp
  • WinHttpOpen