GridinSoft Threat Intelligence

FLEngine_x64_Copy4.dll threat report

Detected as Trojan.Heur! File reputation report
MD5 c2701e88f64252a78bb24f94838e16cd
Latest seen 2025-06-28 23:01:31 (11 months ago)
First seen 2025-06-28 23:01:27 (11 months ago)
Size 62 MB
Publisher Image-Line
Product FL Studio

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Heur!. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Heur!
Recommended action
Scan and remove
Last analysis
2025-06-28 23:01:31 (11 months ago)
File hash
c2701e88f64252a78bb24f94838e16cd
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Heur!, part of the Trojan threat category.

Category context

Malware disguised as legitimate software or delivered through deceptive packaging. Related Trojan reports help compare this file with nearby detections, publishers, and hashes.

Timeline

First seen 2025-06-28 23:01:27 (11 months ago); latest analysis 2025-06-28 23:01:31 (11 months ago).

Publisher context

Company metadata: Image-Line. Product metadata: FL Studio.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present. Review the Trojan category for related samples and common context.

FLEngine_x64_Copy4.dll is a Windows file recorded in the ThreatInfo database. It is associated with FL Studio. The reported company name is Image-Line. The current detection status is Trojan.Heur!, based on the latest analysis from 2025-06-28 23:01:31 (11 months ago). ThreatInfo groups this verdict with Trojan reports for broader family-level investigation.

If FLEngine_x64_Copy4.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: FL Studio
Company Name: Image-Line
MD5: c2701e88f64252a78bb24f94838e16cd
Size: 62 MB
First Published: 2025-06-28 23:01:27 (11 months ago)
Latest Published: 2025-06-28 23:01:31 (11 months ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2025-06-28 23:01:31 (11 months ago)
FLEngine_x64_Copy4.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%programfiles%\image-line

ThreatInfo has observed FLEngine_x64_Copy4.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for FLEngine_x64_Copy4.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

FLEngine_x64_Copy4.dll is identified as pe for 64-bit systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Windows GUI
Entry point 0x03bf1c93
Image base 0x0000000000400000

PE Sections:

Sections 20
Raw data 65461760

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 13651968 bytes · 20.9% of section data
Large raw data
MD5 aa8c83efcc751a852c40825dfa029e8b
.data 1857024 bytes · 2.8% of section data
MD5 5af9d5246362812c22e11904de9dd9eb
.bss 0 bytes · 0.0% of section data
MD5 d41d8cd98f00b204e9800998ecf8427e
.idata 26112 bytes · 0.0% of section data
MD5 da60f964497061a700cf9424130496f3
.didata 4608 bytes · 0.0% of section data
Uncommon name
MD5 faebac06e75312229ff9837219534771
.edata 512 bytes · 0.0% of section data
MD5 d13c83df6ebb786796cce86e070ad69a
.rdata 512 bytes · 0.0% of section data
MD5 19ab6a27aee54f4cc5376359f1d9573b
.xda0 459776 bytes · 0.7% of section data
Uncommon name
MD5 b6ea1b0e0dc888e5b0c7c6c2372d03f5
.pdata 559616 bytes · 0.9% of section data
MD5 1ae278559fb2ba20254f9764d0e455fc
.xda1 37078528 bytes · 56.6% of section data
Large raw data Uncommon name
MD5 fd951a4b2427eedaab3d14d0af81a931
.xda2 7168 bytes · 0.0% of section data
Uncommon name
MD5 92280768eed8fd6bdbef6e09c7a15684
.xda3 5059072 bytes · 7.7% of section data
Large raw data Uncommon name
MD5 9acdc4f641764b04b9e992147d43c425
.xda0 459776 bytes · 0.7% of section data
Uncommon name
MD5 2d5dee71ab9567d931992c6ffb1b3e58
.xda1 1767936 bytes · 2.7% of section data
Uncommon name
MD5 953939ff7739807604d2c1b3fb1d31ea
.xda0 1536 bytes · 0.0% of section data
Uncommon name
MD5 cf3716ca208423e0db41b34c5cf763cc
.xda2 524288 bytes · 0.8% of section data
Uncommon name
MD5 7524b8dc03a81dc66932b052fbf445b2
.xda3 2560 bytes · 0.0% of section data
Uncommon name
MD5 2405ac571e8551d7854cef24b21dbcf9
.xda4 1761280 bytes · 2.7% of section data
Uncommon name
MD5 9ed88a7c0ae7da0eb9d06a3e242f8458
.reloc 471552 bytes · 0.7% of section data
MD5 eba4b89d03c3e503c854ae0b3ba3c750
.rsrc 1767936 bytes · 2.7% of section data
MD5 1e62a8c6819e34ed302ed2cd29d31140

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Heur!

This report identifies FLEngine_x64_Copy4.dll by MD5 c2701e88f64252a78bb24f94838e16cd. It is part of the Trojan report group. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with c2701e88f64252a78bb24f94838e16cd.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found. Use the Trojan category to compare similar reports.