League of Legends.exe threat report

MD5 4d6bd9a4863784e3bce738430f419661
Latest seen 2025-01-28 23:02:35 (a year ago)
First seen 2025-01-28 23:02:34 (a year ago)
Size 26 MB
Publisher Riot Games, Inc.

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Heur!. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Heur!
Recommended action
Scan and remove
Last analysis
2025-01-28 23:02:35 (a year ago)
File hash
4d6bd9a4863784e3bce738430f419661
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Heur!.

Timeline

First seen 2025-01-28 23:02:34 (a year ago); latest analysis 2025-01-28 23:02:35 (a year ago).

Publisher context

Company metadata: Riot Games, Inc.. Product metadata: League of Legends (TM) Client.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

League of Legends.exe is a Windows file recorded in the ThreatInfo database. It is associated with League of Legends (TM) Client. The reported company name is Riot Games, Inc.. The current detection status is Trojan.Heur!, based on the latest analysis from 2025-01-28 23:02:35 (a year ago).

If League of Legends.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: League of Legends (TM) Client
Company Name: Riot Games, Inc.
MD5: 4d6bd9a4863784e3bce738430f419661
Size: 26 MB
First Published: 2025-01-28 23:02:34 (a year ago)
Latest Published: 2025-01-28 23:02:35 (a year ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2025-01-28 23:02:35 (a year ago)
League of Legends.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\riot games\league of legends
%sysdrive%\â™ games\league of legends

ThreatInfo has observed League of Legends.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Iran with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for League of Legends.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

League of Legends.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x01b58000

PE Sections:

Name Size of data MD5
.text 22020096 b792e153a0ac77bd973c3ff4d309eb7e
.rdata 3829760 d450a2f7e27aabef262e1bc396e72227
.data 577536 4b2177a1525379bda5782644f3858530
.pdata 1216512 80057b1faf9d0c2a39f3f802d2e69444
CPADinfo 4096 34d6028f86ab55384855b193ac87dd84
.rodata 4096 ecd8fe418d78f2cb92fb25c2aa2745da
_RDATA 12288 d7b4436f3547eab613db2b810fc5a964
.rsrc 188416 6d7564fab43c8774786456fb75bbecf8
.reloc 212992 51531ccea72d3685f84f154abc9099c7
.toir 4096 3c20b5d38492bcfe6acbe44b0ff22a72
.stub 8192 9600033fd7b6d6e3d48171a91843bae9

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: