TrainerLib_x86.dll threat report

MD5 e7879ae0d70e5467a92633e471233a36
Latest seen 2024-09-30 23:06:41 (2 years ago)
First seen 2024-09-30 23:06:41 (2 years ago)
Size 3 MB
Publisher WeMod LLC
Product WeMod

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for TrainerLib_x86.dll. ThreatInfo currently classifies this sample as Trojan.Heur!.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows TrainerLib_x86.dll detected as Trojan.Heur!. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
Trojan.Heur!
Last analysis
2024-09-30 23:06:41 (2 years ago)
File hash
e7879ae0d70e5467a92633e471233a36
Download Anti-Malware

TrainerLib_x86.dll is a Windows file recorded in the ThreatInfo database. It is associated with WeMod. The reported company name is WeMod LLC. The current detection status is Trojan.Heur!, based on the latest analysis from 2024-09-30 23:06:41 (2 years ago).

If TrainerLib_x86.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: WeMod
Company Name: WeMod LLC
MD5: e7879ae0d70e5467a92633e471233a36
Size: 3 MB
First Published: 2024-09-30 23:06:41 (2 years ago)
Latest Published: 2024-09-30 23:06:41 (2 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2024-09-30 23:06:41 (2 years ago)
TrainerLib_x86.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%localappdata%\squirreltemp\tempb\lib\net45\resources\app.asar.unpacked\static\unpacked

ThreatInfo has observed TrainerLib_x86.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Russia with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for TrainerLib_x86.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

TrainerLib_x86.dll is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x10000000
Entry Address: 0x0054b058

PE Sections:

Name Size of data MD5
131072 0e902c3f50e6b81f85bdbc0777a00614
40448 59248005d296060a297a6b0407af57a3
1536 e6958c77269f1e4121d2204ad397eea3
1024 e91ef9df728fa44a073087a2f8c8fa5d
11264 56b776f2702b97b6576a609f4684cf7a
.edata 512 a1c2dd345d1505440df43384cae8e4b4
.idata 512 feb8bf0c7e4b38b0da8f8febcab98fdc
.rsrc 1536 9cdd816c38c0cc77ff54fe621a0bb604
.wemod 0 d41d8cd98f00b204e9800998ecf8427e
.boot 3046912 28ddd6c5e2bb566ec6af6e74f5b80156

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: