partitionwizard.dll threat report

MD5 dec55fcfb5b325548766d5ea42f8ba97
Latest seen 2025-06-14 23:00:19 (11 months ago)
First seen 2025-06-14 23:00:19 (11 months ago)
Size 5 MB

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for partitionwizard.dll. ThreatInfo currently classifies this sample as Trojan.Wacatac.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows partitionwizard.dll detected as Trojan.Wacatac. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
Trojan.Wacatac
Last analysis
2025-06-14 23:00:19 (11 months ago)
File hash
dec55fcfb5b325548766d5ea42f8ba97
Download Anti-Malware

partitionwizard.dll is a Windows file recorded in the ThreatInfo database. It is associated with MiniTool Partition Wizard. The reported company name is MiniTool Software Limited. The current detection status is Trojan.Wacatac, based on the latest analysis from 2025-06-14 23:00:19 (11 months ago).

If partitionwizard.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Wacatac.

Product Name: MiniTool Partition Wizard
Company Name: MiniTool Software Limited
MD5: dec55fcfb5b325548766d5ea42f8ba97
Size: 5 MB
First Published: 2025-06-14 23:00:19 (11 months ago)
Latest Published: 2025-06-14 23:00:19 (11 months ago)
Status: Trojan.Wacatac (on last analysis)
Analysis Date: 2025-06-14 23:00:19 (11 months ago)
partitionwizard.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%profile%\downloads\compressed\minitool partition wizard 12.9 [ crack .dll & .mth ] - no test\2_crack uz1 [ .dll ] - minitool partition wizard 12.9\x86

ThreatInfo has observed partitionwizard.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Thailand with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for partitionwizard.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

partitionwizard.dll is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x10000000
Entry Address: 0x005ebdb5

PE Sections:

Name Size of data MD5
.text 0 d41d8cd98f00b204e9800998ecf8427e
.rdata 0 d41d8cd98f00b204e9800998ecf8427e
.data 0 d41d8cd98f00b204e9800998ecf8427e
.idata 0 d41d8cd98f00b204e9800998ecf8427e
.xUF 0 d41d8cd98f00b204e9800998ecf8427e
.[[] 11776 91358d26c8dca0652d4c7f3c704114df
.6-m 5351424 06bc46dc24e61daa314995b57e2a33dc
.reloc 2048 d3eb66b1987b81553961a2aba80491be
.rsrc 357888 b94fc8280f9d15109f115a06da96cdda

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: