Gridinsoft Logo

The FH6AllInOneTrainer.exe (FH6 All-in-One Trainer) File Analysis

Technical Analysis

File Name FH6AllInOneTrainer.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
1572864:KIGvZIwn/CGLAx9GCYr7pETrAwxa8ZYtX:zGvX/CmSVYXbwxa8ZU
Scanner Version 1.0.247.174
Database Version 2026-06-13 02:00:22 UTC

Suspicious File Detected

Detected by 4 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.

GameHack refers to game modification tools that manipulate game mechanics to provide unfair advantages, violating game terms of service and fair play principles.
6%
Detection Rate
51,769,878
File Size (bytes)
4/70
Engines Detected
2026-06-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a8edafeb73bc2017217a1fc163588473
SHA1
bc66c6f37b6b9dcb04a5b8eb4c43fab1cfddd498
SHA256
36b05e3b0f7293e958141b00a336faf360d91f50abdf64f04bbd1b2be4ce891c
SHA512
738c727b35aac636d6d960e7426a5f43ec658d74daf9798b4e5e0e6324d9b6aed5d3306eb73b25bdafc3d5677ac56d29e4c140ff74aafcdba25b46141c8c60f8
ImpHash
759a3c183e9207f0571ae8ae7b2a52e0

Security Engines with Detections (4 of 70)

Bkav
W32.Malware.81E2329C Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Malwarebytes
RiskWare.GameHack Malicious
huorong
TrojanDropper/MSIL.Injector.a Malicious
66 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1405c6e50
Compilation Time 2026-04-30 01:10:39
Checksum 0x00000000 (Actual: 0x031647a1)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path D:\a\_work\1\s\src\runtime\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
Digital Signature No valid SignedData structure was found.
Imports 17 libraries
Exports 44 functions
Resources 5 Resources
Sections 9 Sections

Version Information

Translation 0x0000 0x04b0
Comments All-in-one Forza Horizon 6 trainer
CompanyName changcheng967
FileDescription FH6 All-in-One Trainer
FileVersion 6.0.0.0
InternalName FH6AllInOneTrainer.dll
LegalCopyright © 2026 changcheng967 · GPL-3.0
LegalTrademarks
OriginalFilename FH6AllInOneTrainer.dll
ProductName FH6 All-in-One Trainer
ProductVersion 6.0.0
Assembly Version 6.0.0.0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,702,940 bytes 6,703,104 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 08B4EC4CE0BAF8EDBB8DA97D51FE361B
.CLR_UEF 0x00666000 215 bytes 512 bytes 3.09 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 688BC65A85358C1F28D645FBF3C9C07F
.rdata 0x00667000 1,625,670 bytes 1,626,112 bytes 5.71 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 47B89C6087324A0B1625CF89397EE2A0
.data 0x007f4000 102,248 bytes 20,992 bytes 2.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE EF428220BD2C66E6AE8241F68BEA2223
.pdata 0x0080d000 233,820 bytes 233,984 bytes 6.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DB9B080EC28A0500C40ABBD18C5A60DF
.didat 0x00847000 56 bytes 512 bytes 0.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C676ADD2927A59AD3D49F81677E7D735
Section 0x00848000 8 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x00849000 1,354,216 bytes 1,354,240 bytes 6.38 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 81469DD476F565C746770513D8AA449D
.reloc 0x00994000 30,952 bytes 31,232 bytes 5.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ F019697C77E4C008380B4C69D1B3423E

Resource Analysis

Total Resources: 5 (1,353,733 bytes)
Resource Type Count Total Size Percentage
RT_RCDATA 3 1,351,584 bytes
99.8%
RT_VERSION 1 1,008 bytes
0.1%
RT_MANIFEST 1 1,141 bytes
0.1%

Certificate Chain Analysis

Certificate Information
Product FH6 All-in-One Trainer
Description FH6 All-in-One Trainer
File Version 6.0.0.0
Original Name FH6AllInOneTrainer.dll
Internal Name FH6AllInOneTrainer.dll
Copyright © 2026 changcheng967 · GPL-3.0
Certificate Chain Summary
Microsoft Windows Code Signing PCA 2024 #1 Primary
Validity Period: 2024-08-08 21:36:23 → 2035-06-23 22:04:01
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 00 1C 48 9F 81 DF A1 B0 B7 77 00 00 00 00 00 1C
.NET DAC #2 Chain
Validity Period: 2026-03-05 19:58:54 → 2027-03-03 19:58:54
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 01 38 CB 5F A0 B8 D0 E0 6E CA 00 00 00 00 01 38
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2026-02-19 19:40:04 → 2027-05-17 19:40:04
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 27 D5 C0 83 C3 B1 2E 57 2D 00 01 00 00 02 27
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
Google Media Processing Services #5 Chain
Validity Period: 2026-02-17 15:17:12 → 2027-02-12 15:17:11
Signature Algorithm: SHA384ECDSA
Serial Number: 9E AF 15 62 81 A9 49 02 16 5B 48 FF 58 A9 6D 24 98 1E CE
Google C2PA Media Services 1P ICA G3 #6 Chain
Validity Period: 2025-05-08 22:36:26 → 2030-05-08 22:36:26
Signature Algorithm: SHA384ECDSA
Serial Number: 41 FA A5 21 47 76 21 58 DA 7F 9B 2C FF 8D FD 16 09 1E EE 3E
Google Core Time Stamping Authority T11 #7 Chain
Validity Period: 2025-09-08 13:48:59 → 2031-09-09 01:48:58
Signature Algorithm: SHA384ECDSA
Serial Number: 7B 51 99 70 FF D7 5A 95 9D 0C 40 D7 4E 86 F1 D7 70 24 83
Google C2PA Core Time-Stamping ICA G3 #8 Chain
Validity Period: 2025-05-08 22:36:26 → 2040-05-08 22:36:26
Signature Algorithm: SHA384ECDSA
Serial Number: 45 00 83 6E 72 13 02 C5 64 A4 9E 64 33 76 FA 8F 09 B7 64 F4
Google Media Processing Services #9 Chain
Validity Period: 2026-04-16 14:00:45 → 2027-04-11 14:00:44
Signature Algorithm: SHA384ECDSA
Serial Number: A3 E6 61 2A 73 11 9E FB C4 1F 12 A8 F3 D8 4F 40 9D 84 2C
Google Core Time Stamping Authority T10 #10 Chain
Validity Period: 2025-09-08 13:48:57 → 2031-09-09 01:48:56
Signature Algorithm: SHA384ECDSA
Serial Number: 0F 04 3D FD D7 76 34 7E A5 F7 C3 AD 45 A7 0B 5A EE 24 55

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
4 security engines flagged this file. Could be a real threat, or could be a false alarm — common with keygens, game trainers, and legitimate system utilities. Check if the file has a valid digital signature and whether it came from the official source.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware