Gridinsoft Logo
File Icon

The Retoucher.exe (Retoucher Application) File Analysis

Technical Analysis

File Name Retoucher.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
393216:Hs10jo13yTY+KldKe2RclZrOzsDRge4j8Mxk3qEDAN7MQ+jJrF2Ek0FoS:HI0jo8TcldKyVkhxBdy6sFoS
Scanner Version 1.0.214.174
Database Version 2025-04-22 21:00:30 UTC

Suspicious File Detected

Detected by 8 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
11%
Detection Rate
23,737,417
File Size (bytes)
8/72
Engines Detected
2025-04-22
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
3f48f52d908ba46592b7bbd39dd8ba49
SHA1
23f1e938ad30dedc456368a1ecdb4a41abb4cd70
SHA256
86a859c785d50d30ddedff326ed91cf64ee0bccc1e25a830556f2186454bd43d
SHA512
c33f418c67bec5fd23922450f79ef5bd7af093657f31570f8e74e266ebb8a0d695877c435be6fbcb368cd6cccc3fc08d7560e4da3607d550ec448a57eb78f419
ImpHash
9158747dc6240279afce84ac4d726c82

Security Engines with Detections (8 of 72)

Cylance
Unsafe Malicious
Zillya
Trojan.Snovir.Win32.1094 Malicious
NANO-Antivirus
Trojan.Win32.Snovir.kfmibf Malicious
Ikarus
PUA.ASR.6BA0SI Malicious
Varist
W32/S-1d5a7cc5!Eldorado Malicious
Google
Detected Malicious
VBA32
Trojan.Inject Malicious
SentinelOne
Static AI - Suspicious PE Malicious
64 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: dbd7ffb00e04b18c4ff987238d9a46e7
Fuzzy: a7a493187f4ae7162366f2187ed9af48
dHash: b1d0c28eac8ce630
Image Base 0x66200000
Entry Point 0x66201448
Compilation Time 2018-11-21 15:31:42
Checksum 0x00000000 (Actual: 0x016a803f)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path d:\build\ob\bora-23148499\vos3\thinstall\modules\boot_loader.pdb
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
KERNEL32, USER32, ntdll
Exports 0 functions
Resources 19 Resources
Sections 4 Sections

Version Information

CompanyName AKVIS
FileVersion 9.5.1286.17468
LegalCopyright Copyright © 2004-2018
ProductName AKVIS Retoucher
ProductVersion 9.5.1286.17468
FileDescription Retoucher Application
OriginalFilename Retoucher.exe
ThinAppBuildDateTime 20240218 233629
ThinAppLicense Grand Admin
ThinAppVersion 2312.0.0-23148499
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 109,904 bytes 110,080 bytes 6.61 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 20D29A7A06262E43608D65D1200C35EA
.rdata 0x0001c000 36,164 bytes 36,352 bytes 4.88 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 923992F3FF61F6E01297478E7D51B85B
.data 0x00025000 164,796 bytes 156,672 bytes 1.28 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE DF76EBA1CB6DC0CD541532C7C1DCE79C
.rsrc 0x0004e000 823,384 bytes 823,808 bytes 4.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BF4AD203C547D308C62D5DBA4D056916
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 19 (822,068 bytes)
Resource Type Count Total Size Percentage
RT_ICON 16 820,928 bytes
99.9%
RT_GROUP_ICON 2 236 bytes
0%
RT_VERSION 1 904 bytes
0.1%

Certificate Chain Analysis

Certificate Information
Product AKVIS Retoucher
Description Retoucher Application
File Version 9.5.1286.17468
Original Name Retoucher.exe
Copyright Copyright © 2004-2018

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
8 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware