Gridinsoft Logo
File Icon

The photopadpsetup.exe (PhotoPad Software de Edição de Fotos Grátis) File Analysis

Technical Analysis

File Name photopadpsetup.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.216.174
Database Version 2025-05-20 06:00:30 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,320,784
File Size (bytes)
2025-05-20
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
f4e2905de0207c4949419b0936bb9b17
SHA1
8df9b18d370020b289b9b492237a2de4137b5b04
SHA256
87a4ba76912f25744cd0f2109e35d8e2746c362c9d02c4669bc1fdbc504ab3c2
SHA512
150ee97bf7a1a77cfcc778323cde86ee3ddcb85e9c437c4c430165144e4555e449c73da222dfbe582c93685a8790529e8a264c3fa60a8d31e4e4a8ab1761dfc5
ImpHash
dfc6dbbcea4beda15dcbddfb77d26fc5

PE Analysis

Basic Information

Icon
Hash: 49bc95e4f4d0557bfed5bc6ebee0c0c8
Fuzzy: 995532052df54cce63528d07217b1df8
dHash: c492ccd8f2f6fc1c
Image Base 0x00400000
Entry Point 0x00401286
Compilation Time 2025-03-28 00:54:35
Checksum 0x0032e6e0 (Actual: 0x0032e6e0)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 5 libraries
SETUPAPI, ole32, SHELL32, USER32, KERNEL32
Exports 0 functions
Resources 7 Resources
Sections 5 Sections

Version Information

CompanyName NCH Software
FileDescription PhotoPad Software de Edição de Fotos Grátis
FileVersion 14.20PT+
ProductVersion 14.20PT+
ProductName PhotoPad
LegalCopyright NCH Software
InternalName PhotoPad
OriginalFilename PhotoPad.exe
Translation 0x0c09 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,315 bytes 2,560 bytes 5.74 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 879893291378E8412BF92864C1B5F5F0
.rdata 0x00002000 2,818 bytes 3,072 bytes 3.80 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0B00557691E652A9BF4F207E90296A0D
.data 0x00003000 4 bytes 512 bytes 0.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1D7D80E8B5CE8C86E7C833467964B6AE
.rsrc 0x00004000 3,302,856 bytes 3,302,912 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C7BC0E8EF6BE51E92404551825CB4C5A
.reloc 0x0032b000 164 bytes 512 bytes 2.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 4267EE83EA1275AE19675A7CDAC23159
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 7 (3,302,373 bytes)
Resource Type Count Total Size Percentage
RT_ICON 2 5,968 bytes
0.2%
RT_GROUP_ICON 1 34 bytes
0%
RT_VERSION 1 752 bytes
0%
RT_MANIFEST 1 1,149 bytes
0%
None 2 3,294,470 bytes
99.8%

Certificate Chain Analysis

Certificate Information
Product PhotoPad
Description PhotoPad Software de Edição de Fotos Grátis
File Version 14.20PT+
Original Name PhotoPad.exe
Signing Date 05:06 PM 04/30/2025 (56 days ago)
Verification Status Signed
Signers NCH Software, Inc.; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4
Counter Signers Entrust Timestamp Authority - TSA1; Entrust Timestamping CA - TS1; Entrust (2048)
Internal Name PhotoPad
Copyright NCH Software
Certificate Chain Summary
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #1 Primary
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
NCH Software, Inc. #2 Chain
Validity Period: 2025-03-31 00:00:00 → 2028-03-28 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 05 BF 20 1B 48 6D FC 33 84 D7 CF F2 1C 13 80 67
Entrust.net Certification Authority (2048) #3 Chain
Validity Period: 1999-12-24 17:50:51 → 2029-07-24 14:15:12
Signature Algorithm: sha1RSA
Serial Number: 38 63 DE F8
Entrust Timestamping CA - TS1 #4 Chain
Validity Period: 2015-07-22 19:02:54 → 2029-06-22 19:32:54
Signature Algorithm: sha256RSA
Serial Number: 58 DA 13 FF 00 00 00 00 51 CE 0D F7
Entrust Timestamp Authority - TSA1 #5 Chain
Validity Period: 2025-01-22 17:42:33 → 2029-06-21 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 98 40 7C 5E 16 CF 87 C1 E9 C1 FF F9 B4 0A 88 8D

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware