The 0000 ACTA TUTELA RAD 08680415102 exe (PhotoPreviewService) Tenorshare File Malware Analysis
Gridinsoft Logo

The 0000_ACTA_TUTELA_RAD. 08680415102.exe (PhotoPreviewService) File Analysis

Technical Analysis

File Name 0000_ACTA_TUTELA_RAD. 08680415102.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.227.174
Database Version 2025-10-13 00:00:17 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,838,352
File Size (bytes)
2025-10-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
d648abec249827ea963263b77ad0bceb
SHA1
c20ac065212537cacb548bb5bb2f9b9de1cb33bc
SHA256
e8cc702e17ee91f84b4552abdf8cce85e486e2c48e99cce9648997d74613ad9f
SHA512
eaa68988104fddd45c2a4993ccbb4565180fd040e51e3d347fd24b853c62c7a239b5e1d08f80dd03fa2bbd808a0b8f3c86b620566ba33029c8594b9d4f4efd03
ImpHash
da3baf53126b3bf5230230b98f914f3c

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140001659
Compilation Time 2023-07-13 03:03:35
Checksum 0x001c6b49 (Actual: 0x001c6b49)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path F:\Jenkins\WorkSpace\workspace\lib_TSPhotoPreviewSDK\bin\x64\RelWithDebInfo\PhotoPreviewService.pdb
Digital Signature OK
Imports 7 libraries
TSLogSDK, lib_TSCommunication_sdk, BugSplat64, FreeImage, KERNEL32, ole32, gdiplus
Exports 0 functions
Resources 2 Resources
Sections 9 Sections

Version Information

CompanyName Tenorshare
FileDescription PhotoPreviewService
FileVersion 1, 0, 0, 21-d-74eec5c8
InternalName PhotoPreviewService.exe
LegalCopyright Copyright © 2020
OriginalFilename PhotoPreviewService.exe
ProductName PhotoPreviewService
ProductVersion 1, 0, 0, 21-d-74eec5c8
Translation 0x0804 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,367,953 bytes 1,368,064 bytes 5.68 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 418FCF9EC259EC01AD09B349A8BFB42D
.rdata 0x0014f000 332,630 bytes 332,800 bytes 4.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 45BFE68553CE2DF394EDF6A21B984FFE
.data 0x001a1000 35,073 bytes 22,016 bytes 3.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7542D3DEBE996044A4C86CB0DA232934
.pdata 0x001aa000 66,108 bytes 66,560 bytes 5.80 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 66D24F217B8D37C092716AEAC5BD344D
.idata 0x001bb000 10,498 bytes 10,752 bytes 4.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6BC750429E14036DBE00C78A3A011AE4
.tls 0x001be000 777 bytes 1,024 bytes 0.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C573BD7CEA296A9C5D230CA6B5AEE1A6
.00cfg 0x001bf000 283 bytes 512 bytes 0.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DB34FE684F11884401A3E4E2595BBFD8
.rsrc 0x001c0000 2,163 bytes 2,560 bytes 2.60 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 36F6239D88C49E12CF95293CEDAF6562
.reloc 0x001c1000 12,267 bytes 12,288 bytes 3.89 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 71E0FC2F56FEC4291F03DFB2D48080D2

Resource Analysis

Total Resources: 2 (1,213 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 832 bytes
68.6%
RT_MANIFEST 1 381 bytes
31.4%

Certificate Chain Analysis

Certificate Information
Product PhotoPreviewService
Description PhotoPreviewService
File Version 1, 0, 0, 21-d-74eec5c8
Original Name PhotoPreviewService.exe
Signing Date 03:03 AM 07/13/2023 (823 days ago)
Verification Status Signed
Signers Tenorshare Co., Ltd.; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2022 - 2; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Internal Name PhotoPreviewService.exe
Copyright Copyright © 2020
Certificate Chain Summary
DigiCert Trusted Root G4 #1 Primary
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #2 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #3 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
DigiCert Timestamp 2022 - 2 #4 Chain
Validity Period: 2022-09-21 00:00:00 → 2033-11-21 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0C 4D 69 72 4B 94 FA 3C 2A 4A 3D 29 07 80 3D 5A
Tenorshare Co., Ltd. #5 Chain
Validity Period: 2021-07-07 00:00:00 → 2024-07-11 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 01 70 C5 D8 E6 2A BA C7 DB 20 91 8F 8C 95 B7 E8

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware