| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Feb-24 19:19:59 |
| Detected languages |
English - United States
|
| Comments | Photoshop for minimalists: no installation, no trash left behind. For additional details, visit http:\\portableXapps.blogspot.com |
| CompanyName | PortableXApps |
| FileDescription | Photoshop LITE Portable |
| FileVersion | 13.0.1.2 |
| InternalName | Photoshop LITE Portable |
| LegalCopyright | PortableXApps |
| LegalTrademarks | PortableXApps® 2012 |
| OriginalFilename | PhotoshopPortable.exe |
| ProductName | Photoshop LITE Portable |
| ProductVersion | 13.0.1.2 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is an NSIS installer | Unusual section name found: .ndata |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
119351 bytes of data starting at offset 0x12000.
The overlay data has an entropy of 7.97796 and is possibly compressed or encrypted. |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-02-24 15:38:00) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xd0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2012-Feb-24 19:19:59 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x7000 |
| SizeOfInitializedData | 0x6ce00 |
| SizeOfUninitializedData | 0x4200 |
| AddressOfEntryPoint | 0x000039E3 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x8000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 6.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x16d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetFileTime
CompareFileTime SearchPathW GetShortPathNameW GetFullPathNameW MoveFileW SetCurrentDirectoryW GetFileAttributesW GetLastError CreateDirectoryW SetFileAttributesW Sleep GetTickCount CreateFileW GetFileSize GetModuleFileNameW GetCurrentProcess CopyFileW ExitProcess GetWindowsDirectoryW GetTempPathW GetCommandLineW SetErrorMode CloseHandle lstrlenW lstrcpynW GetDiskFreeSpaceW GlobalUnlock GlobalLock CreateThread LoadLibraryW CreateProcessW lstrcmpiA GetTempFileNameW lstrcatW GetProcAddress LoadLibraryA GetModuleHandleA OpenProcess lstrcpyW GetVersionExW GetSystemDirectoryW GetVersion lstrcpyA RemoveDirectoryW lstrcmpA lstrcmpiW lstrcmpW ExpandEnvironmentStringsW GlobalAlloc WaitForSingleObject GetExitCodeProcess GlobalFree GetModuleHandleW LoadLibraryExW FreeLibrary WritePrivateProfileStringW GetPrivateProfileStringW WideCharToMultiByte lstrlenA MulDiv WriteFile ReadFile MultiByteToWideChar SetFilePointer FindClose FindNextFileW FindFirstFileW DeleteFileW lstrcpynA |
|---|---|
| USER32.dll |
GetAsyncKeyState
IsDlgButtonChecked ScreenToClient GetMessagePos CallWindowProcW IsWindowVisible LoadBitmapW CloseClipboard SetClipboardData EmptyClipboard OpenClipboard TrackPopupMenu GetWindowRect AppendMenuW CreatePopupMenu GetSystemMetrics EndDialog EnableMenuItem GetSystemMenu SetClassLongW IsWindowEnabled SetWindowPos DialogBoxParamW CheckDlgButton CreateWindowExW SystemParametersInfoW RegisterClassW SetDlgItemTextW GetDlgItemTextW MessageBoxIndirectW CharNextA CharUpperW CharPrevW wvsprintfW DispatchMessageW PeekMessageW wsprintfA DestroyWindow CreateDialogParamW SetTimer SetWindowTextW PostQuitMessage SetForegroundWindow ShowWindow wsprintfW SendMessageTimeoutW LoadCursorW SetCursor GetWindowLongW GetSysColor CharNextW GetClassInfoW ExitWindowsEx IsWindow GetDlgItem SetWindowLongW LoadImageW GetDC EnableWindow InvalidateRect SendMessageW DefWindowProcW BeginPaint GetClientRect FillRect DrawTextW EndPaint FindWindowExW |
| GDI32.dll |
SetBkColor
GetDeviceCaps DeleteObject CreateBrushIndirect CreateFontIndirectW SetBkMode SetTextColor SelectObject |
| SHELL32.dll |
SHBrowseForFolderW
SHGetPathFromIDListW SHGetFileInfoW ShellExecuteW SHFileOperationW SHGetSpecialFolderLocation |
| ADVAPI32.dll |
RegEnumKeyW
RegOpenKeyExW RegCloseKey RegDeleteKeyW RegDeleteValueW RegCreateKeyExW RegSetValueExW RegQueryValueExW RegEnumValueW |
| COMCTL32.dll |
ImageList_AddMasked
ImageList_Destroy #17 ImageList_Create |
| ole32.dll |
CoTaskMemFree
OleInitialize OleUninitialize CoCreateInstance |
| VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueW |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0 |
| FileVersion | 13.0.1.2 |
| ProductVersion | 13.0.1.2 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| Comments | Photoshop for minimalists: no installation, no trash left behind. For additional details, visit http:\\portableXapps.blogspot.com |
| CompanyName | PortableXApps |
| FileDescription | Photoshop LITE Portable |
| FileVersion (#2) | 13.0.1.2 |
| InternalName | Photoshop LITE Portable |
| LegalCopyright | PortableXApps |
| LegalTrademarks | PortableXApps® 2012 |
| OriginalFilename | PhotoshopPortable.exe |
| ProductName | Photoshop LITE Portable |
| ProductVersion (#2) | 13.0.1.2 |
| Resource LangID | UNKNOWN |
|---|
| XOR Key | 0x38bf1a05 |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2008 SP1 build 30729) | 3 |
| Imports (VS2008 SP1 build 30729) | 17 |
| Total imports | 172 |
| C objects (VS2010 SP1 build 40219) | 12 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.