Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.2.9200.16384 (win8_rtm.120725-1247) 7.14%
6.1.7600.16385 (win7_rtm.090713-1255) 35.71%
6.1.7600.16385 (win7_rtm.090713-1255) 7.14%
6.0.6000.16386 (vista_rtm.061101-2205) 14.29%
6.0.6000.16386 (vista_rtm.061101-2205) 7.14%
6.0.6000.16386 (vista_rtm.061101-2205) 14.29%
6.0.6000.16386 (vista_rtm.061101-2205) 7.14%
5.1.2600.5512 (xpsp.080413-2105) 7.14%

Relationships

Parent processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
DecryptFileW, EncryptFileW, EventWrite, EventRegister, EventUnregister, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, SetNamedSecurityInfoW, GetNamedSecurityInfoW, CloseServiceHandle, QueryServiceConfigW, OpenServiceW, OpenSCManagerW, RegQueryInfoKeyW, RegGetValueW, RegEnumValueW, RegDeleteKeyW, RegEnumKeyExW, RegOpenKeyExA, RegOpenKeyW, RegEnumKeyW, RegQueryValueExA
comctl32.dll
ImageList_Draw, ImageList_ReplaceIcon, ImageList_Remove, PropertySheetW, CreatePropertySheetPageW, ImageList_GetImageCount
comdlg32.dll
GetOpenFileNameW, GetFileTitleW, GetSaveFileNameW, CommDlgExtendedError
gdi32.dll
Polygon, GetTextFaceW, GdiGradientFill, GetTextExtentPoint32W, CreateFontW, Polyline, CreatePolygonRgn, SetROP2, GetTextMetricsW, TranslateCharsetInfo, StretchDIBits, CreateDCW, CreateFontIndirectW, SetStretchBltMode, ExtSelectClipRgn, GetBrushOrgEx, GetRgnBox, CombineRgn, CreateRectRgn, ExtFloodFill, SetBrushOrgEx, UnrealizeObject, GetPixel, MoveToEx, LineTo, SetPixel, CreateDIBSection, CreatePen, SetDIBitsToDevice, CreateDIBitmap, GetDIBits, CreateHalftonePalette, StretchBlt, EnumFontFamiliesExW, OffsetRgn, GetNearestColor, CreatePalette, SetViewportExtEx, PlayMetaFile, SaveDC, SetMapMode, LPtoDP, GetDeviceCaps, CreateCompatibleBitmap, CreateCompatibleDC, RealizePalette, BitBlt, DeleteDC, SelectPalette, SelectObject, DeleteObject, SetDIBits, CreateBitmap, GetPaletteEntries, SetPaletteEntries, GetNearestPaletteIndex, ResizePalette, CreateSolidBrush, CreatePatternBrush, GetObjectW, GetCurrentObject, GetDIBColorTable, SetTextColor, SetBkColor, CreateRectRgnIndirect, FillRgn, PatBlt, GetStockObject, SetDIBColorTable, GdiAlphaBlend, Rectangle, RestoreDC, SetBkMode, SetTextAlign, ExtTextOutW, CreateICW, RoundRect, PtVisible, RectVisible, TextOutW, Escape, GetBkMode, GetTextColor, EnumFontFamiliesW, PolyBezier, Ellipse
imm32.dll
ImmGetCompositionStringW, ImmGetCompositionWindow, ImmGetContext, ImmSetCompositionWindow, ImmReleaseContext, ImmAssociateContext, ImmNotifyIME
kernel32.dll
GetModuleFileNameW, CreateThread, GetCurrentProcess, IsWow64Process, Wow64DisableWow64FsRedirection, Wow64RevertWow64FsRedirection, FreeLibraryAndExitThread, InterlockedExchange, GetVersionExW, HeapFree, GetProcessHeap, HeapAlloc, GetExitCodeThread, GlobalReAlloc, GetTempPathW, MoveFileExW, CopyFileW, DeleteFileW, GetACP, GetModuleHandleA, HeapSetInformation, LoadLibraryW, FreeLibrary, GetTickCount, lstrcmpiW, GetProcAddress, InterlockedDecrement, GetThreadLocale, InterlockedIncrement, DeleteCriticalSection, SetEndOfFile, FindFirstFileW, GlobalAddAtomW, GlobalDeleteAtom, LocalAlloc, LocalFree, SetErrorMode, GetFileSize, FileTimeToLocalFileTime, FileTimeToSystemTime, GetDateFormatW, GetTimeFormatW, GetLocaleInfoW, lstrlenW, MulDiv, CloseHandle, GetFileSizeEx, CreateFileW, FormatMessageW, GetModuleHandleW, GlobalAlloc, GlobalFree, GlobalUnlock, GlobalLock, GetFileTime, GetFileAttributesW, DeviceIoControl, SetFileTime, GetLastError, SetFileAttributesW, FindClose, WriteFile, ReadFile, WideCharToMultiByte, MultiByteToWideChar, Sleep, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, InterlockedCompareExchange, GetStartupInfoW, OutputDebugStringA, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, WaitForSingleObject, ReleaseMutex, CreateMutexW, lstrcmpW, ApplicationRecoveryInProgress, ApplicationRecoveryFinished, RegisterApplicationRecoveryCallback, RegisterApplicationRestart, CompareFileTime, FindFirstStreamW, FindNextStreamW, RaiseException, LoadLibraryA, GetTempFileNameW, GetSystemTime, SystemTimeToFileTime, TerminateThread, IsDBCSLeadByte, lstrcpyW, lstrcpynW, GetCommandLineW, lstrlenA, CreateDirectoryW, GetNumberFormatW, lstrcatW
mfc42u.dll
DllMain
msvcrt.dll
DllMain
ntdll.dll
RtlInitUnicodeString, NtQueryLicenseValue, WinSqmIncrementDWORD, WinSqmStartSession, WinSqmEndSession, WinSqmAddToStream, WinSqmSetIfMaxDWORD
ole32.dll
PropVariantCopy, CreateStreamOnHGlobal, CoInitialize, CoUninitialize, CoMarshalInterThreadInterfaceInStream, PropVariantClear, CoTaskMemFree, CLSIDFromString, CoCreateInstance, WriteClassStg, WriteFmtUserTypeStg, OleGetClipboard, ReleaseStgMedium, FreePropVariantArray, CoGetInterfaceAndReleaseStream
propsys.dll
PropVariantToUInt32, PropVariantToString, PropVariantToUInt32WithDefault
rpcrt4.dll
UuidCreate, RpcStringFreeW, UuidToStringW
shell32.dll
SHChangeNotify, SHAddToRecentDocs, DragFinish, DragQueryFileW, ShellAboutW, SHGetFolderPathEx, SHParseDisplayName, SHCreateShellItem, ShellExecuteExW, SHGetFolderPathW, SHGetSpecialFolderPathW, SHBindToParent, CommandLineToArgvW
shlwapi.dll
SHStrDupW, PathStripPathW
user32.dll
IsWindowVisible, LoadIconW, GetClassInfoW, GetMonitorInfoW, MonitorFromRect, DestroyMenu, PostQuitMessage, LoadImageW, SystemParametersInfoW, RegisterTouchWindow, UnregisterTouchWindow, GetMenu, IsMenu, SetWindowLongW, LoadBitmapW, CheckMenuItem, GetSubMenu, RemoveMenu, GetUpdateRect, ValidateRect, RedrawWindow, GetCaretPos, GetTouchInputInfo, ShowCursor, CloseTouchInputHandle, GetMessageExtraInfo, GetWindowLongW, GetKeyboardLayout, SetPropW, GetParent, GetFocus, SetGestureConfig, FindWindowW, GetSystemMenu, PostMessageW, GetWindowDC, SetClassLongW, LoadStringW, EnableScrollBar, MsgWaitForMultipleObjectsEx, DestroyIcon, GetSysColor, GetWindowRect, GetClientRect, ScreenToClient, UpdateWindow, InvalidateRect, EnableWindow, SendMessageW, SetCapture, SetActiveWindow, ClientToScreen, BringWindowToTop, TrackMouseEvent, ReleaseCapture, LoadCursorW, SetCursor, InflateRect, CopyRect, KillTimer, SetTimer, EqualRect, SetRectEmpty, IsRectEmpty, GetKeyState, GetCursorPos, GetCapture, WindowFromPoint, UnionRect, GetDC, IntersectRect, PtInRect, RegisterClipboardFormatW, OffsetRect, FillRect, IsClipboardFormatAvailable, LoadMenuW, GetSystemMetrics, IsWindow, SetRect, MessageBeep, PeekMessageW, MessageBoxW, SetWindowTextW, ReleaseDC, SetForegroundWindow, GetAncestor, SetWindowPos, DestroyCursor, SendDlgItemMessageW, CheckDlgButton, SetDlgItemInt, GetDlgItemInt, GetDlgItem, DestroyCaret, CreateCaret, ShowCaret, MsgWaitForMultipleObjects, TranslateMessage, DispatchMessageW, DestroyWindow, wsprintfW, wvsprintfW, DrawFocusRect, WinHelpW, FrameRect, CharNextW, GetDesktopWindow, HideCaret, EnableMenuItem, TabbedTextOutW, DrawTextW, GrayStringW, BeginPaint, EndPaint, GetWindow, SetCaretPos
version.dll
GetFileVersionInfoExW, VerQueryValueW, GetFileVersionInfoSizeExW
winmm.dll
timeGetTime

mspaint.exe

Paint by Microsoft

Remove mspaint.exe
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   e97295de2a9fde547feab4fe41df16ca
SHA1:   de87c513e32b4b72edd990b93c8854205f634771
SHA256:   0ed49ca80d2a71a7be4905a8a1042f25b0bd4f87da9c63dd8bb4949e18b51cf6
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

mspaint.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. This version is designed to run on Windows 7 and is compiled as a 32 bit program.

DetailsDetails

File name:mspaint.exe
Publisher:Microsoft Corporation
Product name:Paint
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\mspaint.exe
Original name:MSPAINT.EXE.MUI
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:6.08 MB (6,376,960 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:5.846429
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Approved shell extension
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
  • CLSID: {d3e34b21-9d75-101a-8c3d-00aa001a1652}

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.42591322%
0.028634%
Kernel CPU:0.09402756%
0.013761%
User CPU:0.33188566%
0.014873%
Kernel CPU time:36,647 ms/min
100,923,805ms/min
CPU cycles:39,551/sec
17,470,203/sec
Memory
Private memory:22.32 MB
21.59 MB
Private (maximum):40.83 MB
Private (minimum):21.63 MB
Non-paged memory:22.32 MB
21.59 MB
Virtual memory:126.65 MB
140.96 MB
Virtual memory (peak):146.32 MB
169.69 MB
Working set:30.9 MB
18.61 MB
Working set (peak):37.65 MB
37.95 MB
Page faults:29,173/min
2,039/min
I/O
I/O read transfer:0 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:3 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:8
12
Handles:243
600
GUI GDI count:485
103
GUI GDI peak:532
142
GUI USER count:83
49
GUI USER peak:123
71

BehaviorsProcess properties

Integrety level:High
Platform:32-bit
Command lines:
  • "C:\Windows\System32\mspaint.exe"
  • "C:\Windows\System32\mspaint.exe" "C:\users\computech\downloads\259913_127470977409889_1155527598_n - copie.jpg"
  • C:\Windows\System32\mspaint.exe
  • "C:\Windows\System32\mspaint.exe" "C:\users\user\desktop\aaa10.bmp"
Owner:User
Parent processes:

ResourcesThreads

Averages
 
mspaint.exe (main module)
Total CPU:0.00778067%
0.272967%
Kernel CPU:0.00493141%
0.107585%
User CPU:0.00284926%
0.165382%
CPU cycles:122,328/sec
5,741,424/sec
Memory:6.09 MB
1.16 MB
gdiplus.dll
Total CPU:0.00021917%
Kernel CPU:0.00021917%
User CPU:0.00000000%
CPU cycles:1,474/sec
Memory:1.56 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 28.57%
Windows Vista Ultimate 21.43%
Windows 7 Home Premium 7.14%
Windows 8 7.14%
Microsoft Windows XP 7.14%
Windows Vista Home Premium 7.14%
Windows Server 2008 Standard 7.14%
Windows Vista™ Home Premium 7.14%
Windows 7 Professional 7.14%

Distribution by countryDistribution by country

United States installs about 37.50% of Paint.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 40.00%
Dell 40.00%
Hewlett-Packard 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE