64-bit
zip / exemachine scopegithub.com · known platform- File name
- paint.net.5.1.12.install.x64.zip
- SHA-256
- 3cd861b5af3f85bd28666d4a9017d03de237c08ad0103ee9d92b2cd921f8c867
- Silent install
- /auto
- Product code
- {B33D3774-736A-43FD-BE83-76733BE4CB10}
by dotPDN LLC · Proprietary (Freeware)
An image and photo editing software for PCs that run Windows.
These URLs are the ones dotPDN LLC declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
More than one architecture below. Check which one your Windows is if you are not sure.
Run this against the file on disk. If the output does not match the hash below, the file is not what dotPDN LLC published. Delete it.
Windows · PowerShell
Get-FileHash "paint.net.5.1.12.install.x64.zip" -Algorithm SHA256macOS · Linux
shasum -a 256 "paint.net.5.1.12.install.x64.zip"Expected output
3cd861b5af3f85bd28666d4a9017d03de237c08ad0103ee9d92b2cd921f8c867
Got a different hash, or one you cannot place? Paste it into the hash checker and it will tell you which program and version it belongs to, past releases included.
The unattended switch below is the one dotPDN LLC declares in the installer manifest, not one we guessed by trying flags.
64-bit · machine scope · publisher-declared
.\paint.net.5.1.12.install.x64.zip /autoARM64 · machine scope · publisher-declared
.\paint.net.5.1.12.install.arm64.zip /autoRun it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
Silent install commands for every program we index · silent uninstall
Every guide on this tells you to hunt for the product code with Get-WmiObject or in the registry. You do not need to: it is published in the installer manifest, and it is printed below.
Product code · 64-bit
{B33D3774-736A-43FD-BE83-76733BE4CB10}
Uninstall, with the usual prompts
msiexec /x {B33D3774-736A-43FD-BE83-76733BE4CB10}Silent, for deployment
msiexec /x {B33D3774-736A-43FD-BE83-76733BE4CB10} /qn /norestartProduct code · 64-bit
{C6A29A65-A91B-4F4A-A1B5-B904AC61255D}
Uninstall, with the usual prompts
msiexec /x {C6A29A65-A91B-4F4A-A1B5-B904AC61255D}Silent, for deployment
msiexec /x {C6A29A65-A91B-4F4A-A1B5-B904AC61255D} /qn /norestartProduct code · ARM64
{EBCFDABF-C60D-4836-964E-C5A4AF13E0B2}
Uninstall, with the usual prompts
msiexec /x {EBCFDABF-C60D-4836-964E-C5A4AF13E0B2}Silent, for deployment
msiexec /x {EBCFDABF-C60D-4836-964E-C5A4AF13E0B2} /qn /norestartProduct code · ARM64
{9EA84436-3387-48B6-916C-3968083BB6E1}
Uninstall, with the usual prompts
msiexec /x {9EA84436-3387-48B6-916C-3968083BB6E1}Silent, for deployment
msiexec /x {9EA84436-3387-48B6-916C-3968083BB6E1} /qn /norestartThe codes above belong to paint.net 5.1.12, the version in our index. If you have an older release installed, its code is different and this command will report that the product is not installed. In that case run Get-Package -Name "paint.net*" in PowerShell to read the code of what you actually have.
This removes the program as the publisher packaged it. Settings and files created after installation, typically under AppData, are deliberately left behind by the uninstaller and have to be deleted by hand if you want them gone.
Reinstalling and hitting error 1638? That is this same product code, and the command above is the fix.
Product codes for every program we index, with the msiexec switches and how to read the code off your own machine.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 6 of 6 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 6 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 6 of 6 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 5 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | Proprietary (Freeware)A declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions paint.net registers itself to handle.
The installer comes from a recognised distribution platform rather than dotPDN LLC's own domain. That is normal for this kind of software and not a red flag by itself.
Every one of the 6 installers on this page comes with the SHA-256 dotPDN LLC declared, so you do not have to take our word for it: hash the file you downloaded and compare.
What this does not tell you is whether the software itself is any good, or whether you want what it does once installed. A publisher can ship something you would rather not run and the download is still authentic. We answer the question we can measure and leave the other one to you.
If Windows says “Windows protected your PC” when you run it, that is SmartScreen reporting reputation, not a malware verdict — it shows up on perfectly legitimate software from small publishers and on releases that are simply new. The reverse matters more: no warning does not mean the file was checked.
How the 95/100 score is calculated · why the source matters more than the reputation
Windows ships with a package manager, and this program is in it. The identifier below is the one Microsoft's repository uses, which is also where the download URL and hash on this page come from.
Install
winget install --id dotPDN.PaintDotNet --exactUpgrade later
winget upgrade --id dotPDN.PaintDotNetWhy --exact: without it winget matches on name as well as identifier, and a search that returns more than one package makes it stop and ask rather than install. Pinning the identifier is what makes the command safe to put in a script.
Not installing anything, or getting an error back? The commands that actually come up covers upgrading everything at once, what --include-unknown is for, and why winget can be missing from a machine that should have it.
The version history of paint.net, each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
4B246EF2A05CE29BD54E448DDC6636C93C36F37841E453DFBEF6D780CDB52F3E
2678C868B920C524EF29F4EDE815DE05ABCD8F4CA122419E9D8E486630E18B7F
29E52F6888FBDEE4368491E366CAA935B0D51E585C84D7F2BE87F31CF038E40A
D03E4650F50E2D37D96D553EBB2457412ACAB0209AD2D33597F1534C1AD9C4A7
D865B98192E5B78125508048B7DD809B7493AAD8FE2ADC925D3EA52113362441
426517ED8A55D5EB3B0FA7DB79598C822579ED758DFD37B390AC5CE6AFAE0FC6
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published.
Every paint.net version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.
Matched on the categories dotPDN LLC and others declare in their own manifests, so the grouping is theirs rather than ours. Each one has its official URL and hash on the same terms as this page.
Not related to paint.net — just other entries, each with its own official URL and published hash.