If you don't want to change to another form of padding, just append a single 1 byte to the end of the file contents, and on decryption, after removing any trailing nulls, then remove the appended 1 byte. You won't accidently remove any 0 bytes that belong to the file.