ntkrnlpa.exe

NT Kernel & System

Microsoft Corporation

This is the image for the Windows NT Kernel with Physical Address Extension support and provides the kernel and executive layers responsible for various system services such as hardware virtualization, process and memory management. It is included with the Windows 7 OS.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
NT Kernel & System

 
Part of the Windows 7 Operating System

Version:
6.1.7600.20796 (win7_ldr.100908-1502)

MD5:
7f3517b59e88ce342a1bee4a102854fd

SHA-1:
487e4d594f0f708419e324ee0560da4eda988631

SHA-256:
6a0ff954f5e9824d097a7d482e98ee7d6824aabf7d6f79bb055ce70b2b88423e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/26/2024 12:31:39 AM UTC  (today)

File size:
3.8 MB (3,964,800 bytes)

Product version:
6.1.7600.20796

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ntkrpamp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\ntkrnlpa.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
12/7/2009 10:57:40 PM

Valid to:
3/7/2011 10:57:40 PM

Subject:
CN=Microsoft Windows, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Verification PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6115230F00000000000A

File PE Metadata
Compilation timestamp:
9/9/2010 4:23:12 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
98304:FH8ApezhTZo4fMaMk/m8I8iTth5KyFurwcvWI:FcBzhTZRfMaMk/m8+NdurwcvWI

Entry address:
0x11E4D8

Entry point:
55, 8B, EC, 83, EC, 20, 8B, 5D, 08, 89, 1D, 8C, 98, 56, 00, 8B, 0D, 6C, 99, 56, 00, 89, 4D, E8, 0B, C9, 75, 3C, C7, 43, 34, 80, 43, 53, 00, C7, 43, 28, 00, 80, 52, 00, 0F, 01, 04, 24, 8B, 54, 24, 02, 83, C2, 30, 8D, 05, 00, AC, 52, 00, 66, 89, 42, 02, C1, E8, 10, 88, 42, 04, 88, 62, 07, 66, C7, 02, 48, 37, 6A, 30, 0F, A1, 64, 89, 0D, EC, 04, 00, 00, 8B, 43, 34, 89, 45, E0, 8D, 48, 40, 89, 48, 40, 89, 48, 44, 8B, 43, 28, 89, 45, E4, E8, 47, C1, 1F, 00, 83, 7D, E8, 00, 0F, 85, A2, 01, 00, 00, E8, F7, 02, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.3 MB (3,430,400 bytes)