ntkrnlpa.exe

NT Kernel & System

Microsoft Corporation

This is the image for the Windows NT Kernel with Physical Address Extension support and provides the kernel and executive layers responsible for various system services such as hardware virtualization, process and memory management. It is included with the Windows 7 OS.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
NT Kernel & System

 
Part of the Windows 7 Operating System

Version:
6.1.7600.20881 (win7_ldr.110114-1504)

MD5:
20807845f371e2c47c44779bbbdde9d7

SHA-1:
4eae2c5987745dbc506dd91b5b7de0e2e9abff0c

SHA-256:
8e16f8512b85f3d3379a616fe27f63e85d634b318328e3fac5afaf34146a589c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/23/2024 1:32:26 PM UTC  (today)

File size:
3.8 MB (3,966,848 bytes)

Product version:
6.1.7600.20881

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ntkrpamp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\ntkrnlpa.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
12/7/2009 2:57:40 PM

Valid to:
3/7/2011 2:57:40 PM

Subject:
CN=Microsoft Windows, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Verification PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6115230F00000000000A

File PE Metadata
Compilation timestamp:
1/14/2011 8:22:37 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
98304:Ox5KPEraDnhJNY7gXNanv6UBi17tFi1TuM2zzLbAF:OfiEr2nhJNYUXN4v6UBkvMuM2z7K

Entry address:
0x11E4D8

Entry point:
55, 8B, EC, 83, EC, 20, 8B, 5D, 08, 89, 1D, 8C, 98, 56, 00, 8B, 0D, 6C, 99, 56, 00, 89, 4D, E8, 0B, C9, 75, 3C, C7, 43, 34, 80, 43, 53, 00, C7, 43, 28, 00, 80, 52, 00, 0F, 01, 04, 24, 8B, 54, 24, 02, 83, C2, 30, 8D, 05, 00, AC, 52, 00, 66, 89, 42, 02, C1, E8, 10, 88, 42, 04, 88, 62, 07, 66, C7, 02, 48, 37, 6A, 30, 0F, A1, 64, 89, 0D, EC, 04, 00, 00, 8B, 43, 34, 89, 45, E0, 8D, 48, 40, 89, 48, 40, 89, 48, 44, 8B, 43, 28, 89, 45, E4, E8, 47, D1, 1F, 00, 83, 7D, E8, 00, 0F, 85, A2, 01, 00, 00, E8, F7, 02, 00...
 
[+]

Entropy:
6.3914

Developed / compiled with:
Microsoft Visual C++

Code size:
3.3 MB (3,431,936 bytes)