ntoskrnl.exe

NT Kernel & System

Microsoft Corporation

The Windows NT Operating System Kernel is a non-native library that is used by the OS loader for kernel initialization and provides various system services such as process and memory management, hardware virtualization within the kernal layer. It contains core Windows services such as the executive, memory manager, scheduler and cache manager. It is included with the Windows 7 OS.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
NT Kernel & System

 
Part of the Windows 7 Operating System

Version:
6.1.7600.16988 (win7_gdr.120401-1505)

MD5:
60ee49f30c83be031fa6c2cd6a2e9e71

SHA-1:
596e4dd3f15d57fd393e27e3844e2e936038b477

SHA-256:
b1e00ebf3efdbe8959a88ae54684398874d1c9121c840bc7fba4d7af8679c844

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/25/2024 6:31:32 PM UTC  (today)

File size:
3.7 MB (3,902,320 bytes)

Product version:
6.1.7600.16988

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ntkrnlmp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\ntoskrnl.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
2/14/2011 1:11:44 PM

Valid to:
5/14/2012 2:11:44 PM

Subject:
CN=Microsoft Windows, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Verification PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
61030556000000000010

File PE Metadata
Compilation timestamp:
4/1/2012 7:31:58 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
49152:q72NNarPKV6dyRJt5g61s7sVHih7waRxUymNLuRVKhh/G7lu+8qWe4EKOFTAs:VrazK4dC5gUs7UqUvZuRy/G7luJq+L25

Entry address:
0x1154F0

Entry point:
55, 8B, EC, 83, EC, 20, 8B, 5D, 08, 89, 1D, F4, F7, 55, 00, 8B, 0D, DC, F8, 55, 00, 89, 4D, E8, 0B, C9, 75, 3C, C7, 43, 34, 40, B2, 52, 00, C7, 43, 28, 00, F0, 51, 00, 0F, 01, 04, 24, 8B, 54, 24, 02, 83, C2, 30, 8D, 05, 00, 1C, 52, 00, 66, 89, 42, 02, C1, E8, 10, 88, 42, 04, 88, 62, 07, 66, C7, 02, 48, 37, 6A, 30, 0F, A1, 64, 89, 0D, EC, 04, 00, 00, 8B, 43, 34, 89, 45, E0, 8D, 48, 40, 89, 48, 40, 89, 48, 44, 8B, 43, 28, 89, 45, E4, E8, 7F, 92, 1F, 00, 83, 7D, E8, 00, 0F, 85, A2, 01, 00, 00, E8, FF, 02, 00...
 
[+]

Entropy:
6.3816

Developed / compiled with:
Microsoft Visual C++

Code size:
3.2 MB (3,369,984 bytes)