ntoskrnl.exe

NT Kernel & System

Microsoft Corporation

The Windows NT Operating System Kernel is a non-native library that is used by the OS loader for kernel initialization and provides various system services such as process and memory management, hardware virtualization within the kernal layer. It contains core Windows services such as the executive, memory manager, scheduler and cache manager. It is included with the Windows 7 OS.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
NT Kernel & System

 
Part of the Windows 7 Operating System

Version:
6.1.7600.20881 (win7_ldr.110114-1504)

MD5:
68632f25d4a92b6c12bdd8d5e447c0d6

SHA-1:
cacb459f9479b141a7f828effed6d105b1284a74

SHA-256:
03ba77165590668d744b037392bccf330804ea949e55c9b5263620f7470b3452

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/27/2024 4:18:42 AM UTC  (today)

File size:
3.7 MB (3,911,552 bytes)

Product version:
6.1.7600.20881

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ntkrnlmp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\ntoskrnl.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
12/7/2009 2:57:40 PM

Valid to:
3/7/2011 2:57:40 PM

Subject:
CN=Microsoft Windows, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Verification PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6115230F00000000000A

File PE Metadata
Compilation timestamp:
1/14/2011 8:22:19 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
98304:hpsjc4r1Z51xV8tQocypOFXm0O/XDyuAYu3dFr:7oc4r1ZxV8tNcyIW0QOuAYutN

Entry address:
0x1164D8

Entry point:
55, 8B, EC, 83, EC, 20, 8B, 5D, 08, 89, 1D, F4, 07, 56, 00, 8B, 0D, DC, 08, 56, 00, 89, 4D, E8, 0B, C9, 75, 3C, C7, 43, 34, 40, C3, 52, 00, C7, 43, 28, 00, 00, 52, 00, 0F, 01, 04, 24, 8B, 54, 24, 02, 83, C2, 30, 8D, 05, 00, 2C, 52, 00, 66, 89, 42, 02, C1, E8, 10, 88, 42, 04, 88, 62, 07, 66, C7, 02, 48, 37, 6A, 30, 0F, A1, 64, 89, 0D, EC, 04, 00, 00, 8B, 43, 34, 89, 45, E0, 8D, 48, 40, 89, 48, 40, 89, 48, 44, 8B, 43, 28, 89, 45, E4, E8, 97, 92, 1F, 00, 83, 7D, E8, 00, 0F, 85, A2, 01, 00, 00, E8, F7, 02, 00...
 
[+]

Entropy:
6.3756

Developed / compiled with:
Microsoft Visual C++

Code size:
3.2 MB (3,378,688 bytes)