Gridinsoft Logo

The ntdll.dll (NT Layer DLL) File Analysis

Technical Analysis

File Name ntdll.dll
File Type
PE32+ executable (DLL) (console) x86-64, for MS Windows
Scanner Version 1.0.223.174
Database Version 2025-08-12 06:00:16 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
2,522,016
File Size (bytes)
2025-08-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
83525ca1286dd562776cee6c0cbac865
SHA1
826687ed88474b4cdd0e10dab47172c522a30e66
SHA256
62d4a18a152be2185738349963a8e82773d0807ca425383f63f9f24edc6a2ac3
SHA512
ace60180f0eab641a4ca1db40fec35c12d056f819b1e7879b458feda383450c80d864e35fca83a0035e8207ac078cb4e33995f5dd6945cd9a27781e2a9962363

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x180000000
Compilation Time 2049-08-17 04:36:40
Checksum 0x00269eed (Actual: 0x00269eed)
OS Version 10.0
PEiD Signatures PE32+ executable (DLL) (console) x86-64, for MS Windows
PDB Path ntdll.pdb
Digital Signature OK
Imports 0
Exports 2517 functions
Resources 3 Resources
Sections 15 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription NT Layer DLL
FileVersion 10.0.26100.4768 (WinBuild.160101.0800)
InternalName ntdll.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename ntdll.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.26100.4768
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,489,868 bytes 1,490,944 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 232F27C4760E8B6F55C492FA5582BB01
SCPCFG 0x0016d000 688 bytes 4,096 bytes 1.17 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 67CCCEE178515E155FCD1C234B05CEFB
SCPCFGFP 0x0016e000 688 bytes 4,096 bytes 0.64 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 8FCEF62B1133CD6485B86A5A8E1316DE
SCPCFGNP 0x0016f000 688 bytes 4,096 bytes 0.55 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 73224907CFBB1B7C3C40015757DC4650
SCPCFGES 0x00170000 688 bytes 4,096 bytes 1.18 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9EB4914124C1E80DE1AD638F87B5DA9D
RT 0x00171000 444 bytes 4,096 bytes 1.07 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ B11A10280A3460EA1B71E110A759F0E1
PAGE 0x00172000 2,243 bytes 4,096 bytes 4.22 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ B3BBD96C18F2CB4A8B223CC0C530D18A
fothk 0x00173000 4,096 bytes 4,096 bytes 0.05 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ E5178E6E990460B7C036E6F5E3838492
.rdata 0x00174000 363,263 bytes 364,544 bytes 6.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 832754BA1D1A962FE800C12E85414080
.data 0x001cd000 36,800 bytes 8,192 bytes 1.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 987CFC39F8C7EDAE57CE300896835D49
.pdata 0x001d6000 68,520 bytes 69,632 bytes 6.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B5B41ED7AFA36C413746DCCF42150B94
.mrdata 0x001e7000 13,736 bytes 16,384 bytes 0.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BA6C4BD9133194C161DE77E55092927F
.00cfg 0x001eb000 40 bytes 4,096 bytes 0.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9FA5C887488FB0DD1B553AE0C464C346
.rsrc 0x001ec000 497,848 bytes 499,712 bytes 3.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 20C7ABE1DA9AAD50BE85189A4043784E
.reloc 0x00266000 2,100 bytes 4,096 bytes 3.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 45189765428724AA54EC8702CC5D2307

Resource Analysis

Total Resources: 3 (497,608 bytes)
Resource Type Count Total Size Percentage
MUI 1 200 bytes
0%
RT_MESSAGETABLE 1 496,512 bytes
99.8%
RT_VERSION 1 896 bytes
0.2%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description NT Layer DLL
File Version 10.0.26100.4768 (WinBuild.160101.0800)
Original Name ntdll.dll
Signing Date 11:44 PM 07/15/2025 (29 days ago)
Verification Status Signed
Signers Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name ntdll.dll
Copyright © Microsoft Corporation. All rights reserved.
Certificate Chain Summary
Microsoft Windows #1 Primary
Validity Period: 2025-02-20 19:52:57 → 2026-02-18 19:52:57
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 04 D6 D0 B9 9E FE CC F1 72 6A 00 00 00 00 04 D6
Microsoft Windows Production PCA 2011 #2 Chain
Validity Period: 2011-10-19 18:41:42 → 2026-10-19 18:51:42
Signature Algorithm: sha256RSA
Serial Number: 61 07 76 56 00 00 00 00 00 08
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2024-07-25 18:31:18 → 2025-10-22 18:31:18
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 FE D0 A8 C2 7B 34 21 0B 01 00 01 00 00 01 FE
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware