File Name | ntdll.dll |
File Type |
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
Scanner Version | 1.0.223.174 |
Database Version | 2025-08-12 06:00:16 UTC |
No threats detected by our scanner
Hash Type | Value | Action |
---|---|---|
MD5 |
83525ca1286dd562776cee6c0cbac865
|
|
SHA1 |
826687ed88474b4cdd0e10dab47172c522a30e66
|
|
SHA256 |
62d4a18a152be2185738349963a8e82773d0807ca425383f63f9f24edc6a2ac3
|
|
SHA512 |
ace60180f0eab641a4ca1db40fec35c12d056f819b1e7879b458feda383450c80d864e35fca83a0035e8207ac078cb4e33995f5dd6945cd9a27781e2a9962363
|
Image Base | 0x180000000 |
Entry Point | 0x180000000 |
Compilation Time | 2049-08-17 04:36:40 |
Checksum | 0x00269eed (Actual: 0x00269eed) |
OS Version | 10.0 |
PEiD Signatures |
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
PDB Path | ntdll.pdb |
Digital Signature | OK |
Imports | 0 |
Exports | 2517 functions |
Resources | 3 Resources |
Sections | 15 Sections |
CompanyName | Microsoft Corporation |
FileDescription | NT Layer DLL |
FileVersion | 10.0.26100.4768 (WinBuild.160101.0800) |
InternalName | ntdll.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | ntdll.dll |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.26100.4768 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
1,489,868 bytes | 1,490,944 bytes | 6.46 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
232F27C4760E8B6F55C492FA5582BB01 |
SCPCFG |
0x0016d000 |
688 bytes | 4,096 bytes | 1.17 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
67CCCEE178515E155FCD1C234B05CEFB |
SCPCFGFP |
0x0016e000 |
688 bytes | 4,096 bytes | 0.64 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8FCEF62B1133CD6485B86A5A8E1316DE |
SCPCFGNP |
0x0016f000 |
688 bytes | 4,096 bytes | 0.55 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
73224907CFBB1B7C3C40015757DC4650 |
SCPCFGES |
0x00170000 |
688 bytes | 4,096 bytes | 1.18 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
9EB4914124C1E80DE1AD638F87B5DA9D |
RT |
0x00171000 |
444 bytes | 4,096 bytes | 1.07 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B11A10280A3460EA1B71E110A759F0E1 |
PAGE |
0x00172000 |
2,243 bytes | 4,096 bytes | 4.22 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B3BBD96C18F2CB4A8B223CC0C530D18A |
fothk |
0x00173000 |
4,096 bytes | 4,096 bytes | 0.05 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E5178E6E990460B7C036E6F5E3838492 |
.rdata |
0x00174000 |
363,263 bytes | 364,544 bytes | 6.20 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
832754BA1D1A962FE800C12E85414080 |
.data |
0x001cd000 |
36,800 bytes | 8,192 bytes | 1.53 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
987CFC39F8C7EDAE57CE300896835D49 |
.pdata |
0x001d6000 |
68,520 bytes | 69,632 bytes | 6.12 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B5B41ED7AFA36C413746DCCF42150B94 |
.mrdata |
0x001e7000 |
13,736 bytes | 16,384 bytes | 0.24 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BA6C4BD9133194C161DE77E55092927F |
.00cfg |
0x001eb000 |
40 bytes | 4,096 bytes | 0.06 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
9FA5C887488FB0DD1B553AE0C464C346 |
.rsrc |
0x001ec000 |
497,848 bytes | 499,712 bytes | 3.34 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
20C7ABE1DA9AAD50BE85189A4043784E |
.reloc |
0x00266000 |
2,100 bytes | 4,096 bytes | 3.48 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
45189765428724AA54EC8702CC5D2307 |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
MUI | 1 | 200 bytes | |
RT_MESSAGETABLE | 1 | 496,512 bytes | |
RT_VERSION | 1 | 896 bytes |
Product | Microsoft® Windows® Operating System |
Description | NT Layer DLL |
File Version | 10.0.26100.4768 (WinBuild.160101.0800) |
Original Name | ntdll.dll |
Signing Date | 11:44 PM 07/15/2025 (29 days ago) |
Verification Status | Signed |
Signers | Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010 |
Counter Signers | Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010 |
Internal Name | ntdll.dll |
Copyright | © Microsoft Corporation. All rights reserved. |
33 00 00 04 D6 D0 B9 9E FE CC F1 72 6A 00 00 00 00 04 D6
61 07 76 56 00 00 00 00 00 08
33 00 00 01 FE D0 A8 C2 7B 34 21 0B 01 00 01 00 00 01 FE
33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important