Gridinsoft Logo
File Icon

The RAMMap64.exe (RamMap - physical memory analyzer) File Analysis

Technical Analysis

File Name RAMMap64.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.217.174
Database Version 2025-06-02 17:00:18 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
362,896
File Size (bytes)
2025-06-02
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
633470671cc8035b945f7ccad2cd4024
SHA1
c3807ead9f2081d8d92bf25ec7fdb8a777c837d6
SHA256
f80852a5ab710dde6489760b3fba6907ba63a7d9704dd2fc58b387c472541bf0
SHA512
c89807e4af79afe5331a2f7a26c178a833eecee2c8c8cc380de01baec9cd1f647e13aa294887788ad87356da3278ebeeefb3dee0bd8f37f135479dd1c022ee33
ImpHash
602c1e41c152bfa37542e045c7a387c1

PE Analysis

Basic Information

Icon
Hash: a810bbfbdcaed0982c51fa7370d429f2
Fuzzy: 162007db970dcccb1bc04cbb1ee91ab3
dHash: 3838383838383838
Image Base 0x140000000
Entry Point 0x14001df00
Compilation Time 2022-05-06 22:42:36
Checksum 0x00063d33 (Actual: 0x00063d33)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path D:\a\1\s\x64\Release\RamMap64.pdb
Digital Signature OK
Imports 10 libraries
COMCTL32, VERSION, KERNEL32, USER32, GDI32, COMDLG32, ADVAPI32, SHELL32, ole32, OLEAUT32
Exports 0 functions
Resources 21 Resources
Sections 7 Sections

Version Information

CompanyName Sysinternals - www.sysinternals.com
FileDescription RamMap - physical memory analyzer
FileVersion 1.61
InternalName RamMap
LegalCopyright Copyright © 2010-2022 Mark Russinovich
OriginalFilename RamMap
ProductName RamMap
ProductVersion 1.61
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 219,550 bytes 219,648 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 1A7DE8F33C60C2384FF3328AECB611EB
.rdata 0x00037000 98,404 bytes 98,816 bytes 4.97 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3B34EC60C7B91F130EB9C07633CB8374
.data 0x00050000 11,396 bytes 4,096 bytes 2.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E8933B76A39F32CE387C933C9A92937F
.pdata 0x00053000 10,776 bytes 11,264 bytes 5.35 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7B76F9A4FE82DD14940421A6DEB65BE8
_RDATA 0x00056000 348 bytes 512 bytes 3.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EFF400110D1B60D885250513F95EFB1F
.rsrc 0x00057000 14,536 bytes 14,848 bytes 4.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 98E00E0A2400AFB2FA357A6B622D38F3
.reloc 0x0005b000 2,256 bytes 2,560 bytes 5.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 82C88A9E07080B29BB935EDB893313F2

Resource Analysis

Total Resources: 21 (12,952 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 1 308 bytes
2.4%
RT_ICON 3 3,832 bytes
29.6%
RT_MENU 1 522 bytes
4%
RT_DIALOG 9 5,310 bytes
41%
RT_ACCELERATOR 1 56 bytes
0.4%
RT_GROUP_CURSOR 1 20 bytes
0.2%
RT_GROUP_ICON 3 60 bytes
0.5%
RT_VERSION 1 792 bytes
6.1%
RT_MANIFEST 1 2,052 bytes
15.8%

Certificate Chain Analysis

Certificate Information
Product RamMap
Description RamMap - physical memory analyzer
File Version 1.61
Original Name RamMap
Signing Date 10:43 PM 05/06/2022 (1125 days ago)
Verification Status Signed
Signers Microsoft Corporation; Microsoft Code Signing PCA 2011; Microsoft Root Certificate Authority 2011
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name RamMap
Copyright Copyright © 2010-2022 Mark Russinovich
Certificate Chain Summary
Microsoft Corporation #1 Primary
Validity Period: 2021-09-02 18:32:59 → 2022-09-01 18:32:59
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 52 8B 33 AA F8 95 F3 39 DB 00 00 00 00 02 52
Microsoft Code Signing PCA 2011 #2 Chain
Validity Period: 2011-07-08 20:59:09 → 2026-07-08 21:09:09
Signature Algorithm: sha256RSA
Serial Number: 61 0E 90 D2 00 00 00 00 00 03
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2021-12-02 19:05:19 → 2023-02-28 19:05:19
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 9C 0F A6 4D 61 D2 9E 4B 28 00 01 00 00 01 9C
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware