Gridinsoft Logo

The wow64.dll (Win32 Emulation on NT64) File Analysis

Technical Analysis

File Name wow64.dll
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.218.174
Database Version 2025-06-12 08:00:15 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
356,856
File Size (bytes)
2025-06-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c45a6973e4b061af76e4af24dce66f9c
SHA1
e3836620716ae9184479aed8ef2fec83063b6a09
SHA256
fa31bdeee3f78f6991759c3231d4be85ed1560783cae71461c33cc9efcaa2f1c
SHA512
b929fa1caca5d61dc35f982db0589ffebe36400ba436674c3fdccb6f05265e7b3777b8d0e08e683d79d2aa67afd61e0edd6ee578ac1303fab18811d6235cae3f
ImpHash
9ec74f73a25489f7c95d478a267312ab

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1800295f0
Compilation Time 2004-07-13 19:01:47
Checksum 0x0005d68d (Actual: 0x0005d68d)
OS Version 10.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
PDB Path wow64.pdb
Digital Signature OK
Imports 4 libraries
ntdll, wow64base, wow64win, wow64con
Exports 32 functions
Resources 1 Resources
Sections 8 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Win32 Emulation on NT64
FileVersion 10.0.26100.3912 (WinBuild.160101.0800)
InternalName wow64
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename wow64.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.26100.3912
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 225,702 bytes 229,376 bytes 6.14 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 76A9B264BDA0A2125329E267EE197FB0
fothk 0x00039000 4,096 bytes 4,096 bytes 0.02 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3DF7AEA7468F364A9B8C27FFD56E2EB0
.rdata 0x0003a000 72,942 bytes 73,728 bytes 5.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E71BFDFDC71AF60E689FF201BC5E4F91
.data 0x0004c000 4,780 bytes 4,096 bytes 0.23 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D8199C3D3698B8CD1F546BC62EE566C6
.pdata 0x0004e000 13,788 bytes 16,384 bytes 5.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1F6922310934D2D06B8F717C70AFA58C
.mrdata 0x00052000 512 bytes 4,096 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 620F0B67A91F7F74151BC5BE745B7110
.rsrc 0x00053000 1,008 bytes 4,096 bytes 1.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4C8220B709B784F508ED97E32E4D20E0
.reloc 0x00054000 1,476 bytes 4,096 bytes 2.74 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A30D016F794ECDC9A85BAED954B7D41E

Resource Analysis

Total Resources: 1 (908 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 908 bytes
100%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description Win32 Emulation on NT64
File Version 10.0.26100.3912 (WinBuild.160101.0800)
Original Name wow64.dll
Signing Date 04:32 AM 04/18/2025 (58 days ago)
Verification Status Signed
Signers Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name wow64
Copyright © Microsoft Corporation. All rights reserved.
Certificate Chain Summary
Microsoft Windows #1 Primary
Validity Period: 2025-02-20 19:52:57 → 2026-02-18 19:52:57
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 04 D6 D0 B9 9E FE CC F1 72 6A 00 00 00 00 04 D6
Microsoft Windows Production PCA 2011 #2 Chain
Validity Period: 2011-10-19 18:41:42 → 2026-10-19 18:51:42
Signature Algorithm: sha256RSA
Serial Number: 61 07 76 56 00 00 00 00 00 08
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2025-01-30 19:42:58 → 2026-04-22 19:42:58
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 0B 11 9D 56 29 92 F9 BF 85 00 01 00 00 02 0B
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware