Should I block it?
No, this file is 100% safe to run.
Additional versions
Relationships
Parent process
Child process
Related files
PE file structure |
Show functions |
Import table
advapi32.dll
RegQueryValueExW, RegCloseKey, RegOpenKeyExW
kernel32.dll
FreeLibrary, GetProcAddress, LoadLibraryW, LoadLibraryExW, GetSystemDirectoryW, GetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetStartupInfoA, InterlockedCompareExchange, Sleep, InterlockedExchange, GetModuleHandleW, GetProcessHeap, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, VirtualProtect, IsDebuggerPresent
msvcr80.dll
DllMain
Export table
DllGetLCID
wdCommandDispatch
wdGetApplicationObject
WinWord.exe
2007 Microsoft Office system by Microsoft Corporation (Signed)
Version: | 12.0.6683.5002 |
MD5: | 59588aa5ddcb31b8155d49fe11987a69 |
SHA1: | 21940d127f0bbb8335df713fb0a0b7ee34ff718d |
SHA256: | 4e8a791e146af9562bd12ed886653e5ee20d552606fb28f98570c9b8dc79b1f6 |
What is WinWord.exe?
Microsoft Word is a commercial word processor designed by Microsoft. Microsoft Word is currently the most common word processor on the market.
About WinWord.exe (from Microsoft Corporation)
“Create documents with enhanced features that help you create, edit, and access documents from almost anywhere.”
Overview
winword.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. The file is digitally signed by Microsoft Corporation.
Details
File name: | winword.exe |
Publisher: | Microsoft Corporation |
Product name: | 2007 Microsoft Office system |
Description: | Microsoft Office Word |
Typical file path: | C:\Program Files\microsoft office\office12\winword.exe |
File version: | 12.0.6683.5002 |
Size: | 400.17 KB (409,776 bytes) |
Build date: | 8/14/2013 12:46 PM |
Certificate |
Issued to: | Microsoft Corporation |
Authority (CA): | Microsoft Corporation |
Effective date: | Wednesday, August 22, 2007 |
Expiration date: | Sunday, February 22, 2009 |
Digital DNA |
PE subsystem: | Windows GUI |
Entropy: | 5.803459 |
File packed: | No |
Code language: | Microsoft Visual C++ 8.0 |
.NET CLR: | No |
More details
Behaviors
Shell open commands
Scheduled tasks
- The task '{90C7B17E-11F4-4A18-8680-9A319C34FAE0}' runs on registration in the path '\{90C7B17E-11F4-4A18-8680-9A319C34FAE0}'
- Entry path '\{5983F4DC-5421-41A5-B761-3896EAB58128}'
Network connections
[UDP] listens on port 56644
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.21499252% | |
Kernel CPU: | 0.09976484% | |
User CPU: | 0.11522769% | |
Kernel CPU time: | 838,088 ms/min | |
CPU cycles: | 17,626,517/sec | |
Context switches: | 113/sec | |
Memory |
Private memory: | 44.06 MB | |
Private (maximum): | 74.02 MB | |
Private (minimum): | 23.09 MB | |
Non-paged memory: | 44.06 MB | |
Virtual memory: | 364.56 MB | |
Virtual memory (peak): | 390 MB | |
Working set: | 39.01 MB | |
Working set (peak): | 76.29 MB | |
Page faults: | 1,808,769/min | |
I/O |
I/O read transfer: | 22.94 KB/sec | |
I/O read operations: | 86/sec | |
I/O write transfer: | 11.82 KB/sec | |
I/O write operations: | 4/sec | |
I/O other transfer: | 16.9 KB/sec | |
I/O other operations: | 332/sec | |
Resource allocations |
Threads: | 12 | |
Handles: | 890 | |
GUI GDI count: | 496 | |
GUI GDI peak: | 678 | |
GUI USER count: | 122 | |
GUI USER peak: | 265 | |
Process properties
Integrety level: | Medium |
Platform: | 64-bit |
Command lines: |
- "C:\Program Files\microsoft office\office12\winword.exe" /n /dde
- "C:\Program Files\microsoft office\office12\winword.exe" /n /dde
- "C:\programs\word tools\ms ofc 2007\office12\winword.exe"
|
Owner: | User |
Parent process: | explorer.exe (Windows Explorer by Microsoft Corporation) |
Threads
Averages
WINWORD.EXE (main module) |
Total CPU: | 0.69592573% | |
Kernel CPU: | 0.07878683% | |
User CPU: | 0.61713890% | |
CPU cycles: | 15,550,203/sec | |
Context switches: | 2/sec | |
Memory: | 408 KB | |
ntdll.dll |
Total CPU: | 0.00561364% | |
Kernel CPU: | 0.00560664% | |
User CPU: | 0.00000700% | |
CPU cycles: | 8,859/sec | |
Memory: | 1.66 MB | |
wow64.dll |
Total CPU: | 0.00023123% | |
Kernel CPU: | 0.00015415% | |
User CPU: | 0.00007708% | |
CPU cycles: | 3,435/sec | |
Memory: | 252 KB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
27.00% |
|
Windows 7 Ultimate |
25.00% |
|
Microsoft Windows XP |
13.50% |
|
Windows Vista Home Premium |
8.50% |
|
Windows 7 Professional |
7.00% |
|
Windows 8.1 |
4.50% |
|
Windows 7 Home Basic |
3.50% |
|
Windows 8 |
3.00% |
|
Windows 8 Pro |
2.50% |
|
Windows Vista Home Basic |
1.50% |
|
Windows 8 Single Language |
1.00% |
|
Windows 8.1 Single Language |
1.00% |
|
Windows 8.1 Pro |
0.50% |
|
Windows 8.1 Pro with Media Center |
0.50% |
|
Windows 7 Starter |
0.50% |
|
Windows Seven Black Edition |
0.50% |
|
Distribution by country
United States installs about 31.00% of 2007 Microsoft Office system.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
16.10% |
|
Dell |
15.73% |
|
ASUS |
14.23% |
|
Acer |
12.73% |
|
Toshiba |
11.99% |
|
Lenovo |
5.24% |
|
Sony |
5.24% |
|
Compaq |
3.75% |
|
GIGABYTE |
3.37% |
|
Intel |
3.00% |
|
American Megatrends |
2.62% |
|
Samsung |
2.25% |
|
Sahara |
1.87% |
|
MSI |
0.75% |
|
Gateway |
0.75% |
|
Alienware |
0.37% |
|