Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

15.0.4623.1000 5.21%
15.0.4623.1000 1.04%
15.0.4623.1000 0.52%
15.0.4619.1000 2.08%
15.0.4615.1000 0.52%
15.0.4615.1000 0.52%
15.0.4609.1000 6.77%
15.0.4551.1509 0.52%
15.0.4551.1001 1.56%
15.0.4535.1507 3.65%
15.0.4535.1507 1.56%
15.0.4535.1507 6.77%
15.0.4535.1000 0.52%
15.0.4535.1000 1.56%
15.0.4517.1505 0.52%
15.0.4517.1003 2.08%
15.0.4517.1003 0.52%
15.0.4517.1003 0.52%
15.0.4505.1510 2.08%
15.0.4505.1003 0.52%
15.0.4481.1508 3.65%
15.0.4481.1508 3.13%
15.0.4481.1508 1.56%
15.0.4481.1001 6.25%
15.0.4454.1504 1.04%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, RegOpenKeyExA, RegOpenKeyA, RegQueryValueExA, RegQueryValueExW, RegCloseKey
gdi32.dll
SetWindowExtEx, GetViewportExtEx, GetWindowExtEx, SetMapMode, SelectClipRgn, SetViewportExtEx, CreateRectRgnIndirect, GetClipRgn, CreateRectRgn, SetTextColor, LineTo, MoveToEx, RoundRect, Polygon, SetBkMode, CreatePen, CreateSolidBrush, GetTextExtentPoint32W, PatBlt, BitBlt, CreateCompatibleDC, CreateDIBitmap, ExtTextOutA, GetTextAlign, SetBkColor, SetBrushOrgEx, StretchBlt, SetStretchBltMode, GetBrushOrgEx, SetTextAlign, GetDeviceCaps, ScaleViewportExtEx, SetViewportOrgEx, SetWindowOrgEx, GetViewportOrgEx, SaveDC, CreateCompatibleBitmap, GetWindowOrgEx, GetBitmapBits, GetObjectA, GetTextMetricsA, DeleteEnhMetaFile, GetBitmapDimensionEx, DeleteDC, RealizePalette, SelectPalette, GetGlyphOutlineA, GetTextColor, GetBkColor, StretchDIBits, PlayMetaFile, PlayEnhMetaFile, GetObjectType, IntersectClipRect, DeleteMetaFile, GetNearestColor, StrokePath, StrokeAndFillPath, PlayMetaFileRecord, BeginPath, GetRgnBox, RestoreDC, EndPath, SelectObject, SetROP2, GetStockObject, InvertRgn, ExcludeClipRect, GetClipBox, RectVisible, UnrealizeObject, OffsetRgn, RectInRegion, ExtEscape, CreateBitmap, FillRgn, SetRectRgn, Rectangle, SetBitmapBits, GetTextExtentPointA, GetCharABCWidthsA, SetTextJustification, GetCharWidthA, GetMetaFileBitsEx, EnumMetaFile, CloseEnhMetaFile, GdiComment, CreateEnhMetaFileA, GetEnhMetaFileHeader, SetMetaFileBitsEx, EnumEnhMetaFile, GetTextCharsetInfo, GetCurrentObject, GetPaletteEntries, GetDIBits, CreateBitmapIndirect, CopyMetaFileA, CopyEnhMetaFileA, CloseMetaFile, CreateMetaFileA, SetEnhMetaFileBits, GetEnhMetaFileBits, CreatePatternBrush, Ellipse, GetFontData, GetOutlineTextMetricsA, GetKerningPairsA, GdiFlush, GetBkMode, SetWinMetaFileBits, SetAbortProc, AbortDoc, EndDoc, EndPage, OffsetViewportOrgEx, StartPage, ExtCreateRegion, LPtoDP, GetRegionData, DeleteObject, GdiSetBatchLimit, TextOutA, CreateFontA, CreatePenIndirect, GetTextCharset, Polyline, CombineRgn, CreatePolygonRgn, SetBitmapDimensionEx
kernel32.dll
IsValidCodePage, LeaveCriticalSection, EnterCriticalSection, GlobalUnlock, GlobalLock, GlobalAlloc, GlobalSize, CloseHandle, GetFileTime, CompareFileTime, GlobalFree, GlobalReAlloc, GetLastError, GetCurrentProcessId, SetFileTime, GetTickCount, GetACP, Sleep, GetPriorityClass, SetPriorityClass, CreateProcessA, GetCurrentProcess, GetUserDefaultLCID, ReadFile, WaitForSingleObject, WriteFile, ResumeThread, CreateThread, CreatePipe, GetUserDefaultLangID, EnumSystemLocalesA, GetLocaleInfoA, GetLocaleInfoW, WideCharToMultiByte, GlobalDeleteAtom, GetDriveTypeA, IsBadReadPtr, IsBadWritePtr, LocalFileTimeToFileTime, SystemTimeToFileTime, FileTimeToLocalFileTime, GetSystemTimeAsFileTime, SetLastError, GetFileType, SetThreadPriority, GetThreadPriority, GetCurrentThread, UnmapViewOfFile, MapViewOfFile, CreateFileMappingA, OpenFileMappingA, GetProfileIntA, MulDiv, GetModuleHandleA, FreeEnvironmentStringsA, GetEnvironmentStrings, GlobalMemoryStatus, GetSystemInfo, DeleteCriticalSection, InitializeCriticalSection, SetFilePointer, GetDiskFreeSpaceA, GetLocalTime, GetVersionExA, LoadLibraryW, GlobalFlags, GetCurrentThreadId, FlushFileBuffers, GetLogicalDrives, SetErrorMode, IsDBCSLeadByteEx, LoadResource, SizeofResource, GlobalFindAtomA, GlobalHandle, OpenEventA, CreateEventA, SetEvent, SwitchToThread, ResetEvent, LoadLibraryA, GetProfileStringA, GetSystemTime, WinExec, FindResourceA, GetSystemDefaultLangID, GetOEMCP, CreateFileA, FindFirstFileA, DebugBreak, ExitProcess, QueryPerformanceCounter, QueryPerformanceFrequency, VirtualFree, VirtualAlloc, VirtualProtect, GetFullPathNameA, GetFullPathNameW, GetCommandLineA, GetCommandLineW, GetStartupInfoA, SuspendThread, TerminateProcess, SetUnhandledExceptionFilter, AddAtomA, FreeResource, LockResource, GetProcAddress, FreeLibrary, FindClose, FileTimeToSystemTime, RaiseException, GetStringTypeW, GetStringTypeA, MultiByteToWideChar, UnhandledExceptionFilter, RtlUnwind, InterlockedExchange, LocalAlloc, OpenFile, LoadLibraryExA, FormatMessageA, LocalFree
ole32.dll
OleSaveToStream, OleDuplicateData, CoFreeUnusedLibraries, StringFromGUID2, CoGetTreatAsClass, CoTreatAsClass, OleSetClipboard, OleCreate, OleCreateFromFile, OleCreateLinkFromData, OleCreateFromData, OleCreateLinkToFile, GetClassFile, CoGetClassObject, CreateDataCache, OleQueryLinkFromData, OleQueryCreateFromData, OleConvertIStorageToOLESTREAMEx, OleConvertIStorageToOLESTREAM, OleConvertOLESTREAMToIStorage, IIDFromString, OleCreateDefaultHandler, OleLoad, CoIsOle1Class, CoRegisterMessageFilter, OleGetIconOfClass, GetConvertStg, SetConvertStg, GetRunningObjectTable, OleSetMenuDescriptor, OleSave, CreateFileMoniker, CreateGenericComposite, CreateDataAdviseHolder, OleRegEnumFormatEtc, OleFlushClipboard, OleRun, OleRegEnumVerbs, OleTranslateAccelerator, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, ReadClassStm, IsAccelerator, CoGetMalloc, CoRevokeClassObject, CoDisconnectObject, CoRegisterClassObject, StringFromCLSID, CoInitialize, CoUninitialize, OleCreateLink, WriteClassStm, ProgIDFromCLSID, MkParseDisplayName, StgIsStorageFile, ReleaseStgMedium, CoCreateInstance, OleIsCurrentClipboard, OleGetClipboard, CreateStreamOnHGlobal, GetHGlobalFromStream, CLSIDFromString, OleIsRunning, CreateItemMoniker, CoLockObjectExternal, ReadClassStg, CreateBindCtx, StgOpenStorage, WriteClassStg, WriteFmtUserTypeStg, StgCreateDocfile, ReadFmtUserTypeStg, CoTaskMemFree, CreateOleAdviseHolder, OleRegGetMiscStatus
user32.dll
DllMain
Export table
DllGetLCID
wdCommandDispatch
wdGetApplicationObject

WinWord.exe

Microsoft Office XP by Microsoft Corporation (Signed)

Remove WinWord.exe
Version:   15.0.4481.1508
MD5:   b1e420c9f55e6ef4e5f07684238afb7a
SHA1:   3a83bc638a30e1d593216c780f86590a15db72ac
SHA256:   59fdf91a70826ad25ba7f47c176e67ab2f4fab120e2e80f9b2bee1dba974da68

What is WinWord.exe?

Microsoft Word is a commercial word processor designed by Microsoft. Microsoft Word is currently the most common word processor on the market.

About WinWord.exe (from Microsoft Corporation)

Create documents with enhanced features that help you create, edit, and access documents from almost anywhere.

Overview

winword.exe executes as a process with the local user's privileges. The file is digitally signed by Microsoft Corporation.

DetailsDetails

File name:winword.exe
Publisher:Microsoft Corporation
Product name:Microsoft Office XP
Description:Microsoft Word
Typical file path:C:\Program Files\microsoft office\office10\winword.exe
File version:15.0.4481.1508
Size:1.84 MB (1,924,768 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Monday, December 7, 2009
Expiration date:Monday, March 7, 2011
Digital DNA
Entropy:6.433466
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Shell open commands
  • wordhtmlfile
Scheduled tasks
  • The task '{AF8E3B26-83C1-45E8-A9B0-C6456B5DB853}' runs on registration in the path '\{AF8E3B26-83C1-45E8-A9B0-C6456B5DB853}'
  • The task '{2483674E-B0FB-4503-BFBA-681CF6066A79}' runs on registration in the path '\{2483674E-B0FB-4503-BFBA-681CF6066A79}'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00066049%
0.028634%
Kernel CPU:0.00066049%
0.013761%
Kernel CPU time:43,953 ms/min
100,923,805ms/min
Memory
Private memory:96.02 MB
21.59 MB
Private (maximum):246.98 MB
Private (minimum):104.62 MB
Non-paged memory:96.02 MB
21.59 MB
Virtual memory:859.23 MB
140.96 MB
Virtual memory (peak):1.01 GB
169.69 MB
Working set:187.8 MB
18.61 MB
Working set (peak):247.46 MB
37.95 MB
Resource allocations
Threads:29
12
Handles:1045
600
GUI GDI count:584
103
GUI GDI peak:769
142
GUI USER count:201
49
GUI USER peak:332
71

BehaviorsProcess properties

Integrety level:Medium
Platform:64-bit
Command line:"C:\Program Files\microsoft office\office15\winword.exe" /n "C:\users\user\desktop\sun tzu tan.doc
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
WINWORD.EXE (main module)
Total CPU:1.17273832%
0.272967%
Kernel CPU:0.14568393%
0.107585%
User CPU:1.02705439%
0.165382%
CPU cycles:28,593,558/sec
5,741,424/sec
Memory:1.84 MB
1.16 MB
mso.dll
Total CPU:0.25321079%
Kernel CPU:0.02335914%
User CPU:0.22985165%
CPU cycles:6,002,070/sec
Memory:33.72 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 15.38%
Windows 8 Pro 13.85%
Microsoft Windows XP 11.54%
Windows 8.1 10.77%
Windows 7 Ultimate 10.77%
Windows 7 Home Premium 10.77%
Windows 8.1 Pro 5.38%
Windows 7 Professional 5.38%
Windows 8 Pro with Media Center 4.62%
Windows Vista Home Premium 3.85%
Windows 7 Home Basic 1.54%
Windows 8 Enterprise 1.54%
Windows 8.1 Pro Preview 1.54%
Windows 8.1 Enterprise Evaluation 0.77%
Windows 7 Enterprise 0.77%
Windows 8.1 Pro Preview with Media Center 0.77%
Microsoft Windows XP Home Edition 0.77%

Distribution by countryDistribution by country

United States installs about 61.72% of Microsoft Office XP.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 20.78%
Hewlett-Packard 16.23%
ASUS 14.29%
Lenovo 11.69%
Acer 11.04%
Toshiba 6.49%
Intel 3.90%
MSI 3.90%
Gateway 3.90%
GIGABYTE 2.60%
Samsung 1.95%
Sony 1.30%
Apple 1.30%
American Megatrends 0.65%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE