| File Name | WINWORD.EXE |
| File Type |
PE32+ executable (GUI) x86-64, for MS Windows
|
| Scanner Version | 1.0.228.174 |
| Database Version | 2025-11-04 04:00:27 UTC |
No threats detected by our scanner
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
dda8fafbf79e51c6a2f6c72f04db6e52
|
|
| SHA1 |
bafcc47b26f0920a64bd182837387740d54156a2
|
|
| SHA256 |
a378c44206781108fae7daf796a625c9ed6736a7400635dc5ee8e93908af0a96
|
|
| SHA512 |
9f5e6430eea53da2441b413192b096355dda1605ed5efa41573206473c2a379e1258ba4aa0513a1775351f9a981aef21eddce8404f36df67c6acd02ab25234d5
|
|
| ImpHash |
cbcc3e0661fdf067103373849217fd73
|
| Icon |
Hash: d22181d2aba5e26188e85a41b13652a3
Fuzzy: 20252e75bce7470c992245b7771bb0cc dHash: 88a0a5acae8e8198 |
| Image Base | 0x140000000 |
| Entry Point | 0x140001730 |
| Compilation Time | 2025-10-08 00:03:35 |
| Checksum | 0x001b0f18 (Actual: 0x001b0f18) |
| OS Version | 6.1 |
| PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
| PDB Path | D:\dbs\el\omr\Target\x64\ship\postc2r\x-none\winword.pdb 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
| Digital Signature | OK |
| Imports | 13 libraries |
| Exports | 1 functions |
| Resources | 243 Resources |
| Sections | 8 Sections |
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Word |
| FileVersion | 16.0.19127.20302 |
| InternalName | WinWord |
| LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFilename | WinWord.exe |
| ProductName | Microsoft Office |
| ProductVersion | 16.0.19127.20302 |
| Translation | 0x0000 0x04e4 |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
15,672 bytes | 15,872 bytes | 6.14 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
013BB77111DE984B996188EBCB599867 |
.rdata |
0x00005000 |
9,167 bytes | 9,216 bytes | 4.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
9B0F54B9E0C4223840D09272CC361852 |
.data |
0x00008000 |
2,656 bytes | 1,024 bytes | 1.61 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6286CAF2FA3313928C0D8B1ECDA736B6 |
.pdata |
0x00009000 |
1,320 bytes | 1,536 bytes | 3.79 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
1B1E5695F21E17C15B0B329BDFC40426 |
.didat |
0x0000a000 |
80 bytes | 512 bytes | 0.54 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9F7163C3779DD8D004EB40FD516A83A8 |
.c2r |
0x0000b000 |
336 bytes | 512 bytes | 1.82 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D0917E599D87B2649EC07F04B1A14715 |
.rsrc |
0x0000c000 |
1,717,368 bytes | 1,717,760 bytes | 4.47 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
65D45EB753E8C66F91FB3C11468252B0 |
.reloc |
0x001b0000 |
168 bytes | 512 bytes | 2.28 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
50A7106E36A84DCECB74FF0A52C2D6B1 |
| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| EDPENLIGHTENEDAPPINFOID | 1 | 2 bytes | |
| EDPPERMISSIVEAPPINFOID | 1 | 2 bytes | |
| LIMITEDACCESSFEATURE | 1 | 70 bytes | |
| RT_ICON | 225 | 1,566,026 bytes | |
| RT_GROUP_ICON | 13 | 3,228 bytes | |
| RT_VERSION | 1 | 2,044 bytes | |
| RT_MANIFEST | 1 | 133,833 bytes |
| Product | Microsoft Office |
| Description | Microsoft Word |
| File Version | 16.0.19127.20302 |
| Original Name | WinWord.exe |
| Signing Date | 12:05 AM 10/08/2025 (94 days ago) |
| Verification Status | Signed |
| Signers | Microsoft Corporation; Microsoft Windows Code Signing PCA 2024; Microsoft Root Certificate Authority 2010 |
| Counter Signers | Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010 |
| Internal Name | WinWord |
33 00 00 00 1C 48 9F 81 DF A1 B0 B7 77 00 00 00 00 00 1C33 00 00 00 C3 33 AB 2C 1A F5 42 F2 C8 00 00 00 00 00 C333 00 00 02 05 3C 75 6C 82 44 87 CD FE 00 01 00 00 02 0533 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 1533 00 00 00 C0 5C 75 FF F0 2A 66 B5 35 00 00 00 00 00 C033 00 00 02 0E 2C CB 28 7D 95 20 75 63 00 01 00 00 02 0E✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!