Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 3.91%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.13%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.21%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.04%
6.2.9200.16384 (win8_rtm.120725-1247) 1.70%
6.2.9200.16384 (win8_rtm.120725-1247) 6.34%
6.2.9200.16384 (win8_rtm.120725-1247) 5.95%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.09%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.09%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.04%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.09%
6.1.7600.16385 (win7_rtm.090713-1255) 2.72%
6.1.7600.16385 (win7_rtm.090713-1255) 2.47%
6.1.7600.16385 (win7_rtm.090713-1255) 34.82%
6.1.7600.16385 (win7_rtm.090713-1255) 16.20%
6.1.7600.16385 (win7_rtm.090713-1255) 2.25%
6.1.7600.16385 (win7_rtm.090713-1255) 1.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.04%
6.1.7600.16385 (win7_rtm.090713-1255) 0.04%
6.0.6000.16386 (vista_rtm.061101-2205) 5.23%
6.0.6000.16386 (vista_rtm.061101-2205) 0.04%
6.0.6000.16386 (vista_rtm.061101-2205) 0.38%
6.0.6000.16386 (vista_rtm.061101-2205) 1.19%
6.0.6000.16386 (vista_rtm.061101-2205) 0.38%
6.0.6000.16386 (vista_rtm.061101-2205) 0.04%
View more

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
EventWrite, EventRegister, EventUnregister, RegCloseKey, RegOpenKeyExW, RegQueryValueExW, RegGetValueW, CloseServiceHandle, QueryServiceConfigW, OpenServiceW, OpenSCManagerW, RegQueryInfoKeyW, RegEnumValueW, RegDeleteKeyW, RegSetValueExW, RegCreateKeyExW, RegEnumKeyExW
comctl32.dll
PropertySheetW, ImageList_Draw, CreatePropertySheetPageW, ImageList_ReplaceIcon, ImageList_GetImageCount, ImageList_Remove
comdlg32.dll
GetFileTitleW, CommDlgExtendedError
gdi32.dll
CreateCompatibleDC, EnumFontFamiliesExW, GetTextFaceW, CreateFontW, Rectangle, GetViewportOrgEx, GetMetaFileBitsEx, CreateMetaFileA, SetWindowOrgEx, SetWindowExtEx, CloseMetaFile, DeleteMetaFile, CreateRectRgn, CreateRectRgnIndirect, CombineRgn, DeleteDC, GetObjectW, GetTextMetricsW, BitBlt, ScaleWindowExtEx, CreateSolidBrush, Escape, ExtTextOutW, RectVisible, PtVisible, GdiGradientFill, CreatePen, SelectObject, DeleteObject, Polyline, CreateICW, SetMetaFileBitsEx, GetTextExtentPoint32W, TextOutW, DPtoLP, CreateDCW, CreateFontIndirectW, DeleteEnhMetaFile, GetDeviceCaps
kernel32.dll
GetVersionExW, InterlockedExchange, FreeLibraryAndExitThread, Wow64RevertWow64FsRedirection, Wow64DisableWow64FsRedirection, IsWow64Process, GetCurrentProcess, CreateThread, GetProcessHeap, HeapAlloc, HeapFree, GetCurrentThreadId, GetTempPathW, GlobalAlloc, GetTempFileNameW, GetFileSize, GetModuleHandleA, GetProcAddress, GetShortPathNameW, CreateFileW, ReadFile, CloseHandle, AddAtomW, SetCurrentDirectoryW, GlobalDeleteAtom, GetVersion, GlobalAddAtomW, HeapSetInformation, WideCharToMultiByte, Sleep, DeleteAtom, lstrcmpA, ResumeThread, SetThreadPriority, GlobalSize, FindResourceW, GetModuleHandleW, GlobalGetAtomNameW, GetNumberFormatEx, GetModuleFileNameW, GetFileAttributesW, GetLocaleInfoW, GetLocalTime, GetLocaleInfoEx, EnumDateFormatsExW, LoadLibraryA, lstrcmpW, lstrcmpiW, GlobalLock, GlobalUnlock, GlobalFree, LoadLibraryW, EnumTimeFormatsW, GetTimeFormatW, GetDateFormatW, CopyFileW, MultiByteToWideChar, FileTimeToDosDateTime, WriteFile, SetFilePointer, LeaveCriticalSection, EnterCriticalSection, CreateDirectoryW, DeleteCriticalSection, InitializeCriticalSection, FileTimeToSystemTime, GetSystemTime, SystemTimeToFileTime, CompareFileTime, RegisterApplicationRestart, RegisterApplicationRecoveryCallback, ApplicationRecoveryFinished, ApplicationRecoveryInProgress, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, SetUnhandledExceptionFilter, OutputDebugStringA, GetStartupInfoW, InterlockedCompareExchange, GetLongPathNameW, LocalAlloc, InterlockedDecrement, InterlockedIncrement, LocalFree, GetLastError, CompareStringOrdinal, MoveFileW, DeleteFileW, lstrlenW, MulDiv, FreeLibrary, RaiseException
mfc42u.dll
DllMain
msvcrt.dll
DllMain
ntdll.dll
RtlInitUnicodeString, NtQueryLicenseValue, WinSqmStartSession, WinSqmEndSession, WinSqmSetDWORD, WinSqmAddToStream, WinSqmIncrementDWORD
ole32.dll
OleUninitialize, CoInitialize, CoUninitialize, OleInitialize, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, CoGetMalloc, WriteClassStg, PropVariantCopy, OleRegGetUserType, StringFromGUID2, CoCreateGuid, OleSave, OleDuplicateData, PropVariantClear, StgOpenStorageEx, StringFromCLSID, CLSIDFromString, IIDFromString, StgOpenStorage, ReadClassStg, OleLoad, ReleaseStgMedium, ProgIDFromCLSID, CoCreateInstance, CreateStreamOnHGlobal, CoTaskMemFree
propsys.dll
PropVariantToString, PropVariantToUInt32, PropVariantToUInt32WithDefault
rpcrt4.dll
UuidToStringW, UuidCreate, RpcStringFreeW
shell32.dll
DragFinish, SHGetFolderPathW, ShellExecuteExW, SHGetSpecialFolderPathW, ShellAboutW, SHAddToRecentDocs, SHCreateItemInKnownFolder, SHCreateItemFromParsingName, DragQueryFileW, ShellExecuteW
shlwapi.dll
PathFileExistsW, StrCmpIW, PathIsFileSpecW, PathFindFileNameW, PathFindExtensionW, SHCreateStreamOnFileW, SHCreateStreamOnFileEx, SHStrDupW, StrCmpNIW, PathAddBackslashW
urlmon.dll
CreateUri
user32.dll
EndDialog, DialogBoxParamW, LoadStringW, SetWindowRgn, SetTimer, KillTimer, SetFocus, GetMenuItemCount, IsMenu, CreatePopupMenu, CreateMenu, GetMenuStringW, GetMenuItemInfoW, InsertMenuW, DeleteMenu, GetMenuItemID, GetKeyboardLayout, TrackMouseEvent, LoadImageW, GrayStringW, DrawTextW, GetPropW, GetSubMenu, OemToCharBuffA, CharToOemBuffA, SetRect, FindWindowW, EnumWindows, RegisterClipboardFormatW, RegisterWindowMessageW, GetDC, ReleaseDC, OffsetRect, GetWindowRect, GetClientRect, ClientToScreen, UpdateWindow, InvalidateRect, SetActiveWindow, SetCapture, GetParent, HideCaret, ShowCaret, GetCapture, GetKeyState, GetSystemMetrics, ReleaseCapture, IsClipboardFormatAvailable, CountClipboardFormats, GetMonitorInfoW, MonitorFromWindow, EnableWindow, SetWindowLongW, GetWindowLongW, SetWindowTextW, GetWindowTextW, GetClassNameW, SendMessageTimeoutW, IsIconic, SetForegroundWindow, SystemParametersInfoW, DrawEdge, LoadBitmapW, LoadCursorW, FillRect, SendDlgItemMessageW, ShowWindow, PtInRect, GetDlgCtrlID, IsWindow, GetWindow, IsRectEmpty, SetRectEmpty, IntersectRect, CopyRect, PostMessageW, ScreenToClient, TabbedTextOutW, IsWindowVisible, PostQuitMessage, GetGestureInfo, DefWindowProcW, UnhookWindowsHookEx, CallNextHookEx, SetWindowsHookExW, GetClassInfoW, ShowScrollBar, DestroyCursor, SetCursor, GetCursorPos, SetWindowPos, GetAncestor, SendMessageW, GetFocus, LoadIconW, GetSysColor, MonitorFromRect, GetDlgItem, IsDlgButtonChecked, SetGestureConfig, CloseGestureInfoHandle, DestroyMenu
version.dll
GetFileVersionInfoExW, VerQueryValueW, GetFileVersionInfoSizeExW
winmm.dll
timeGetTime
xmllite.dll
CreateXmlWriter

wordpad.exe

Windows Wordpad Application by Microsoft

Remove wordpad.exe
Version:   6.3.9600.16384 (winblue_rtm.130821-1623)
MD5:   324f9d3eeee321ea60641362fe94d188
SHA1:   4b9e5e1b8a309c4ac49900c18a9fab9223185a11
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wordpad.exe?

WordPad is a basic word processor that is included with almost all versions of Microsoft Windows. It is more advanced than Notepad but simpler than Microsoft Word. WordPad can format and print text, but lacks intermediate features such as a spell checker, thesaurus, and support for tables. As such, it is suitable for writing letters or short pieces, but underpowered for work that relies heavily on graphics or typesetting. WordPad natively supports the Rich Text Format.

About wordpad.exe (from Microsoft)

WordPad is a basic word processor that is included in Windows. A word processor is a computer program that you can use to create, edit, view, and print text documents. With WordPad, you can type let

DetailsDetails

File name:wordpad.exe
Publisher:Microsoft Corporation
Product name:Windows Wordpad Application
Description:Microsoft® Windows® Operating System
Typical file path:C:\Program Files\windows nt\accessories\wordpad.exe
Original name:WORDPAD.EXE.MUI
File version:6.3.9600.16384 (winblue_rtm.130821-1623)
Product version:6.3.9600.16384
Size:4.35 MB (4,561,920 bytes)
Build date:8/22/2013 6:21 AM
Digital DNA
PE subsystem:Windows GUI
Entropy:4.973523
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Shell open command
  • rtffile

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00008420%
0.028634%
Kernel CPU:0.00005067%
0.013761%
User CPU:0.00003353%
0.014873%
Kernel CPU time:7,531 ms/min
100,923,805ms/min
CPU cycles:231,887/sec
17,470,203/sec
Memory
Private memory:30.19 MB
21.59 MB
Private (maximum):42.54 MB
Private (minimum):22.06 MB
Non-paged memory:30.19 MB
21.59 MB
Virtual memory:239.84 MB
140.96 MB
Virtual memory (peak):355.85 MB
169.69 MB
Working set:42 MB
18.61 MB
Working set (peak):53.7 MB
37.95 MB
Page faults:72,790/min
2,039/min
I/O
I/O read transfer:977 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:884 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:88 Bytes/sec
448.09 KB/min
I/O other operations:4/sec
1,671/min
Resource allocations
Threads:6
12
Handles:358
600
GUI GDI count:898
103
GUI GDI peak:994
142
GUI USER count:86
49
GUI USER peak:172
71

BehaviorsProcess properties

Integrety level:High
Platform:64-bit
Command lines:
  • "C:\Program Files\windows nt\accessories\wordpad.exe" "C:\users\jtbab_000\downloads\euro comp review.docx"
  • "C:\Program Files\windows nt\accessories\wordpad.exe" "C:\users\jtbab_000\downloads\european history.docx"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
WORDPAD.EXE (main module)
Total CPU:0.00528948%
0.272967%
Kernel CPU:0.00356930%
0.107585%
User CPU:0.00172018%
0.165382%
CPU cycles:205,454/sec
5,741,424/sec
Memory:4.37 MB
1.16 MB
UIRibbon.dll
Total CPU:0.00075224%
Kernel CPU:0.00065821%
User CPU:0.00009403%
CPU cycles:36,633/sec
Memory:4.02 MB
FunDisc.dll
Total CPU:0.00023236%
Kernel CPU:0.00000000%
User CPU:0.00023236%
CPU cycles:3,907/sec
Memory:160 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 32.50%
Windows 8.1 18.00%
Windows 7 Ultimate 14.50%
Windows 8.1 Pro 7.50%
Windows 7 Professional 6.00%
Windows 8 4.00%
Windows 8.1 Single Language 3.50%
Windows 8 Single Language 3.00%
Windows 8 Pro 3.00%
Windows 8.1 Pro with Media Center 2.00%
Windows 7 Home Basic 1.50%
Windows Vista Home Premium 1.50%
Windows 8 Enterprise N 1.00%
Windows 8.1 N 0.50%
Windows Seven Black Edition 0.50%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 8 Enterprise 0.50%

Distribution by countryDistribution by country

United States installs about 46.23% of Windows Wordpad Application.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 19.69%
ASUS 18.11%
Hewlett-Packard 17.72%
Acer 12.20%
Toshiba 11.02%
Lenovo 8.66%
Sony 4.72%
Intel 2.36%
GIGABYTE 1.97%
Samsung 1.57%
Alienware 1.18%
Medion 0.79%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE