Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 3.91%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.13%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.21%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.04%
6.2.9200.16384 (win8_rtm.120725-1247) 1.70%
6.2.9200.16384 (win8_rtm.120725-1247) 6.34%
6.2.9200.16384 (win8_rtm.120725-1247) 5.95%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.09%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.09%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.04%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.09%
6.1.7600.16385 (win7_rtm.090713-1255) 2.72%
6.1.7600.16385 (win7_rtm.090713-1255) 2.47%
6.1.7600.16385 (win7_rtm.090713-1255) 34.82%
6.1.7600.16385 (win7_rtm.090713-1255) 16.20%
6.1.7600.16385 (win7_rtm.090713-1255) 2.25%
6.1.7600.16385 (win7_rtm.090713-1255) 1.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.04%
6.1.7600.16385 (win7_rtm.090713-1255) 0.04%
6.0.6000.16386 (vista_rtm.061101-2205) 5.23%
6.0.6000.16386 (vista_rtm.061101-2205) 0.04%
6.0.6000.16386 (vista_rtm.061101-2205) 0.38%
6.0.6000.16386 (vista_rtm.061101-2205) 1.19%
6.0.6000.16386 (vista_rtm.061101-2205) 0.38%
6.0.6000.16386 (vista_rtm.061101-2205) 0.04%
View more

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
EventWrite, EventRegister, EventUnregister, RegCloseKey, RegOpenKeyExW, RegQueryValueExW, RegGetValueW, CloseServiceHandle, QueryServiceConfigW, OpenServiceW, OpenSCManagerW, RegQueryInfoKeyW, RegEnumValueW, RegDeleteKeyW, RegSetValueExW, RegCreateKeyExW, RegEnumKeyExW
comctl32.dll
PropertySheetW, ImageList_Draw, CreatePropertySheetPageW, ImageList_ReplaceIcon, ImageList_GetImageCount, ImageList_Remove
comdlg32.dll
GetFileTitleW, CommDlgExtendedError
gdi32.dll
CreateCompatibleDC, EnumFontFamiliesExW, GetTextFaceW, CreateFontW, Rectangle, GetViewportOrgEx, GetMetaFileBitsEx, CreateMetaFileA, SetWindowOrgEx, SetWindowExtEx, CloseMetaFile, DeleteMetaFile, CreateRectRgn, CreateRectRgnIndirect, CombineRgn, DeleteDC, GetObjectW, GetTextMetricsW, BitBlt, ScaleWindowExtEx, CreateSolidBrush, Escape, ExtTextOutW, RectVisible, PtVisible, GdiGradientFill, CreatePen, SelectObject, DeleteObject, Polyline, CreateICW, SetMetaFileBitsEx, GetTextExtentPoint32W, TextOutW, DPtoLP, CreateDCW, CreateFontIndirectW, DeleteEnhMetaFile, GetDeviceCaps
kernel32.dll
GetVersionExW, InterlockedExchange, FreeLibraryAndExitThread, Wow64RevertWow64FsRedirection, Wow64DisableWow64FsRedirection, IsWow64Process, GetCurrentProcess, CreateThread, GetProcessHeap, HeapAlloc, HeapFree, GetCurrentThreadId, GetTempPathW, GlobalAlloc, GetTempFileNameW, GetFileSize, GetModuleHandleA, GetProcAddress, GetShortPathNameW, CreateFileW, ReadFile, CloseHandle, AddAtomW, SetCurrentDirectoryW, GlobalDeleteAtom, GetVersion, GlobalAddAtomW, HeapSetInformation, WideCharToMultiByte, Sleep, DeleteAtom, lstrcmpA, ResumeThread, SetThreadPriority, GlobalSize, FindResourceW, GetModuleHandleW, GlobalGetAtomNameW, GetNumberFormatEx, GetModuleFileNameW, GetFileAttributesW, GetLocaleInfoW, GetLocalTime, GetLocaleInfoEx, EnumDateFormatsExW, LoadLibraryA, lstrcmpW, lstrcmpiW, GlobalLock, GlobalUnlock, GlobalFree, LoadLibraryW, EnumTimeFormatsW, GetTimeFormatW, GetDateFormatW, CopyFileW, MultiByteToWideChar, FileTimeToDosDateTime, WriteFile, SetFilePointer, LeaveCriticalSection, EnterCriticalSection, CreateDirectoryW, DeleteCriticalSection, InitializeCriticalSection, FileTimeToSystemTime, GetSystemTime, SystemTimeToFileTime, CompareFileTime, RegisterApplicationRestart, RegisterApplicationRecoveryCallback, ApplicationRecoveryFinished, ApplicationRecoveryInProgress, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, SetUnhandledExceptionFilter, OutputDebugStringA, GetStartupInfoW, InterlockedCompareExchange, GetLongPathNameW, LocalAlloc, InterlockedDecrement, InterlockedIncrement, LocalFree, GetLastError, CompareStringOrdinal, MoveFileW, DeleteFileW, lstrlenW, MulDiv, FreeLibrary, RaiseException
mfc42u.dll
DllMain
msvcrt.dll
DllMain
ntdll.dll
RtlInitUnicodeString, NtQueryLicenseValue, WinSqmStartSession, WinSqmEndSession, WinSqmSetDWORD, WinSqmAddToStream, WinSqmIncrementDWORD
ole32.dll
OleUninitialize, CoInitialize, CoUninitialize, OleInitialize, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, CoGetMalloc, WriteClassStg, PropVariantCopy, OleRegGetUserType, StringFromGUID2, CoCreateGuid, OleSave, OleDuplicateData, PropVariantClear, StgOpenStorageEx, StringFromCLSID, CLSIDFromString, IIDFromString, StgOpenStorage, ReadClassStg, OleLoad, ReleaseStgMedium, ProgIDFromCLSID, CoCreateInstance, CreateStreamOnHGlobal, CoTaskMemFree
propsys.dll
PropVariantToString, PropVariantToUInt32, PropVariantToUInt32WithDefault
rpcrt4.dll
UuidToStringW, UuidCreate, RpcStringFreeW
shell32.dll
DragFinish, SHGetFolderPathW, ShellExecuteExW, SHGetSpecialFolderPathW, ShellAboutW, SHAddToRecentDocs, SHCreateItemInKnownFolder, SHCreateItemFromParsingName, DragQueryFileW, ShellExecuteW
shlwapi.dll
PathFileExistsW, StrCmpIW, PathIsFileSpecW, PathFindFileNameW, PathFindExtensionW, SHCreateStreamOnFileW, SHCreateStreamOnFileEx, SHStrDupW, StrCmpNIW, PathAddBackslashW
urlmon.dll
CreateUri
user32.dll
EndDialog, DialogBoxParamW, LoadStringW, SetWindowRgn, SetTimer, KillTimer, SetFocus, GetMenuItemCount, IsMenu, CreatePopupMenu, CreateMenu, GetMenuStringW, GetMenuItemInfoW, InsertMenuW, DeleteMenu, GetMenuItemID, GetKeyboardLayout, TrackMouseEvent, LoadImageW, GrayStringW, DrawTextW, GetPropW, GetSubMenu, OemToCharBuffA, CharToOemBuffA, SetRect, FindWindowW, EnumWindows, RegisterClipboardFormatW, RegisterWindowMessageW, GetDC, ReleaseDC, OffsetRect, GetWindowRect, GetClientRect, ClientToScreen, UpdateWindow, InvalidateRect, SetActiveWindow, SetCapture, GetParent, HideCaret, ShowCaret, GetCapture, GetKeyState, GetSystemMetrics, ReleaseCapture, IsClipboardFormatAvailable, CountClipboardFormats, GetMonitorInfoW, MonitorFromWindow, EnableWindow, SetWindowLongW, GetWindowLongW, SetWindowTextW, GetWindowTextW, GetClassNameW, SendMessageTimeoutW, IsIconic, SetForegroundWindow, SystemParametersInfoW, DrawEdge, LoadBitmapW, LoadCursorW, FillRect, SendDlgItemMessageW, ShowWindow, PtInRect, GetDlgCtrlID, IsWindow, GetWindow, IsRectEmpty, SetRectEmpty, IntersectRect, CopyRect, PostMessageW, ScreenToClient, TabbedTextOutW, IsWindowVisible, PostQuitMessage, GetGestureInfo, DefWindowProcW, UnhookWindowsHookEx, CallNextHookEx, SetWindowsHookExW, GetClassInfoW, ShowScrollBar, DestroyCursor, SetCursor, GetCursorPos, SetWindowPos, GetAncestor, SendMessageW, GetFocus, LoadIconW, GetSysColor, MonitorFromRect, GetDlgItem, IsDlgButtonChecked, SetGestureConfig, CloseGestureInfoHandle, DestroyMenu
version.dll
GetFileVersionInfoExW, VerQueryValueW, GetFileVersionInfoSizeExW
winmm.dll
timeGetTime
xmllite.dll
CreateXmlWriter

wordpad.exe

Windows Wordpad Application by Microsoft

Remove wordpad.exe
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   715bff236158f61c042928a53c0d5aa8
SHA1:   f75557bd48f608bb6fb7351faba6f47897e01085
SHA256:   d05369e606122090468137dfbce4d6054bf35bcf1684e96074c22bd890551a8b
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is wordpad.exe?

WordPad is a basic word processor that is included with almost all versions of Microsoft Windows. It is more advanced than Notepad but simpler than Microsoft Word. WordPad can format and print text, but lacks intermediate features such as a spell checker, thesaurus, and support for tables. As such, it is suitable for writing letters or short pieces, but underpowered for work that relies heavily on graphics or typesetting. WordPad natively supports the Rich Text Format.

About wordpad.exe (from Microsoft)

WordPad is a basic word processor that is included in Windows. A word processor is a computer program that you can use to create, edit, view, and print text documents. With WordPad, you can type let

DetailsDetails

File name:wordpad.exe
Publisher:Microsoft Corporation
Product name:Windows Wordpad Application
Description:Microsoft® Windows® Operating System
Typical file path:C:\Program Files\windows nt\accessories\wordpad.exe
Original name:WORDPAD.EXE.MUI
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:4.37 MB (4,583,424 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:4.973523
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Shell open command
  • rtffile

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00130540%
0.028634%
Kernel CPU:0.00058810%
0.013761%
User CPU:0.00071729%
0.014873%
Kernel CPU time:16,178,807 ms/min
100,923,805ms/min
CPU cycles:297,254/sec
17,470,203/sec
Memory
Private memory:37.37 MB
21.59 MB
Private (maximum):59.07 MB
Private (minimum):15.67 MB
Non-paged memory:37.37 MB
21.59 MB
Virtual memory:499.33 MB
140.96 MB
Virtual memory (peak):514.74 MB
169.69 MB
Working set:23.11 MB
18.61 MB
Working set (peak):61.96 MB
37.95 MB
Page faults:55,314/min
2,039/min
I/O
I/O read transfer:174 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:14 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:236 Bytes/sec
448.09 KB/min
I/O other operations:3/sec
1,671/min
Resource allocations
Threads:7
12
Handles:399
600
GUI GDI count:475
103
GUI GDI peak:566
142
GUI USER count:72
49
GUI USER peak:190
71

BehaviorsProcess properties

Integrety level:Medium
Platform:64-bit
Command line:"C:\Program Files\windows nt\accessories\wordpad.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
wordpad.exe (main module)
Total CPU:0.00822929%
0.272967%
Kernel CPU:0.00434587%
0.107585%
User CPU:0.00388342%
0.165382%
CPU cycles:254,601/sec
5,741,424/sec
Memory:4.39 MB
1.16 MB
SHLWAPI.dll
Total CPU:0.00003774%
Kernel CPU:0.00001499%
User CPU:0.00002275%
CPU cycles:3,020/sec
Memory:452 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 32.50%
Windows 8.1 18.00%
Windows 7 Ultimate 14.50%
Windows 8.1 Pro 7.50%
Windows 7 Professional 6.00%
Windows 8 4.00%
Windows 8.1 Single Language 3.50%
Windows 8 Single Language 3.00%
Windows 8 Pro 3.00%
Windows 8.1 Pro with Media Center 2.00%
Windows 7 Home Basic 1.50%
Windows Vista Home Premium 1.50%
Windows 8 Enterprise N 1.00%
Windows 8.1 N 0.50%
Windows Seven Black Edition 0.50%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 8 Enterprise 0.50%

Distribution by countryDistribution by country

United States installs about 46.23% of Windows Wordpad Application.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 19.69%
ASUS 18.11%
Hewlett-Packard 17.72%
Acer 12.20%
Toshiba 11.02%
Lenovo 8.66%
Sony 4.72%
Intel 2.36%
GIGABYTE 1.97%
Samsung 1.57%
Alienware 1.18%
Medion 0.79%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE