WinWord.exe

2007 Microsoft Office system

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable WinWord.exe, “Microsoft Office Word” has been detected as malware by 5 anti-virus scanners.
Publisher:
Microsoft Corporation*  (Invalid match)

Product:
2007 Microsoft Office system

Description:
Microsoft Office Word

Version:
12.0.4518.1014

MD5:
bf2eed04585fa8c1a140000d95dad755

SHA-1:
c33144b083a43bac2cca8ef59d8f365ec2d0b1cf

SHA-256:
888db7dd2804221ea192d82705f8d01fc3bf7e1ba27087ab949335c9c8775f30

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/19/2024 5:47:25 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Patched.Gen
7.11.30.172

avast!
Win32:WrongInf-A [Susp]
2014.9-141024

Bkav FE
W32.HfsAutoA
1.3.0.4959

NANO AntiVirus
Virus.Win32.Virut-Gen.bwpxnc
0.28.2.62841

VIPRE Antivirus
Threat.4728187
33706

File size:
336.8 KB (344,854 bytes)

Product version:
12.0.4518.1014

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
WinWord.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\microsoft office\office12\winword.exe

File PE Metadata
Compilation timestamp:
10/28/2006 4:54:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:8lsHe0BivO39zYpmH+kAzkA7ZUgbc6AYJ8rEdrEbAgMMV6NX5ZNeVgjYfb:znIO39YAeNLFjAYarEdrEb5P6VxYT

Entry address:
0x10CC

Entry point:
E8, 05, 00, 00, 00, E9, DD, 00, 00, 00, 55, 8B, EC, 83, EC, 14, 53, 56, 57, 68, A0, 11, 00, 30, 68, 84, 11, 00, 30, FF, 15, 38, 10, 00, 30, 50, FF, 15, 04, 10, 00, 30, 8B, F0, 85, F6, 74, 0F, 6A, 00, 6A, 00, 6A, 01, FF, 15, 3C, 10, 00, 30, 50, FF, D6, 8D, 45, F4, 50, FF, 15, 40, 10, 00, 30, 8B, 75, F8, 33, 75, F4, FF, 15, 44, 10, 00, 30, 33, F0, FF, 15, 48, 10, 00, 30, 33, F0, FF, 15, 4C, 10, 00, 30, 33, F0, 8D, 45, EC, 50, FF, 15, 50, 10, 00, 30, 8B, 45, F0, 33, 45, EC, 8B, 3D, 54, 10, 00, 30, 33, F0, 8D...
 
[+]

Code size:
5 KB (5,120 bytes)

Shell Open Command
Open type:
wordhtmlfile

Command:
"C:\Program Files\microsoft office\office12\winword.exe"


Remove WinWord.exe - Powered by Reason Core Security