Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.4318 (srv03_sp2_gdr.080620-1216) 0.30%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.30%
5.1.2600.5649 (xpsp_sp3_qfe.080728-1259) 3.88%
5.1.2600.5649 (xpsp_sp3_qfe.080728-1259) 0.30%
5.1.2600.5649 (xpsp_sp3_qfe.080728-1259) 0.30%
5.1.2600.5625 (xpsp_sp3_qfe.080620-1309) 5.07%
5.1.2600.5625 (xpsp_sp3_qfe.080620-1309) 0.90%
5.1.2600.5625 (xpsp_sp3_qfe.080620-1309) 0.30%
5.1.2600.5625 (xpsp_sp3_qfe.080620-1309) 1.19%
5.1.2600.5625 (xpsp_sp3_qfe.080620-1309) 1.49%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 52.24%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 2.99%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.30%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.30%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 2.39%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.60%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 2.39%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.60%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.30%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.90%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 1.79%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 0.30%
5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) 1.19%
5.1.2600.5512 (xpsp.080413-0852) 2.99%
5.1.2600.5512 (xpsp.080413-0852) 0.30%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetUserNameA, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyExW, RegDeleteKeyW, RegSetValueExW, RegCreateKeyExW, RegSetValueExA, SetServiceStatus, DeregisterEventSource, RegNotifyChangeKeyValue, RegCreateKeyExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AddAccessAllowedAce, InitializeAcl, GetLengthSid, RegisterEventSourceA, ReportEventA, RegDeleteValueW, RegOpenCurrentUser, RegQueryInfoKeyA, RegEnumValueW, OpenSCManagerA, OpenServiceA, StartServiceA, QueryServiceStatus, CloseServiceHandle, RegisterServiceCtrlHandlerA, RevertToSelf
kernel32.dll
LocalAlloc, LocalFree, FormatMessageA, ReadFile, WriteFile, SetConsoleMode, GetConsoleMode, CreateFileA, ExpandEnvironmentStringsA, QueryPerformanceCounter, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, DelayLoadFailureHook, GetComputerNameExA, WriteProcessMemory, GetCurrentThreadId, IsBadWritePtr, IsBadCodePtr, ResetEvent, SwitchToThread, HeapCreate, HeapAlloc, CreateFileMappingA, MapViewOfFile, GetProcessHeap, HeapDestroy, HeapFree, UnmapViewOfFile, VirtualFree, GetSystemInfo, FormatMessageW, lstrcmpW, TerminateThread, CreateEventW, ResumeThread, SetEvent, lstrlenW, lstrcpyW, VirtualAlloc, CreateEventA, WaitForMultipleObjects, MultiByteToWideChar, LCMapStringW, WideCharToMultiByte, GetOverlappedResult, OpenProcess, GetCurrentProcess, DuplicateHandle, IsBadReadPtr, WaitForSingleObject, GetTickCount, InterlockedExchange, CreateThread, InterlockedExchangeAdd, GetCurrentThread, SetThreadPriority, GetCurrentProcessId, FreeLibraryAndExitThread, GetProcAddress, FreeLibrary, InterlockedCompareExchange, LoadLibraryA, GetLastError, Sleep, SetLastError, LeaveCriticalSection, EnterCriticalSection, GetModuleFileNameA, LoadLibraryW, ExpandEnvironmentStringsW, InterlockedDecrement, GetEnvironmentVariableA, CloseHandle, InitializeCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, PostQueuedCompletionStatus, CreateIoCompletionPort, InterlockedIncrement, SleepEx, OutputDebugStringA
msvcrt.dll
DllMain
ntdll.dll
NtSetIoCompletion, NtRemoveIoCompletion, NtClose, NtSetInformationFile, NtCreateEvent, NtSetInformationObject, NtCreateIoCompletion, RtlFreeHeap, RtlRegisterSecureMemoryCacheCallback, RtlAllocateHeap, DbgPrint, NtOpenKey, RtlInitUnicodeString, RtlQueryRegistryValues, RtlGetNtProductType, NtDeviceIoControlFile, NtCreateFile, NtCancelIoFile, RtlInitializeCriticalSectionAndSpinCount, RtlDeleteCriticalSection, NtSetEvent, RtlRaiseStatus, NtWaitForSingleObject, NtDelayExecution, NtLoadDriver, RtlAdjustPrivilege, RtlImpersonateSelf, NtQuerySystemTime, NtAlertThread, NtQueueApcThread, NtClearEvent, NtReadFile, NtWaitForMultipleObjects, RtlNtStatusToDosError, NtQueryEvent, RtlUnicodeStringToAnsiString, RtlFreeUnicodeString, RtlAnsiStringToUnicodeString, RtlInitAnsiString, RtlFreeAnsiString, RtlDestroyHeap, RtlCreateHeap, RtlDeregisterWaitEx, RtlQueueWorkItem, RtlRegisterWait, NtCreateWaitablePort, NtRequestWaitReplyPort, NtConnectPort, NtReplyPort, RtlIpv6StringToAddressA, RtlIpv6StringToAddressW, RtlInitString, NtQueryValueKey, NtDuplicateObject, NtResetEvent, NtAcceptConnectPort, NtReplyWaitReceivePortEx, NtCompleteConnectPort
rpcrt4.dll
UuidFromStringW, UuidCreate, UuidToStringW, RpcStringFreeW
ws2_32.dll
WSAProviderConfigChange, WSARecv, WSCInstallProvider, WSCUpdateProvider, WSCDeinstallProvider, WSAEnumProtocolsW, WSAIoctl, WSCEnumProtocols, WSCGetProviderPath, WSASocketW
ws2help.dll
WahEnumerateHandleContexts, WahRemoveHandleContext, WahReferenceContextByHandle, WahInsertHandleContext, WahDestroyHandleContextTable, WahCreateHandleContextTable
Export table
AcceptEx
dn_expand
EnumProtocolsA
EnumProtocolsW
GetAcceptExSockaddrs
GetAddressByNameA
GetAddressByNameW
GetNameByTypeA
GetNameByTypeW
getnetbyname
GetServiceA
GetServiceW
GetTypeByNameA
GetTypeByNameW
inet_network
MigrateWinsockConfiguration
NPLoadNameSpaces
NSPStartup
rcmd
rexec
rresvport
s_perror
ServiceMain
sethostname
SetServiceA
SetServiceW
StartWsdpService
StopWsdpService
SvchostPushServiceGlobals
TransmitFile
WSARecvEx
WSPStartup

mswsock.dll

Microsoft Windows Sockets 2.0 Service Provider by Microsoft

Remove mswsock.dll
Version:   5.1.2600.5649 (xpsp_sp3_qfe.080728-1259)
MD5:   290c1a30defc723bbe10910ac2d6f6d0
SHA1:   d35e52abf18f98756537718533fa80c927ad54c7
SHA256:   b9cc2882b2a8f27b77fb6291471e07574281a16aaf14dc5d4b97be7a4589cb59
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

mswsock.dll is loaded as dynamic link library that runs in the context of a process. This version is installed on Windows XP.

DetailsDetails

File name:mswsock.dll
Publisher:Microsoft Corporation
Product name:Microsoft Windows Sockets 2.0 Service Provider
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\mswsock.dll
File version:5.1.2600.5649 (xpsp_sp3_qfe.080728-1259)
Product version:5.1.2600.5649
Size:239.5 KB (245,248 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'
  • Shared name is 'Nla'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 46.84% of Microsoft Windows Sockets 2.0 Service Provider.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 42.78%
Intel 12.83%
Toshiba 7.49%
Compaq 7.49%
American Megatrends 6.42%
GIGABYTE 5.35%
Hewlett-Packard 5.35%
Sahara 3.21%
ASUS 3.21%
Gateway 2.14%
Acer 1.60%
Lenovo 1.07%
Sony 1.07%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE