Should I block it?

4%
4% of PCs block this file from running.

VersionsAdditional versions

2013,10,22,7337 14.29%
2013,10,17,235 14.29%
2013,09,27,133 14.29%
2013,05,13,5759 14.29%
2013,01,30,25 28.57%
2012,12,11,4700 14.29%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegSetValueExW, RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegOpenKeyExW
gdi32.dll
DeleteObject, SelectObject, PatBlt, DeleteDC, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap
gdiplus.dll
GdiplusStartup, GdipCloneImage, GdipGetImageEncoders, GdipGetImageEncodersSize, GdipDrawImagePointRectI, GdipSaveImageToStream, GdipDisposeImage, GdipFree, GdipCreateBitmapFromHBITMAP, GdipCreateBitmapFromScan0, GdipDeleteGraphics, GdipGetImageGraphicsContext, GdiplusShutdown, GdipAlloc
kernel32.dll
GetModuleFileNameW, WriteFile, GetPrivateProfileStringW, ReadFile, GetModuleHandleW, GetProcAddress, OpenMutexW, GetCurrentProcess, ResetEvent, ReleaseMutex, GetCurrentProcessId, IsBadReadPtr, SetCurrentDirectoryW, GetTickCount, LoadLibraryW, FreeLibrary, GetLocalTime, SystemTimeToFileTime, DeleteFileW, FindResourceExW, InterlockedIncrement, InterlockedCompareExchange, LocalFree, Sleep, SetEndOfFile, GetModuleFileNameA, GetFileAttributesA, SetFilePointer, LocalAlloc, CreateThread, GetComputerNameA, GetSystemDirectoryW, GetDiskFreeSpaceExW, GetWindowsDirectoryW, WritePrivateProfileStringW, IsValidCodePage, GetOEMCP, GetStdHandle, HeapCreate, VirtualAlloc, VirtualFree, ExitProcess, CreateFileW, GetFileAttributesW, WaitNamedPipeW, MapViewOfFile, OpenFileMappingW, CloseHandle, UnmapViewOfFile, GetPrivateProfileIntW, WaitForMultipleObjects, TerminateThread, WaitForSingleObject, SetEvent, CreateEventW, OpenEventW, lstrlenA, GetLastError, WideCharToMultiByte, lstrlenW, MultiByteToWideChar, FreeResource, LockResource, LoadResource, SizeofResource, FindResourceW, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, GetModuleHandleA, GetStringTypeW, GetStringTypeA, GetCPInfo, CreateFileA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, LCMapStringW, LCMapStringA, RtlUnwind, GetCommandLineA, CreateDirectoryA, GetSystemTimeAsFileTime, GetCurrentThreadId, ExitThread, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, InterlockedDecrement, RaiseException, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetFileType, GetStartupInfoA, GetConsoleCP, GetConsoleMode, FlushFileBuffers, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetLocaleInfoW, LoadLibraryA, QueryPerformanceCounter, IsValidLocale, EnumSystemLocalesA, GetUserDefaultLCID, SetHandleCount
ole32.dll
CoCreateGuid, CoGetInterfaceAndReleaseStream, CreateStreamOnHGlobal
psapi.dll
GetModuleFileNameExW
shell32.dll
ShellExecuteW, SHGetSpecialFolderPathW, SHGetFolderPathW
shlwapi.dll
StrStrW, PathFindFileNameW, StrStrIW, PathRemoveFileSpecW, PathFileExistsW, StrCmpNW, PathAppendA, PathAppendW
user32.dll
GetClientRect, GetWindowRect, WindowFromPoint, GetCursorPos, GetDC, UnregisterClassA
wininet.dll
InternetCrackUrlW, InternetCrackUrlA
Export table
NP_GetEntryPoints
NP_Initialize
NP_Shutdown

npkws.dll

Kingsoft Internet Security by Beijing Kingsoft Security software Co. (Signed)

Remove npkws.dll
Version:   2013,10,22,7337
MD5:   4a05fe149964fc982ac66bd5e4042363
SHA1:   cbba30bcb44706ec385bc44dff43e633b1b419c0

Overview

npkws.dll is loaded as dynamic link library that runs in the context of the Mozilla Firefox web browser. The file is digitally signed by Beijing Kingsoft Security software Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:npkws.dll
Publisher:Kingsoft Corporation
Product name:Kingsoft Internet Security
Description:Kingsoft Chrome WebShield
Typical file path:C:\Program Files\kingsoft\kingsoft antivirus\npkws.dll
File version:2013,10,22,7337
Product version:9,1,127829,7337
Size:859.85 KB (880,488 bytes)
Build date:10/22/2013 9:37 AM
Certificate
Issued to:Beijing Kingsoft Security software Co.
Authority (CA):VeriSign
Effective date:Sunday, December 25, 2011
Expiration date:Thursday, December 25, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Mozilla plugin
  • npkws

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 42.86%
Windows 8 Enterprise 28.57%
Windows 8.1 14.29%
Windows 7 Home Premium 14.29%

Distribution by countryDistribution by country

Taiwan installs about 42.86% of Kingsoft Internet Security.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 28.57%
Sony 28.57%
Alienware 14.29%
GIGABYTE 14.29%
Acer 14.29%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE