Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.1.2600.5512 (xpsp.080413-2113) 68.00%
5.1.2600.5512 (xpsp.080413-2113) 4.00%
5.1.2600.5512 (xpsp.080413-2113) 8.00%
5.1.2600.5512 (xpsp.080413-2113) 4.00%
5.1.2600.3015 (xpsp_sp2_gdr.061013-0145) 4.00%
5.1.2600.3015 (xpsp.061013-0149) 4.00%
5.1.2600.2736 (xpsp.050810-1536) 4.00%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 4.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
SetServiceStatus, RegEnumValueW, LsaQuerySecret, LsaClose, LsaCreateSecret, LsaSetSecret, LsaDelete, LsaOpenSecret, LsaOpenPolicy, RegDeleteKeyW, RegDeleteValueW, LsaFreeMemory, RegSetValueExW, RegCreateKeyExW, RegEnumKeyW, GetUserNameW, OpenThreadToken, GetTokenInformation, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegisterServiceCtrlHandlerW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW
kernel32.dll
LocalFileTimeToFileTime, FileTimeToSystemTime, lstrlenA, SystemTimeToFileTime, LeaveCriticalSection, lstrcmpiW, QueryDosDeviceW, DosPathToSessionPathW, DefineDosDeviceW, GetCurrentThread, LocalAlloc, WaitForSingleObject, CreateEventW, CreateThread, WaitForMultipleObjects, ExitThread, FormatMessageW, SetEvent, CloseHandle, LocalFree, LocalReAlloc, DisableThreadLibraryCalls, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, WideCharToMultiByte, GetLastError, lstrcmpW, EnterCriticalSection, SetConsoleCtrlHandler, LoadLibraryW, GetProcAddress, FreeLibrary, InitializeCriticalSection, DeleteCriticalSection
msvcrt.dll
DllMain
netapi32.dll
NetShareDelSticky
ntdll.dll
NtUnloadDriver, RtlNtStatusToDosError, NtOpenThreadToken, NtQueryInformationToken, NtQueryDefaultLocale, RtlInitUnicodeString, NtFsControlFile, NtLoadDriver, RtlAdjustPrivilege, NtQueryValueKey, RtlOemStringToUnicodeString, RtlInitAnsiString, NtQueryInformationProcess, NtClose, RtlCopyLuid, RtlCopyUnicodeString, NtOpenFile, NtCreateFile, RtlRunEncodeUnicodeString, RtlRunDecodeUnicodeString, NtQueryDirectoryFile, RtlInitString, RtlFreeOemString, RtlUnicodeStringToOemString, NtWriteFile, RtlQueryRegistryValues
nwapi32.dll
NwNdsGetQueueInformation, NWReadPropertyValue, NWDetachFromFileServer, NWAttachToFileServerW, UnmapSpecialJapaneseChars, NwNdsChangePassword, NWGetFileServerVersionInfo, NwNdsOpenTreeHandle, NwNdsResolveName, NwlibMakeNcp, NwLibCanonLocalName, NwLibCanonUserName, NwLibCanonRemoteName, NwNdsList, NwlibCopyStringToBuffer, NwNdsReadObjectInfo, NwNdsOpenGenericHandle, MapSpecialJapaneseChars
nwprovau.dll
NwDeregisterService, NwRegisterService, NwGetService, NwInitializeServiceProvider
rpcrt4.dll
RpcStringFreeW, RpcBindingFree, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcBindingServerFromClient, RpcServerUnregisterIf, RpcRevertToSelf, RpcImpersonateClient, NdrServerCall2, RpcServerUseProtseqEpW, RpcServerRegisterIfEx
secur32.dll
LsaRegisterLogonProcess, LsaCallAuthenticationPackage, LsaFreeReturnBuffer, LsaLookupAuthenticationPackage, LsaDeregisterLogonProcess
user32.dll
MessageBoxW, wsprintfW, CharUpperW, MessageBeep
ws2_32.dll
WSALookupServiceBeginW, WSALookupServiceNextW, WSALookupServiceEnd
Export table
ServiceMain
SvchostPushServiceGlobals

nwwks.dll

Client Service for Netware by Microsoft

Remove nwwks.dll
Version:   5.1.2600.5512 (xpsp.080413-2113)
MD5:   2c2fd0e6b0180f94c260dd26706aa5f4
SHA1:   64f21ae9781a82533754a838bd63924019791c0c
SHA256:   0ab7b33cf1ab6933f86390904aca08353c2e4b97b76edfecc309be9a3fca0d0e
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

nwwks.dll is loaded as dynamic link library that runs in the context of a process. This version is installed on Windows XP.

DetailsDetails

File name:nwwks.dll
Publisher:Microsoft Corporation
Product name:Client Service for Netware
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\nwwks.dll
File version:5.1.2600.5512 (xpsp.080413-2113)
Product version:5.1.2600.5512
Size:64 KB (65,536 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'
  • Shared name is 'NWCWorkstation'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 96.00%
Windows 7 Home Premium 4.00%

Distribution by countryDistribution by country

United States installs about 40.00% of Client Service for Netware.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 42.86%
GIGABYTE 28.57%
Lenovo 14.29%
Hewlett-Packard 7.14%
American Megatrends 7.14%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE