Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 3.66%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.10%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.14%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.05%
6.2.9200.16384 (win8_rtm.120725-1247) 2.42%
6.2.9200.16384 (win8_rtm.120725-1247) 11.83%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.10%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.10%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.05%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.10%
6.1.7600.16385 (win7_rtm.090713-1255) 30.17%
6.1.7600.16385 (win7_rtm.090713-1255) 5.13%
6.1.7600.16385 (win7_rtm.090713-1255) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 18.19%
6.1.7600.16385 (win7_rtm.090713-1255) 2.99%
6.0.6000.16386 (vista_rtm.061101-2205) 1.09%
6.0.6000.16386 (vista_rtm.061101-2205) 0.38%
6.0.6000.16386 (vista_rtm.061101-2205) 5.75%
6.0.6000.16386 (vista_rtm.061101-2205) 0.43%
5.2.3790.4530 (srv03_sp2_gdr.090615-1611) 0.05%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.05%
5.1.2600.5826 (xpsp_sp3_qfe.090609-1445) 1.33%
5.1.2600.5826 (xpsp_sp3_qfe.090609-1445) 0.10%
5.1.2600.5826 (xpsp_sp3_qfe.090609-1445) 0.14%
5.1.2600.5826 (xpsp_sp3_qfe.090609-1445) 0.14%
View more

PE structurePE file structure

Show functions
Import table
advapi32.dll
StartServiceW, SetServiceStatus, I_ScSetServiceBitsW, SystemFunction029, MD5Init, MD5Update, MD5Final, RegQueryValueExW, SystemFunction007, SystemFunction001, RegQueryInfoKeyW, LsaDelete, LsaCreateSecret, LsaQuerySecret, LsaSetSecret, LsaSetInformationPolicy, RegDeleteKeyW, RegCreateKeyExW, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, LookupAccountSidW, GetSidSubAuthorityCount, GetSidSubAuthority, RegOpenKeyW, LsaOpenSecret, ChangeServiceConfigW, RegNotifyChangeKeyValue, EnumDependentServicesW, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, QueryServiceStatus, CloseServiceHandle, RegConnectRegistryW, SetThreadToken, RevertToSelf, OpenThreadToken, RegisterEventSourceW, ReportEventW, DeregisterEventSource, LsaOpenPolicy, ConvertStringSecurityDescriptorToSecurityDescriptorW, LsaQueryInformationPolicy, LsaFreeMemory, LsaClose, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegisterServiceCtrlHandlerExW
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll
SetLastError, GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll
CreateFileW, DefineDosDeviceW, QueryDosDeviceW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapFree, GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalReAlloc, LocalAlloc, LocalFree, LocalUnlock, LocalLock
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange, InterlockedDecrement, InterlockedIncrement
api-ms-win-core-io-l1-1-1.dll
CreateIoCompletionPort, GetQueuedCompletionStatus, PostQueuedCompletionStatus
api-ms-win-core-kernel32-legacy-l1-1-0.dll
AddLocalAlternateComputerNameW, DnsHostnameToComputerNameW
api-ms-win-core-kernel32-private-l1-1-0.dll
SetLocalPrimaryComputerNameW, RemoveLocalAlternateComputerNameW, DosPathToSessionPathW, EnumerateLocalComputerNamesW
api-ms-win-core-processthreads-l1-1-1.dll
CreateThread, GetCurrentProcessId, GetCurrentProcess, TerminateProcess, OpenThreadToken, SetThreadToken, GetCurrentThread, GetCurrentThreadId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegCloseKey, RegOpenKeyExW, RegQueryInfoKeyW, RegQueryValueExW, RegSetValueExW, RegNotifyChangeKeyValue
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpW
api-ms-win-core-synch-l1-2-0.dll
EnterCriticalSection, SetEvent, InitializeCriticalSection, LeaveCriticalSection, WaitForSingleObject, ResetEvent, OpenEventW, WaitForMultipleObjectsEx, Sleep, DeleteCriticalSection, CreateEventW
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount, SetComputerNameExW, GetVersion, GetLocalTime, GetComputerNameExW, GetVersionExW, GlobalMemoryStatusEx
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolTimer, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroup, WaitForThreadpoolTimerCallbacks, CloseThreadpoolTimer, CloseThreadpoolCleanupGroupMembers, TrySubmitThreadpoolCallback
api-ms-win-eventing-classicprovider-l1-1-0.dll
RegisterTraceGuidsW, GetTraceEnableLevel, GetTraceLoggerHandle, TraceMessage, UnregisterTraceGuids, GetTraceEnableFlags
api-ms-win-eventing-provider-l1-1-0.dll
EventUnregister, EventRegister, EventWrite
api-ms-win-security-activedirectoryclient-l1-1-0.dll
DsBindWithSpnExW, DsMakePasswordCredentialsW, DsCrackNamesW, DsFreeNameResultW, DsUnBindW, DsGetDomainControllerInfoW, DsFreeDomainControllerInfoW, DsFreePasswordCredentials
api-ms-win-security-base-l1-2-0.dll
CheckTokenMembership, CreateWellKnownSid, RevertToSelf
api-ms-win-security-lsalookup-l1-1-1.dll
LsaLookupGetDomainInfo, LsaLookupOpenLocalPolicy, LsaLookupClose, LsaLookupFreeMemory
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-private-l1-1-0.dll
I_ScSetServiceBitsW
iphlpapi.dll
CancelMibChangeNotify2, GetIfEntry2, NotifyIpInterfaceChange
kernel32.dll
SetLastError, ResetEvent, WaitForSingleObject, DeleteCriticalSection, CloseHandle, InitializeCriticalSection, CreateEventW, LocalFree, lstrcmpW, SetEvent, EnterCriticalSection, GetLastError, LeaveCriticalSection, WaitForMultipleObjects, LocalLock, LocalUnlock, LocalReAlloc, GlobalMemoryStatus, GetVersion, DosPathToSessionPathW, GetLocalTime, RegQueryInfoKeyW, GetComputerNameExW, LocalAlloc, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, Sleep, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetProcAddress, DelayLoadFailureHook, DnsHostnameToComputerNameW, AddLocalAlternateComputerNameW, RemoveLocalAlternateComputerNameW, SetLocalPrimaryComputerNameW, EnumerateLocalComputerNamesW, GetVersionExW, SetComputerNameExW, InterlockedExchange, HeapFree, HeapAlloc, GetCurrentThread, QueryDosDeviceW, OpenEventW, SetUnhandledExceptionFilter, CreateFileW, DefineDosDeviceW, GlobalFree, LoadLibraryW, GetComputerNameW, GetSystemWindowsDirectoryW, LoadLibraryA, FlushFileBuffers, SetFilePointer, WideCharToMultiByte, GetWindowsDirectoryW, GetFileAttributesW, CreateDirectoryW, GetFileSize, WriteFile, MoveFileExW, ReadFile
msvcrt.dll
DllMain
netapi32.dll
DsGetDcNameWithAccountW, NetApiBufferFree, I_NetListTraverse, I_NetListCanonicalize, I_NetNameCanonicalize, I_NetPathType, NetUnregisterDomainNameChangeNotification, NetRegisterDomainNameChangeNotification, DsRoleGetPrimaryDomainInformation, DsRoleFreeMemory, DsGetDcNameW, NetApiBufferAllocate, NetUserGetInfo, I_NetServerReqChallenge, I_NetServerAuthenticate, NetUseDel, NetUseAdd, Netbios, NetLocalGroupAddMember, NetLocalGroupDelMember, DsEnumerateDomainTrustsW, I_NetNameCompare, I_NetNameValidate, NetUserAdd, NetUserSetInfo, NetpIsRemote, I_NetPathCanonicalize
netjoin.dll
NetpQueryService, NetpCrackNamesStatus2Win32Error, NetpGetMachineAccountName, NetpSeparateUserAndDomain, NetpControlServices, NetpAvoidNetlogonSpnSet, NetSetuppOpenLog, NetSetuppCloseLog, NetpManageIPCConnect, NetpLogPrintHelper, NetpGetListOfJoinableOUs, NetpChangeMachineName, NetpGetJoinInformation, NetpValidateName, NetpGetLsaPrimaryDomain, NetpUnJoinDomain, NetpIsSetupInProgress, NetpGetNewMachineName, NetpDoDomainJoin, NetpMachineValidToJoin
netutils.dll
NetApiBufferAllocate, NetpwPathType, NetpwPathCanonicalize, NetpwNameCanonicalize, NetpwListCanonicalize, NetpwListTraverse, NetApiBufferFree
ntdll.dll
NtCreateEvent, RtlInitializeGenericTable, RtlLookupElementGenericTable, RtlInsertElementGenericTable, RtlEnumerateGenericTable, RtlDeleteElementGenericTable, RtlCompareMemory, RtlInitString, RtlMapSecurityErrorToNtStatus, NtCreateFile, RtlIntegerToUnicodeString, RtlAppendUnicodeStringToString, RtlRunDecodeUnicodeString, RtlRunEncodeUnicodeString, NtQueryVolumeInformationFile, RtlQueryRegistryValues, RtlGetNtProductType, NtOpenThreadToken, NtQueryInformationToken, RtlCompareUnicodeString, NtClose, NtDeviceIoControlFile, NtFsControlFile, RtlInitUnicodeString, NtOpenFile, RtlCopyLuid, RtlAcquireResourceShared, RtlDeleteResource, DbgPrint, RtlInitializeResource, RtlNtStatusToDosError, RtlDeregisterWaitEx, RtlDeregisterWait, RtlAcquireResourceExclusive, RtlReleaseResource, RtlRegisterWait, NtAccessCheckAndAuditAlarm, RtlAdjustPrivilege, RtlCompareMemoryUlong, RtlCopySid, RtlDeleteSecurityObject, RtlLengthSid, RtlSetSaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAce, RtlCreateAcl, RtlNewSecurityObject, NtOpenProcessToken, WinSqmIsOptedIn, WinSqmSetDWORD, RtlInitializeSid, RtlSubAuthoritySid, RtlEqualSid, RtlFreeUnicodeString, RtlConvertSidToUnicodeString, RtlFreeOemString, RtlUnicodeStringToOemString, RtlDowncaseUnicodeString, NtQueryInformationProcess, NtQueryLicenseValue, RtlIpv4AddressToStringW, RtlIpv6AddressToStringW, RtlIpv4StringToAddressW, RtlIpv6StringToAddressW, RtlIpv4AddressToStringExW, RtlIpv6AddressToStringExW, RtlQueryRegistryValuesEx
ntdsapi.dll
DsFreeNameResultW, DsMakePasswordCredentialsW, DsBindWithCredW, DsCrackNamesW, DsFreePasswordCredentials, DsUnBindW
rpcrt4.dll
RpcBindingFree, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcBindingServerFromClient, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerUnregisterIf, RpcImpersonateClient, RpcRevertToSelf, I_RpcBindingIsClientLocal, NdrServerCall2, RpcStringFreeW, RpcAsyncCompleteCall, RpcServerInqBindings, RpcAsyncAbortCall, NdrClientCall2, NdrAsyncClientCall, I_RpcExceptionFilter, RpcMgmtSetComTimeout, NdrAsyncServerCall, RpcBindingSetAuthInfoExW, RpcMgmtInqServerPrincNameW, RpcEpResolveBinding, RpcBindingFromStringBindingW, RpcStringBindingComposeW, UuidToStringW, UuidCompare, RpcAsyncInitializeHandle, RpcAsyncCancelCall, RpcEpRegisterW, RpcServerUseProtseqW, RpcBindingVectorFree, RpcServerTestCancel, RpcServerUnregisterIfEx, I_RpcMapWin32Status, RpcEpUnregister, RpcServerInqCallAttributesW
samlib.dll
SamCloseHandle, SamSetInformationUser, SamQueryInformationUser, SamOpenUser, SamFreeMemory, SamLookupNamesInDomain, SamOpenDomain, SamConnect
secur32.dll
LsaCallAuthenticationPackage, LsaDeregisterLogonProcess, LsaConnectUntrusted, LsaLookupAuthenticationPackage, LsaFreeReturnBuffer
user32.dll
UnregisterDeviceNotification, RegisterDeviceNotificationW
winbrand.dll
BrandingFormatString
Export table
ServiceMain
SvchostPushServiceGlobals

wkssvc.dll

Workstation Service DLL by Microsoft

Remove wkssvc.dll
Version:   5.1.2600.3235 (xpsp_sp2_qfe.071016-1326)
MD5:   2299b1933cd9207630a00676e390f32f
SHA1:   b9524a0407a0570e0f8735265135b378701dba86
SHA256:   76ecf62b6f0c6b689477443b0b1b92af6819f20b3e9e719c12a35b23742b647d
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

wkssvc.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is installed on Windows XP.

DetailsDetails

File name:wkssvc.dll
Publisher:Microsoft Corporation
Product name:Workstation Service DLL
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\wkssvc.dll
Original name:WKSSVC.DLL.MUI
File version:5.1.2600.3235 (xpsp_sp2_qfe.071016-1326)
Product version:5.1.2600.3235
Size:129 KB (132,096 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'
  • Shared name is 'LanmanWorkstation'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 52.00%
Windows 7 Ultimate 28.00%
Windows 7 Professional 10.50%
Windows 7 Home Basic 3.00%
Windows 8 Pro 2.00%
Windows 7 Starter 1.50%
Windows 8 Enterprise Evaluation 0.50%
Windows 7 Enterprise 0.50%
Windows Se7en Titan 0.50%
Windows 8 Pro with Media Center 0.50%
Windows 8 0.50%
Windows Vista Business 0.50%

Distribution by countryDistribution by country

United States installs about 39.90% of Workstation Service DLL.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 24.15%
ASUS 14.34%
Hewlett-Packard 13.96%
Acer 13.96%
Toshiba 11.32%
Lenovo 4.53%
Sony 3.77%
Intel 3.02%
GIGABYTE 2.64%
Samsung 2.26%
MSI 1.51%
Alienware 1.13%
Medion 0.75%
Gateway 0.75%
NEC 0.75%
Compaq 0.75%
Sahara 0.38%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE