Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

9.07.0613.0 50.00%
9.07.0613.0 50.00%
(Note, Microsoft Corporation publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegQueryInfoKeyW, RegQueryValueExW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegDeleteKeyW
gdi32.dll
GetStockObject, GetDeviceCaps, CreateFontIndirectW, TranslateCharsetInfo, CreateCompatibleBitmap, CreateCompatibleDC, GetObjectW, DeleteObject, DeleteDC, SelectObject, BitBlt, CreateSolidBrush
kernel32.dll
MultiByteToWideChar, SetEvent, InitializeCriticalSection, FreeLibrary, lstrcmpiW, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, InterlockedDecrement, InterlockedIncrement, GetModuleHandleW, GetCurrentThreadId, DeleteCriticalSection, lstrcpynA, lstrcpynW, lstrlenW, GetVersionExW, CloseHandle, GetCurrentProcess, GetVersionExA, LeaveCriticalSection, GetModuleFileNameW, lstrcmpW, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, GetVersion, SetLastError, EnterCriticalSection, CreateSemaphoreW, GetLastError, Sleep, RaiseException, IsValidCodePage, WideCharToMultiByte, IsValidLocale, GetUserDefaultLCID, GetACP, GetCommandLineW, HeapFree, GetProcessHeap, HeapAlloc, InterlockedCompareExchange, GetProcAddress, LoadLibraryA, IsProcessorFeaturePresent, VirtualFree, VirtualAlloc, InterlockedExchange, GetLocaleInfoA, GetThreadLocale, GetStartupInfoA, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, FlushInstructionCache
msvcr80.dll
DllMain
ole32.dll
CoTaskMemFree, CoTaskMemRealloc, OleUninitialize, CoTaskMemAlloc, StringFromGUID2, OleLockRunning, CoCreateInstance, CoGetClassObject, CLSIDFromProgID, CLSIDFromString, CreateStreamOnHGlobal, OleInitialize
user32.dll
RegisterWindowMessageA, CreateWindowExW, MessageBoxW, DeleteMenu, SetRect, IsMenu, GetSysColor, BeginPaint, FillRect, EndPaint, GetDC, ReleaseDC, IsChild, GetDlgItem, RedrawWindow, DestroyWindow, GetClassNameW, CharNextW, CreateAcceleratorTableW, ClientToScreen, GetParent, SetCapture, ReleaseCapture, InvalidateRect, InvalidateRgn, SetWindowLongW, GetClassInfoExW, LoadCursorW, RegisterClassExW, ShowWindow, CallWindowProcW, LoadAcceleratorsW, LoadMenuW, GetMessageW, TranslateMessage, DispatchMessageW, wsprintfW, LoadImageW, DefWindowProcW, GetMenuItemInfoW, RemoveMenu, GetMenuItemCount, AppendMenuW, GetFocus, GetDesktopWindow, GetKeyState, GetWindow, GetTopWindow, PostMessageW, MoveWindow, GetWindowTextLengthW, GetWindowTextW, SetWindowTextW, ScreenToClient, DestroyAcceleratorTable, DestroyMenu, CreatePopupMenu, GetWindowRect, GetWindowLongW, PtInRect, PeekMessageW, TrackPopupMenuEx, IsWindow, MapWindowPoints, MessageBeep, SetWindowPos, GetClientRect, LoadStringA, PostQuitMessage, SetFocus, IsWindowVisible, LoadStringW, CallNextHookEx, UnhookWindowsHookEx, SetWindowsHookExW, SendMessageW, RegisterWindowMessageW, FindWindowW, UnregisterClassA
wkwbl90.dll
WksSqmOnBroadcast, WksSqmEnd, WksSqmBegin, WksSqmRegWinMsg

WksWp.exe

Microsoft Works 9 by Microsoft Corporation (Signed)

Remove WksWp.exe
Version:   9.07.0613.0
MD5:   21725d27021a41cd764bbfb4110cc918
SHA1:   5d1dbf9241561c806615ae413ea673a093f4b556
SHA256:   05091d5c90da5a463bfb84dd12a9e0b7274578be9b25e7b3f329b5590d7b58e7

Overview

wkswp.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. This is typically installed with the program Microsoft Works published by Microsoft Corporation. The file is digitally signed by Microsoft Corporation.

DetailsDetails

File name:wkswp.exe
Publisher:Microsoft® Corporation
Product name:Microsoft® Works 9
Description:Microsoft® Works Word Processor
Typical file path:C:\Program Files\microsoft works\wkswp.exe
File version:9.07.0613.0
Product version:9.07.0613.0
Size:693.34 KB (709,984 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Tuesday, April 4, 2006
Expiration date:Thursday, October 4, 2007
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Microsoft Corporation
1% remove
Microsoft Works is an integrated package software that was produced by Microsoft. Works is smaller, less expensive, and has fewer features than Microsoft Office or other major office suites. Its core functionality includes a word processor, a spreadsheet and a database management system. Microsoft Works has built-in compatibility for the Microsoft Office document formats (DOC and XLS), including, but not limited to, the ability of the W...
Network connections
  • [UDP] listens on port 59702

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01197444%
    0.028634%
    Kernel CPU:0.01118550%
    0.013761%
    User CPU:0.00078895%
    0.014873%
    Kernel CPU time:1,716 ms/min
    100,923,805ms/min
    Memory
    Private memory:15.8 MB
    21.59 MB
    Private (maximum):39.07 MB
    Private (minimum):38.61 MB
    Non-paged memory:15.8 MB
    21.59 MB
    Virtual memory:228.66 MB
    140.96 MB
    Virtual memory (peak):249.21 MB
    169.69 MB
    Working set:38.95 MB
    18.61 MB
    Working set (peak):39.23 MB
    37.95 MB
    Resource allocations
    Threads:18
    12
    Handles:498
    600
    GUI GDI count:222
    103
    GUI GDI peak:236
    142
    GUI USER count:154
    49
    GUI USER peak:162
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command line:"C:\Program Files\microsoft works\wkswp.exe"
    Owner:User
    Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    WksWP.exe (main module)
    Total CPU:0.01511420%
    0.272967%
    Kernel CPU:0.00938129%
    0.107585%
    User CPU:0.00573292%
    0.165382%
    CPU cycles:332,119/sec
    5,741,424/sec
    Context switches:9/sec
    79/sec
    Memory:684 KB
    1.16 MB
    ntdll.dll
    Total CPU:0.00156466%
    Kernel CPU:0.00104311%
    User CPU:0.00052155%
    CPU cycles:26,587/sec
    Memory:1.66 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows Vista Home Premium 50.00%
    Windows 7 Home Premium 50.00%

    Distribution by countryDistribution by country

    United States installs about 100.00% of Microsoft® Works 9.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Toshiba 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE