Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
kernel32.dll
SetLastError, ResetEvent, WaitForSingleObject, DeleteCriticalSection, CloseHandle, InitializeCriticalSection, CreateEventW, LocalFree, lstrcmpW, SetEvent, EnterCriticalSection, GetLastError, LeaveCriticalSection, WaitForMultipleObjects, LocalLock, LocalUnlock, LocalReAlloc, GlobalMemoryStatus, GetVersion, DosPathToSessionPathW, GetLocalTime, RegQueryInfoKeyW, GetComputerNameExW, LocalAlloc, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, Sleep, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetProcAddress, DelayLoadFailureHook, DnsHostnameToComputerNameW, AddLocalAlternateComputerNameW, RemoveLocalAlternateComputerNameW, SetLocalPrimaryComputerNameW, EnumerateLocalComputerNamesW, GetVersionExW, SetComputerNameExW, InterlockedExchange, HeapFree, HeapAlloc, GetCurrentThread, QueryDosDeviceW, OpenEventW, SetUnhandledExceptionFilter, CreateFileW, DefineDosDeviceW
msvcrt.dll
DllMain
netjoin.dll
NetpQueryService, NetpCrackNamesStatus2Win32Error, NetpGetMachineAccountName, NetpSeparateUserAndDomain, NetpControlServices, NetpAvoidNetlogonSpnSet, NetSetuppOpenLog, NetSetuppCloseLog, NetpManageIPCConnect, NetpLogPrintHelper, NetpGetListOfJoinableOUs, NetpChangeMachineName, NetpGetJoinInformation, NetpValidateName, NetpGetLsaPrimaryDomain, NetpUnJoinDomain, NetpIsSetupInProgress, NetpGetNewMachineName, NetpDoDomainJoin, NetpMachineValidToJoin
netutils.dll
NetApiBufferAllocate, NetpwPathType, NetpwPathCanonicalize, NetpwNameCanonicalize, NetpwListCanonicalize, NetpwListTraverse, NetApiBufferFree
ntdll.dll
NtCreateEvent, RtlInitializeGenericTable, RtlLookupElementGenericTable, RtlInsertElementGenericTable, RtlEnumerateGenericTable, RtlDeleteElementGenericTable, RtlCompareMemory, RtlInitString, RtlMapSecurityErrorToNtStatus, NtCreateFile, RtlIntegerToUnicodeString, RtlAppendUnicodeStringToString, RtlRunDecodeUnicodeString, RtlRunEncodeUnicodeString, NtQueryVolumeInformationFile, RtlQueryRegistryValues, RtlGetNtProductType, NtOpenThreadToken, NtQueryInformationToken, RtlCompareUnicodeString, NtClose, NtDeviceIoControlFile, NtFsControlFile, RtlInitUnicodeString, NtOpenFile, RtlCopyLuid, RtlAcquireResourceShared, RtlDeleteResource, DbgPrint, RtlInitializeResource, RtlNtStatusToDosError, RtlDeregisterWaitEx, RtlDeregisterWait, RtlAcquireResourceExclusive, RtlReleaseResource, RtlRegisterWait, NtAccessCheckAndAuditAlarm, RtlAdjustPrivilege, RtlCompareMemoryUlong, RtlCopySid, RtlDeleteSecurityObject, RtlLengthSid, RtlSetSaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAce, RtlCreateAcl, RtlNewSecurityObject, NtOpenProcessToken, WinSqmIsOptedIn, WinSqmSetDWORD
rpcrt4.dll
RpcBindingFree, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcBindingServerFromClient, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerUnregisterIf, RpcImpersonateClient, RpcRevertToSelf, I_RpcBindingIsClientLocal, NdrServerCall2, RpcStringFreeW
Export table
ServiceMain
SvchostPushServiceGlobals

wkssvc.dll

Archivo DLL del servicio Estación de trabajo by Microsoft

Remove wkssvc.dll
Version:   6.1.7264.0 (win7_rtm.090622-1900)
MD5:   fafbc0e0c67a01b8b8f9b85c98b29bd9
SHA1:   40c9d2c881fdfb93ab9472fbe67bddb76feac190
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

wkssvc.dll is loaded as dynamic link library that runs in the context of a process. This version is designed to run on Windows 7.

DetailsDetails

File name:wkssvc.dll
Publisher:Microsoft Corporation
Product name:Archivo DLL del servicio Estación de trabajo
Description:Sistema operativo Microsoft® Windows®
Typical file path:C:\Windows\System32\wkssvc.dll
Original name:WKSSVC.DLL.MUI
File version:6.1.7264.0 (win7_rtm.090622-1900)
Product version:6.1.7264.0
Size:82.5 KB (84,480 bytes)
Build date:7/11/2009 12:59 AM
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted service
Runs as a shared service under the Windows svcHost
  • Shared name is 'LanmanWorkstation'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE