srmclient.dll

Description: Microsoft® File Server Resource Management Client Extensions

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: 8a39328615df355fe486aaa532beb3c5

File Size: 927.5 KB

Uploaded At: Dec. 1, 2025, 8:04 a.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x21050)
  • DllGetClassObject (Ordinal: 2, Address: 0x21070)

Imported DLLs & Functions

ACTIVEDS.dll
  • (Address: 0x100da000)
ADVAPI32.dll
  • ConvertSidToStringSidW (Address: 0x100da02c)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100da03c)
  • DeregisterEventSource (Address: 0x100da00c)
  • GetSecurityInfo (Address: 0x100da030)
  • LookupAccountSidW (Address: 0x100da018)
  • OpenProcessToken (Address: 0x100da010)
  • OpenThreadToken (Address: 0x100da014)
  • RegCloseKey (Address: 0x100da01c)
  • RegCreateKeyExW (Address: 0x100da008)
  • RegisterEventSourceW (Address: 0x100da038)
  • RegOpenKeyExW (Address: 0x100da034)
  • RegQueryValueExW (Address: 0x100da044)
  • RegSetValueExW (Address: 0x100da040)
  • ReportEventW (Address: 0x100da020)
  • SetSecurityInfo (Address: 0x100da028)
  • SetThreadToken (Address: 0x100da024)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x100da324)
  • CheckTokenMembership (Address: 0x100da308)
  • CopySid (Address: 0x100da32c)
  • CreateWellKnownSid (Address: 0x100da328)
  • FreeSid (Address: 0x100da318)
  • GetAce (Address: 0x100da320)
  • GetAclInformation (Address: 0x100da31c)
  • GetLengthSid (Address: 0x100da314)
  • GetTokenInformation (Address: 0x100da30c)
  • InitializeAcl (Address: 0x100da304)
  • MapGenericMask (Address: 0x100da310)
api-ms-win-security-base-l1-2-0.dll
  • AddResourceAttributeAce (Address: 0x100da334)
ATL.DLL
  • (Address: 0x100da04c)
  • (Address: 0x100da050)
  • (Address: 0x100da054)
  • (Address: 0x100da058)
  • (Address: 0x100da05c)
  • (Address: 0x100da060)
AUTHZ.dll
  • AuthzReportSecurityEventFromParams (Address: 0x100da068)
CLUSAPI.dll
  • CloseCluster (Address: 0x100da074)
  • ClusterRegCloseKey (Address: 0x100da070)
  • ClusterRegCreateKey (Address: 0x100da08c)
  • ClusterRegDeleteKey (Address: 0x100da098)
  • ClusterRegEnumKey (Address: 0x100da078)
  • ClusterRegOpenKey (Address: 0x100da094)
  • ClusterRegQueryValue (Address: 0x100da084)
  • ClusterRegSetValue (Address: 0x100da088)
  • GetClusterKey (Address: 0x100da080)
  • GetNodeClusterState (Address: 0x100da07c)
  • OpenCluster (Address: 0x100da090)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x100da0cc)
  • CheckRemoteDebuggerPresent (Address: 0x100da1b8)
  • CloseHandle (Address: 0x100da0e0)
  • CloseThreadpoolTimer (Address: 0x100da1e8)
  • CloseThreadpoolWait (Address: 0x100da16c)
  • CompareFileTime (Address: 0x100da1f0)
  • CreateDirectoryW (Address: 0x100da21c)
  • CreateEventW (Address: 0x100da164)
  • CreateFileW (Address: 0x100da0e4)
  • CreateThread (Address: 0x100da200)
  • CreateThreadpoolTimer (Address: 0x100da1e0)
  • CreateThreadpoolWait (Address: 0x100da154)
  • DebugBreak (Address: 0x100da1bc)
  • DeleteCriticalSection (Address: 0x100da0f8)
  • DeleteFileW (Address: 0x100da150)
  • DeviceIoControl (Address: 0x100da188)
  • DisableThreadLibraryCalls (Address: 0x100da100)
  • DuplicateHandle (Address: 0x100da174)
  • EnterCriticalSection (Address: 0x100da218)
  • ExitProcess (Address: 0x100da1c0)
  • ExpandEnvironmentStringsW (Address: 0x100da214)
  • FileTimeToLocalFileTime (Address: 0x100da1d0)
  • FileTimeToSystemTime (Address: 0x100da1d4)
  • FindClose (Address: 0x100da124)
  • FindFirstFileW (Address: 0x100da12c)
  • FindFirstVolumeMountPointW (Address: 0x100da19c)
  • FindNextFileW (Address: 0x100da128)
  • FindNextVolumeMountPointW (Address: 0x100da194)
  • FindVolumeMountPointClose (Address: 0x100da198)
  • FlushFileBuffers (Address: 0x100da140)
  • FormatMessageW (Address: 0x100da1b0)
  • FreeLibrary (Address: 0x100da138)
  • GetCommandLineW (Address: 0x100da134)
  • GetComputerNameW (Address: 0x100da0d8)
  • GetCurrentProcess (Address: 0x100da0b0)
  • GetCurrentProcessId (Address: 0x100da0bc)
  • GetCurrentThread (Address: 0x100da158)
  • GetCurrentThreadId (Address: 0x100da220)
  • GetDateFormatW (Address: 0x100da1c8)
  • GetDriveTypeW (Address: 0x100da13c)
  • GetFileAttributesW (Address: 0x100da204)
  • GetFileInformationByHandle (Address: 0x100da10c)
  • GetFileInformationByHandleEx (Address: 0x100da190)
  • GetFileSize (Address: 0x100da0dc)
  • GetFileSizeEx (Address: 0x100da18c)
  • GetFileTime (Address: 0x100da144)
  • GetFileType (Address: 0x100da11c)
  • GetLastError (Address: 0x100da0b8)
  • GetOverlappedResult (Address: 0x100da148)
  • GetSystemInfo (Address: 0x100da0fc)
  • GetSystemTime (Address: 0x100da1f4)
  • GetSystemTimeAsFileTime (Address: 0x100da0a0)
  • GetTickCount (Address: 0x100da0a4)
  • GetTimeFormatW (Address: 0x100da1cc)
  • GetVolumeInformationW (Address: 0x100da1ac)
  • GetVolumeNameForVolumeMountPointW (Address: 0x100da110)
  • GetVolumePathNamesForVolumeNameW (Address: 0x100da108)
  • GetVolumePathNameW (Address: 0x100da1a8)
  • GlobalLock (Address: 0x100da1c4)
  • GlobalUnlock (Address: 0x100da1b4)
  • InitializeCriticalSection (Address: 0x100da1a4)
  • InitializeCriticalSectionAndSpinCount (Address: 0x100da1a0)
  • LeaveCriticalSection (Address: 0x100da20c)
  • LoadLibraryExW (Address: 0x100da1d8)
  • LocalAlloc (Address: 0x100da178)
  • LocalFree (Address: 0x100da1f8)
  • MoveFileExW (Address: 0x100da120)
  • MoveFileW (Address: 0x100da118)
  • OpenProcess (Address: 0x100da170)
  • OutputDebugStringW (Address: 0x100da130)
  • PrivCopyFileExW (Address: 0x100da208)
  • QueryPerformanceCounter (Address: 0x100da0c0)
  • ReadFile (Address: 0x100da0f0)
  • ReleaseSRWLockExclusive (Address: 0x100da0d0)
  • ReOpenFile (Address: 0x100da104)
  • SetEndOfFile (Address: 0x100da0e8)
  • SetFileAttributesW (Address: 0x100da168)
  • SetFileInformationByHandle (Address: 0x100da15c)
  • SetFileTime (Address: 0x100da114)
  • SetThreadpoolTimer (Address: 0x100da1e4)
  • SetThreadpoolWait (Address: 0x100da14c)
  • SetThreadPriority (Address: 0x100da180)
  • SetUnhandledExceptionFilter (Address: 0x100da0ac)
  • Sleep (Address: 0x100da0d4)
  • SleepConditionVariableSRW (Address: 0x100da0c4)
  • SystemTimeToFileTime (Address: 0x100da1dc)
  • TerminateProcess (Address: 0x100da0b4)
  • UnhandledExceptionFilter (Address: 0x100da0a8)
  • VirtualAlloc (Address: 0x100da210)
  • VirtualProtect (Address: 0x100da1fc)
  • VirtualQuery (Address: 0x100da0f4)
  • WaitForMultipleObjects (Address: 0x100da184)
  • WaitForSingleObject (Address: 0x100da17c)
  • WaitForThreadpoolTimerCallbacks (Address: 0x100da1ec)
  • WaitForThreadpoolWaitCallbacks (Address: 0x100da160)
  • WakeAllConditionVariable (Address: 0x100da0c8)
  • WriteFile (Address: 0x100da0ec)
MPR.dll
  • WNetGetUniversalNameW (Address: 0x100da228)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x100da3d0)
  • __dllonexit (Address: 0x100da3a0)
  • _amsg_exit (Address: 0x100da3b8)
  • _callnewh (Address: 0x100da3e0)
  • _CxxThrowException (Address: 0x100da3d8)
  • _errno (Address: 0x100da358)
  • _except_handler4_common (Address: 0x100da3ac)
  • _i64tow_s (Address: 0x100da3c0)
  • _initterm (Address: 0x100da3b4)
  • _itow_s (Address: 0x100da348)
  • _lock (Address: 0x100da3a8)
  • _onexit (Address: 0x100da39c)
  • _purecall (Address: 0x100da3fc)
  • _snwscanf_s (Address: 0x100da384)
  • _ui64tow_s (Address: 0x100da368)
  • _unlock (Address: 0x100da3a4)
  • _vsnprintf (Address: 0x100da388)
  • _vsnwprintf (Address: 0x100da350)
  • _wcsicmp (Address: 0x100da340)
  • _wcsnicmp (Address: 0x100da33c)
  • _wcstoui64 (Address: 0x100da360)
  • _wtoi (Address: 0x100da344)
  • _wtoi64 (Address: 0x100da374)
  • _wtol (Address: 0x100da3c4)
  • _XcptFilter (Address: 0x100da3d4)
  • ??0exception@@QAE@ABQBD@Z (Address: 0x100da3f0)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x100da3ec)
  • ??0exception@@QAE@XZ (Address: 0x100da3dc)
  • ??1exception@@UAE@XZ (Address: 0x100da3f4)
  • ??1type_info@@UAE@XZ (Address: 0x100da398)
  • ?terminate@@YAXXZ (Address: 0x100da3b0)
  • ?what@exception@@UBEPBDXZ (Address: 0x100da3f8)
  • free (Address: 0x100da3e8)
  • iswalpha (Address: 0x100da370)
  • iswdigit (Address: 0x100da3bc)
  • iswspace (Address: 0x100da364)
  • malloc (Address: 0x100da3e4)
  • memcmp (Address: 0x100da38c)
  • memcpy (Address: 0x100da390)
  • memmove (Address: 0x100da394)
  • memset (Address: 0x100da404)
  • realloc (Address: 0x100da400)
  • swscanf (Address: 0x100da354)
  • towlower (Address: 0x100da378)
  • wcschr (Address: 0x100da34c)
  • wcscspn (Address: 0x100da36c)
  • wcsncmp (Address: 0x100da380)
  • wcsrchr (Address: 0x100da37c)
  • wcsstr (Address: 0x100da3cc)
  • wcstol (Address: 0x100da35c)
  • wcstoul (Address: 0x100da3c8)
NETAPI32.dll
  • DsGetDcNameW (Address: 0x100da230)
  • NetApiBufferFree (Address: 0x100da234)
  • NetGetJoinInformation (Address: 0x100da238)
ntdll.dll
  • NtCreateFile (Address: 0x100da420)
  • NtOpenFile (Address: 0x100da44c)
  • NtQueryInformationFile (Address: 0x100da458)
  • RtlAcquireResourceExclusive (Address: 0x100da438)
  • RtlAcquireResourceShared (Address: 0x100da444)
  • RtlCompareMemory (Address: 0x100da454)
  • RtlCreateSystemVolumeInformationFolder (Address: 0x100da430)
  • RtlDeleteResource (Address: 0x100da448)
  • RtlDosPathNameToNtPathName_U (Address: 0x100da42c)
  • RtlDosPathNameToRelativeNtPathName_U (Address: 0x100da424)
  • RtlFreeHeap (Address: 0x100da450)
  • RtlFreeUnicodeString (Address: 0x100da428)
  • RtlInitializeResource (Address: 0x100da43c)
  • RtlInitializeSid (Address: 0x100da414)
  • RtlInitUnicodeString (Address: 0x100da418)
  • RtlNtStatusToDosError (Address: 0x100da41c)
  • RtlReleaseResource (Address: 0x100da440)
  • RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x100da434)
  • WinSqmIsOptedIn (Address: 0x100da410)
  • WinSqmSetDWORD (Address: 0x100da40c)
ole32.dll
  • CLSIDFromString (Address: 0x100da474)
  • CoCreateGuid (Address: 0x100da478)
  • CoCreateInstance (Address: 0x100da49c)
  • CoCreateInstanceEx (Address: 0x100da4a0)
  • CoGetInterfaceAndReleaseStream (Address: 0x100da464)
  • CoImpersonateClient (Address: 0x100da488)
  • CoInitializeEx (Address: 0x100da46c)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x100da460)
  • CoRevertToSelf (Address: 0x100da490)
  • CoSetProxyBlanket (Address: 0x100da48c)
  • CoTaskMemAlloc (Address: 0x100da498)
  • CoTaskMemFree (Address: 0x100da494)
  • CoTaskMemRealloc (Address: 0x100da470)
  • CoUninitialize (Address: 0x100da468)
  • CreateStreamOnHGlobal (Address: 0x100da484)
  • GetHGlobalFromStream (Address: 0x100da480)
  • StringFromGUID2 (Address: 0x100da47c)
OLEAUT32.dll
  • CreateErrorInfo (Address: 0x100da278)
  • GetErrorInfo (Address: 0x100da274)
  • LoadRegTypeLib (Address: 0x100da280)
  • SafeArrayCopy (Address: 0x100da26c)
  • SafeArrayCreate (Address: 0x100da290)
  • SafeArrayCreateVector (Address: 0x100da25c)
  • SafeArrayDestroy (Address: 0x100da268)
  • SafeArrayGetElement (Address: 0x100da24c)
  • SafeArrayGetLBound (Address: 0x100da248)
  • SafeArrayGetUBound (Address: 0x100da250)
  • SafeArrayGetVartype (Address: 0x100da244)
  • SafeArrayPutElement (Address: 0x100da264)
  • SetErrorInfo (Address: 0x100da27c)
  • SysAllocString (Address: 0x100da258)
  • SysAllocStringLen (Address: 0x100da28c)
  • SysFreeString (Address: 0x100da288)
  • SysStringLen (Address: 0x100da284)
  • VariantChangeType (Address: 0x100da270)
  • VariantClear (Address: 0x100da260)
  • VariantCopy (Address: 0x100da254)
  • VariantInit (Address: 0x100da294)
  • VariantTimeToSystemTime (Address: 0x100da240)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x100da29c)
SHLWAPI.dll
  • (Address: 0x100da2a4)
  • PathFindFileNameW (Address: 0x100da2b0)
  • PathIsUNCW (Address: 0x100da2a8)
  • PathRemoveFileSpecW (Address: 0x100da2ac)
SrmTrace.DLL
  • (Address: 0x100da2b8)
  • (Address: 0x100da2bc)
  • (Address: 0x100da2c0)
  • (Address: 0x100da2c4)
  • (Address: 0x100da2c8)
  • (Address: 0x100da2cc)
  • (Address: 0x100da2d0)
  • (Address: 0x100da2d4)
  • (Address: 0x100da2d8)
USER32.dll
  • LoadStringW (Address: 0x100da2e0)
VSSAPI.DLL
  • CreateVssBackupComponentsInternal (Address: 0x100da2e8)
  • VssFreeSnapshotPropertiesInternal (Address: 0x100da2ec)
XmlLite.dll
  • CreateXmlReader (Address: 0x100da2f4)
  • CreateXmlWriter (Address: 0x100da2fc)
  • CreateXmlWriterOutputWithEncodingName (Address: 0x100da2f8)