srmclient.dll
Description: Microsoft® File Server Resource Management Client Extensions
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 32-bit
Operating System: Windows NT
SHA256: 8a39328615df355fe486aaa532beb3c5
File Size: 927.5 KB
Uploaded At: Dec. 1, 2025, 8:04 a.m.
Views: 12
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x21050)
- DllGetClassObject (Ordinal: 2, Address: 0x21070)
Imported DLLs & Functions
ACTIVEDS.dll
- (Address: 0x100da000)
ADVAPI32.dll
- ConvertSidToStringSidW (Address: 0x100da02c)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100da03c)
- DeregisterEventSource (Address: 0x100da00c)
- GetSecurityInfo (Address: 0x100da030)
- LookupAccountSidW (Address: 0x100da018)
- OpenProcessToken (Address: 0x100da010)
- OpenThreadToken (Address: 0x100da014)
- RegCloseKey (Address: 0x100da01c)
- RegCreateKeyExW (Address: 0x100da008)
- RegisterEventSourceW (Address: 0x100da038)
- RegOpenKeyExW (Address: 0x100da034)
- RegQueryValueExW (Address: 0x100da044)
- RegSetValueExW (Address: 0x100da040)
- ReportEventW (Address: 0x100da020)
- SetSecurityInfo (Address: 0x100da028)
- SetThreadToken (Address: 0x100da024)
api-ms-win-security-base-l1-1-0.dll
- AllocateAndInitializeSid (Address: 0x100da324)
- CheckTokenMembership (Address: 0x100da308)
- CopySid (Address: 0x100da32c)
- CreateWellKnownSid (Address: 0x100da328)
- FreeSid (Address: 0x100da318)
- GetAce (Address: 0x100da320)
- GetAclInformation (Address: 0x100da31c)
- GetLengthSid (Address: 0x100da314)
- GetTokenInformation (Address: 0x100da30c)
- InitializeAcl (Address: 0x100da304)
- MapGenericMask (Address: 0x100da310)
api-ms-win-security-base-l1-2-0.dll
- AddResourceAttributeAce (Address: 0x100da334)
ATL.DLL
- (Address: 0x100da04c)
- (Address: 0x100da050)
- (Address: 0x100da054)
- (Address: 0x100da058)
- (Address: 0x100da05c)
- (Address: 0x100da060)
AUTHZ.dll
- AuthzReportSecurityEventFromParams (Address: 0x100da068)
CLUSAPI.dll
- CloseCluster (Address: 0x100da074)
- ClusterRegCloseKey (Address: 0x100da070)
- ClusterRegCreateKey (Address: 0x100da08c)
- ClusterRegDeleteKey (Address: 0x100da098)
- ClusterRegEnumKey (Address: 0x100da078)
- ClusterRegOpenKey (Address: 0x100da094)
- ClusterRegQueryValue (Address: 0x100da084)
- ClusterRegSetValue (Address: 0x100da088)
- GetClusterKey (Address: 0x100da080)
- GetNodeClusterState (Address: 0x100da07c)
- OpenCluster (Address: 0x100da090)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x100da0cc)
- CheckRemoteDebuggerPresent (Address: 0x100da1b8)
- CloseHandle (Address: 0x100da0e0)
- CloseThreadpoolTimer (Address: 0x100da1e8)
- CloseThreadpoolWait (Address: 0x100da16c)
- CompareFileTime (Address: 0x100da1f0)
- CreateDirectoryW (Address: 0x100da21c)
- CreateEventW (Address: 0x100da164)
- CreateFileW (Address: 0x100da0e4)
- CreateThread (Address: 0x100da200)
- CreateThreadpoolTimer (Address: 0x100da1e0)
- CreateThreadpoolWait (Address: 0x100da154)
- DebugBreak (Address: 0x100da1bc)
- DeleteCriticalSection (Address: 0x100da0f8)
- DeleteFileW (Address: 0x100da150)
- DeviceIoControl (Address: 0x100da188)
- DisableThreadLibraryCalls (Address: 0x100da100)
- DuplicateHandle (Address: 0x100da174)
- EnterCriticalSection (Address: 0x100da218)
- ExitProcess (Address: 0x100da1c0)
- ExpandEnvironmentStringsW (Address: 0x100da214)
- FileTimeToLocalFileTime (Address: 0x100da1d0)
- FileTimeToSystemTime (Address: 0x100da1d4)
- FindClose (Address: 0x100da124)
- FindFirstFileW (Address: 0x100da12c)
- FindFirstVolumeMountPointW (Address: 0x100da19c)
- FindNextFileW (Address: 0x100da128)
- FindNextVolumeMountPointW (Address: 0x100da194)
- FindVolumeMountPointClose (Address: 0x100da198)
- FlushFileBuffers (Address: 0x100da140)
- FormatMessageW (Address: 0x100da1b0)
- FreeLibrary (Address: 0x100da138)
- GetCommandLineW (Address: 0x100da134)
- GetComputerNameW (Address: 0x100da0d8)
- GetCurrentProcess (Address: 0x100da0b0)
- GetCurrentProcessId (Address: 0x100da0bc)
- GetCurrentThread (Address: 0x100da158)
- GetCurrentThreadId (Address: 0x100da220)
- GetDateFormatW (Address: 0x100da1c8)
- GetDriveTypeW (Address: 0x100da13c)
- GetFileAttributesW (Address: 0x100da204)
- GetFileInformationByHandle (Address: 0x100da10c)
- GetFileInformationByHandleEx (Address: 0x100da190)
- GetFileSize (Address: 0x100da0dc)
- GetFileSizeEx (Address: 0x100da18c)
- GetFileTime (Address: 0x100da144)
- GetFileType (Address: 0x100da11c)
- GetLastError (Address: 0x100da0b8)
- GetOverlappedResult (Address: 0x100da148)
- GetSystemInfo (Address: 0x100da0fc)
- GetSystemTime (Address: 0x100da1f4)
- GetSystemTimeAsFileTime (Address: 0x100da0a0)
- GetTickCount (Address: 0x100da0a4)
- GetTimeFormatW (Address: 0x100da1cc)
- GetVolumeInformationW (Address: 0x100da1ac)
- GetVolumeNameForVolumeMountPointW (Address: 0x100da110)
- GetVolumePathNamesForVolumeNameW (Address: 0x100da108)
- GetVolumePathNameW (Address: 0x100da1a8)
- GlobalLock (Address: 0x100da1c4)
- GlobalUnlock (Address: 0x100da1b4)
- InitializeCriticalSection (Address: 0x100da1a4)
- InitializeCriticalSectionAndSpinCount (Address: 0x100da1a0)
- LeaveCriticalSection (Address: 0x100da20c)
- LoadLibraryExW (Address: 0x100da1d8)
- LocalAlloc (Address: 0x100da178)
- LocalFree (Address: 0x100da1f8)
- MoveFileExW (Address: 0x100da120)
- MoveFileW (Address: 0x100da118)
- OpenProcess (Address: 0x100da170)
- OutputDebugStringW (Address: 0x100da130)
- PrivCopyFileExW (Address: 0x100da208)
- QueryPerformanceCounter (Address: 0x100da0c0)
- ReadFile (Address: 0x100da0f0)
- ReleaseSRWLockExclusive (Address: 0x100da0d0)
- ReOpenFile (Address: 0x100da104)
- SetEndOfFile (Address: 0x100da0e8)
- SetFileAttributesW (Address: 0x100da168)
- SetFileInformationByHandle (Address: 0x100da15c)
- SetFileTime (Address: 0x100da114)
- SetThreadpoolTimer (Address: 0x100da1e4)
- SetThreadpoolWait (Address: 0x100da14c)
- SetThreadPriority (Address: 0x100da180)
- SetUnhandledExceptionFilter (Address: 0x100da0ac)
- Sleep (Address: 0x100da0d4)
- SleepConditionVariableSRW (Address: 0x100da0c4)
- SystemTimeToFileTime (Address: 0x100da1dc)
- TerminateProcess (Address: 0x100da0b4)
- UnhandledExceptionFilter (Address: 0x100da0a8)
- VirtualAlloc (Address: 0x100da210)
- VirtualProtect (Address: 0x100da1fc)
- VirtualQuery (Address: 0x100da0f4)
- WaitForMultipleObjects (Address: 0x100da184)
- WaitForSingleObject (Address: 0x100da17c)
- WaitForThreadpoolTimerCallbacks (Address: 0x100da1ec)
- WaitForThreadpoolWaitCallbacks (Address: 0x100da160)
- WakeAllConditionVariable (Address: 0x100da0c8)
- WriteFile (Address: 0x100da0ec)
MPR.dll
- WNetGetUniversalNameW (Address: 0x100da228)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x100da3d0)
- __dllonexit (Address: 0x100da3a0)
- _amsg_exit (Address: 0x100da3b8)
- _callnewh (Address: 0x100da3e0)
- _CxxThrowException (Address: 0x100da3d8)
- _errno (Address: 0x100da358)
- _except_handler4_common (Address: 0x100da3ac)
- _i64tow_s (Address: 0x100da3c0)
- _initterm (Address: 0x100da3b4)
- _itow_s (Address: 0x100da348)
- _lock (Address: 0x100da3a8)
- _onexit (Address: 0x100da39c)
- _purecall (Address: 0x100da3fc)
- _snwscanf_s (Address: 0x100da384)
- _ui64tow_s (Address: 0x100da368)
- _unlock (Address: 0x100da3a4)
- _vsnprintf (Address: 0x100da388)
- _vsnwprintf (Address: 0x100da350)
- _wcsicmp (Address: 0x100da340)
- _wcsnicmp (Address: 0x100da33c)
- _wcstoui64 (Address: 0x100da360)
- _wtoi (Address: 0x100da344)
- _wtoi64 (Address: 0x100da374)
- _wtol (Address: 0x100da3c4)
- _XcptFilter (Address: 0x100da3d4)
- ??0exception@@QAE@ABQBD@Z (Address: 0x100da3f0)
- ??0exception@@QAE@ABV0@@Z (Address: 0x100da3ec)
- ??0exception@@QAE@XZ (Address: 0x100da3dc)
- ??1exception@@UAE@XZ (Address: 0x100da3f4)
- ??1type_info@@UAE@XZ (Address: 0x100da398)
- ?terminate@@YAXXZ (Address: 0x100da3b0)
- ?what@exception@@UBEPBDXZ (Address: 0x100da3f8)
- free (Address: 0x100da3e8)
- iswalpha (Address: 0x100da370)
- iswdigit (Address: 0x100da3bc)
- iswspace (Address: 0x100da364)
- malloc (Address: 0x100da3e4)
- memcmp (Address: 0x100da38c)
- memcpy (Address: 0x100da390)
- memmove (Address: 0x100da394)
- memset (Address: 0x100da404)
- realloc (Address: 0x100da400)
- swscanf (Address: 0x100da354)
- towlower (Address: 0x100da378)
- wcschr (Address: 0x100da34c)
- wcscspn (Address: 0x100da36c)
- wcsncmp (Address: 0x100da380)
- wcsrchr (Address: 0x100da37c)
- wcsstr (Address: 0x100da3cc)
- wcstol (Address: 0x100da35c)
- wcstoul (Address: 0x100da3c8)
NETAPI32.dll
- DsGetDcNameW (Address: 0x100da230)
- NetApiBufferFree (Address: 0x100da234)
- NetGetJoinInformation (Address: 0x100da238)
ntdll.dll
- NtCreateFile (Address: 0x100da420)
- NtOpenFile (Address: 0x100da44c)
- NtQueryInformationFile (Address: 0x100da458)
- RtlAcquireResourceExclusive (Address: 0x100da438)
- RtlAcquireResourceShared (Address: 0x100da444)
- RtlCompareMemory (Address: 0x100da454)
- RtlCreateSystemVolumeInformationFolder (Address: 0x100da430)
- RtlDeleteResource (Address: 0x100da448)
- RtlDosPathNameToNtPathName_U (Address: 0x100da42c)
- RtlDosPathNameToRelativeNtPathName_U (Address: 0x100da424)
- RtlFreeHeap (Address: 0x100da450)
- RtlFreeUnicodeString (Address: 0x100da428)
- RtlInitializeResource (Address: 0x100da43c)
- RtlInitializeSid (Address: 0x100da414)
- RtlInitUnicodeString (Address: 0x100da418)
- RtlNtStatusToDosError (Address: 0x100da41c)
- RtlReleaseResource (Address: 0x100da440)
- RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x100da434)
- WinSqmIsOptedIn (Address: 0x100da410)
- WinSqmSetDWORD (Address: 0x100da40c)
ole32.dll
- CLSIDFromString (Address: 0x100da474)
- CoCreateGuid (Address: 0x100da478)
- CoCreateInstance (Address: 0x100da49c)
- CoCreateInstanceEx (Address: 0x100da4a0)
- CoGetInterfaceAndReleaseStream (Address: 0x100da464)
- CoImpersonateClient (Address: 0x100da488)
- CoInitializeEx (Address: 0x100da46c)
- CoMarshalInterThreadInterfaceInStream (Address: 0x100da460)
- CoRevertToSelf (Address: 0x100da490)
- CoSetProxyBlanket (Address: 0x100da48c)
- CoTaskMemAlloc (Address: 0x100da498)
- CoTaskMemFree (Address: 0x100da494)
- CoTaskMemRealloc (Address: 0x100da470)
- CoUninitialize (Address: 0x100da468)
- CreateStreamOnHGlobal (Address: 0x100da484)
- GetHGlobalFromStream (Address: 0x100da480)
- StringFromGUID2 (Address: 0x100da47c)
OLEAUT32.dll
- CreateErrorInfo (Address: 0x100da278)
- GetErrorInfo (Address: 0x100da274)
- LoadRegTypeLib (Address: 0x100da280)
- SafeArrayCopy (Address: 0x100da26c)
- SafeArrayCreate (Address: 0x100da290)
- SafeArrayCreateVector (Address: 0x100da25c)
- SafeArrayDestroy (Address: 0x100da268)
- SafeArrayGetElement (Address: 0x100da24c)
- SafeArrayGetLBound (Address: 0x100da248)
- SafeArrayGetUBound (Address: 0x100da250)
- SafeArrayGetVartype (Address: 0x100da244)
- SafeArrayPutElement (Address: 0x100da264)
- SetErrorInfo (Address: 0x100da27c)
- SysAllocString (Address: 0x100da258)
- SysAllocStringLen (Address: 0x100da28c)
- SysFreeString (Address: 0x100da288)
- SysStringLen (Address: 0x100da284)
- VariantChangeType (Address: 0x100da270)
- VariantClear (Address: 0x100da260)
- VariantCopy (Address: 0x100da254)
- VariantInit (Address: 0x100da294)
- VariantTimeToSystemTime (Address: 0x100da240)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x100da29c)
SHLWAPI.dll
- (Address: 0x100da2a4)
- PathFindFileNameW (Address: 0x100da2b0)
- PathIsUNCW (Address: 0x100da2a8)
- PathRemoveFileSpecW (Address: 0x100da2ac)
SrmTrace.DLL
- (Address: 0x100da2b8)
- (Address: 0x100da2bc)
- (Address: 0x100da2c0)
- (Address: 0x100da2c4)
- (Address: 0x100da2c8)
- (Address: 0x100da2cc)
- (Address: 0x100da2d0)
- (Address: 0x100da2d4)
- (Address: 0x100da2d8)
USER32.dll
- LoadStringW (Address: 0x100da2e0)
VSSAPI.DLL
- CreateVssBackupComponentsInternal (Address: 0x100da2e8)
- VssFreeSnapshotPropertiesInternal (Address: 0x100da2ec)
XmlLite.dll
- CreateXmlReader (Address: 0x100da2f4)
- CreateXmlWriter (Address: 0x100da2fc)
- CreateXmlWriterOutputWithEncodingName (Address: 0x100da2f8)