srclient.dll

Description: Microsoft® Windows System Restore Client Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4957

Architecture: 64-bit

Operating System: Windows NT

SHA256: e45a7c5c250245d62f079e082d305eaa

File Size: 73.0 KB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 4

Exported Functions

  • SysprepCleanup (Ordinal: 1, Address: 0x6dc0)
  • SysprepGeneralize (Ordinal: 2, Address: 0x6de0)
  • DisableSR (Ordinal: 3, Address: 0x30c0)
  • DisableSRInternal (Ordinal: 4, Address: 0x3140)
  • EnableSR (Ordinal: 5, Address: 0x2fb0)
  • EnableSREx (Ordinal: 6, Address: 0x2fb0)
  • EnableSRInternal (Ordinal: 7, Address: 0x3030)
  • SRNewSystemId (Ordinal: 8, Address: 0x3490)
  • SRRemoveRestorePoint (Ordinal: 9, Address: 0x3410)
  • SRSetRestorePointA (Ordinal: 10, Address: 0x32e0)
  • SRSetRestorePointInternal (Ordinal: 11, Address: 0x3370)
  • SRSetRestorePointW (Ordinal: 12, Address: 0x3240)
  • SetSRStateAfterSetup (Ordinal: 13, Address: 0x31d0)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x18000f1e0)
  • AllocateAndInitializeSid (Address: 0x18000f210)
  • CheckTokenMembership (Address: 0x18000f208)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000f190)
  • CreateWellKnownSid (Address: 0x18000f198)
  • DeregisterEventSource (Address: 0x18000f1d8)
  • FreeSid (Address: 0x18000f200)
  • GetSecurityDescriptorDacl (Address: 0x18000f1a8)
  • GetTraceEnableFlags (Address: 0x18000f148)
  • GetTraceEnableLevel (Address: 0x18000f150)
  • GetTraceLoggerHandle (Address: 0x18000f158)
  • LookupPrivilegeValueW (Address: 0x18000f1e8)
  • OpenProcessToken (Address: 0x18000f1f0)
  • OpenThreadToken (Address: 0x18000f1f8)
  • RegCloseKey (Address: 0x18000f188)
  • RegCreateKeyExW (Address: 0x18000f180)
  • RegDeleteTreeW (Address: 0x18000f1c0)
  • RegDeleteValueW (Address: 0x18000f1c8)
  • RegisterEventSourceW (Address: 0x18000f218)
  • RegisterTraceGuidsW (Address: 0x18000f160)
  • RegOpenKeyExW (Address: 0x18000f178)
  • RegQueryValueExW (Address: 0x18000f1b0)
  • RegSetValueExW (Address: 0x18000f1b8)
  • ReportEventW (Address: 0x18000f1d0)
  • SetNamedSecurityInfoW (Address: 0x18000f1a0)
  • TraceMessage (Address: 0x18000f170)
  • UnregisterTraceGuids (Address: 0x18000f168)
KERNEL32.dll
  • CloseHandle (Address: 0x18000f2e0)
  • CreateFileW (Address: 0x18000f258)
  • DeleteFileW (Address: 0x18000f290)
  • DeviceIoControl (Address: 0x18000f2a0)
  • DisableThreadLibraryCalls (Address: 0x18000f340)
  • ExpandEnvironmentStringsW (Address: 0x18000f288)
  • FindClose (Address: 0x18000f2e8)
  • FindFirstFileW (Address: 0x18000f300)
  • FindNextFileW (Address: 0x18000f2f8)
  • GetCommandLineW (Address: 0x18000f330)
  • GetCurrentProcess (Address: 0x18000f248)
  • GetCurrentProcessId (Address: 0x18000f2c8)
  • GetCurrentThread (Address: 0x18000f260)
  • GetCurrentThreadId (Address: 0x18000f2c0)
  • GetDiskFreeSpaceExW (Address: 0x18000f280)
  • GetDriveTypeW (Address: 0x18000f348)
  • GetLastError (Address: 0x18000f2f0)
  • GetModuleFileNameW (Address: 0x18000f338)
  • GetSystemDirectoryW (Address: 0x18000f298)
  • GetSystemTimeAsFileTime (Address: 0x18000f308)
  • GetTickCount (Address: 0x18000f270)
  • GetVolumeInformationW (Address: 0x18000f278)
  • GetVolumeNameForVolumeMountPointW (Address: 0x18000f2b0)
  • GetVolumePathNameW (Address: 0x18000f2a8)
  • IsWow64Process (Address: 0x18000f268)
  • LocalFree (Address: 0x18000f310)
  • MultiByteToWideChar (Address: 0x18000f320)
  • QueryDosDeviceW (Address: 0x18000f2b8)
  • QueryPerformanceCounter (Address: 0x18000f2d0)
  • RtlCaptureContext (Address: 0x18000f328)
  • RtlLookupFunctionEntry (Address: 0x18000f228)
  • RtlVirtualUnwind (Address: 0x18000f230)
  • SetLastError (Address: 0x18000f318)
  • SetUnhandledExceptionFilter (Address: 0x18000f240)
  • Sleep (Address: 0x18000f2d8)
  • TerminateProcess (Address: 0x18000f250)
  • UnhandledExceptionFilter (Address: 0x18000f238)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000f3b8)
  • _amsg_exit (Address: 0x18000f3c8)
  • _callnewh (Address: 0x18000f3d8)
  • _initterm (Address: 0x18000f3c0)
  • _vscwprintf (Address: 0x18000f3a8)
  • _vsnwprintf (Address: 0x18000f3f0)
  • _wcsicmp (Address: 0x18000f400)
  • _wcsnicmp (Address: 0x18000f398)
  • _XcptFilter (Address: 0x18000f3d0)
  • free (Address: 0x18000f3f8)
  • malloc (Address: 0x18000f3e0)
  • memcpy (Address: 0x18000f3b0)
  • memset (Address: 0x18000f3a0)
  • strchr (Address: 0x18000f3e8)
  • wcschr (Address: 0x18000f408)
  • wcsrchr (Address: 0x18000f390)
ntdll.dll
  • EtwTraceMessage (Address: 0x18000f480)
  • NtClose (Address: 0x18000f440)
  • NtCreateFile (Address: 0x18000f420)
  • NtOpenKey (Address: 0x18000f4a8)
  • NtQueryInformationFile (Address: 0x18000f460)
  • NtQueryValueKey (Address: 0x18000f418)
  • NtQueryVolumeInformationFile (Address: 0x18000f428)
  • NtSetInformationFile (Address: 0x18000f458)
  • RtlDeleteCriticalSection (Address: 0x18000f498)
  • RtlGetCurrentTransaction (Address: 0x18000f488)
  • RtlGetLastNtStatus (Address: 0x18000f468)
  • RtlGetNtSystemRoot (Address: 0x18000f438)
  • RtlGetSuiteMask (Address: 0x18000f430)
  • RtlInitializeCriticalSection (Address: 0x18000f4a0)
  • RtlNtStatusToDosError (Address: 0x18000f478)
  • RtlRunOnceExecuteOnce (Address: 0x18000f448)
  • RtlSetCurrentTransaction (Address: 0x18000f490)
  • RtlSetThreadErrorMode (Address: 0x18000f470)
  • WinSqmAddToStreamEx (Address: 0x18000f450)
ole32.dll
  • CoCreateInstance (Address: 0x18000f4d0)
  • CoInitializeEx (Address: 0x18000f4c0)
  • CoTaskMemAlloc (Address: 0x18000f4e0)
  • CoTaskMemFree (Address: 0x18000f4b8)
  • CoTaskMemRealloc (Address: 0x18000f4d8)
  • CoUninitialize (Address: 0x18000f4c8)
  • StringFromGUID2 (Address: 0x18000f4e8)
POWRPROF.dll
  • CallNtPowerInformation (Address: 0x18000f358)
SPP.dll
  • SppFreeGroupPropArray (Address: 0x18000f380)
  • SxTracerDebuggerBreak (Address: 0x18000f370)
  • SxTracerGetThreadContextRetail (Address: 0x18000f378)
  • SxTracerShouldTrackFailure (Address: 0x18000f368)