srmclient.dll
Description: Microsoft® File Server Resource Management Client Extensions
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: 9c40b358ab9b45ab7b3fb613aa611bb0
File Size: 1.3 MB
Uploaded At: Dec. 1, 2025, 7:39 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x28e0)
- DllGetClassObject (Ordinal: 2, Address: 0x2900)
Imported DLLs & Functions
ACTIVEDS.dll
- (Address: 0x1800daa40)
ADVAPI32.dll
- ConvertSidToStringSidW (Address: 0x1800daa78)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800daa88)
- DeregisterEventSource (Address: 0x1800daab0)
- GetSecurityInfo (Address: 0x1800daa80)
- LookupAccountSidW (Address: 0x1800daa50)
- OpenProcessToken (Address: 0x1800daaa8)
- OpenThreadToken (Address: 0x1800daa90)
- RegCloseKey (Address: 0x1800daa68)
- RegCreateKeyExW (Address: 0x1800daab8)
- RegisterEventSourceW (Address: 0x1800daa58)
- RegOpenKeyExW (Address: 0x1800daa98)
- RegQueryValueExW (Address: 0x1800daac8)
- RegSetValueExW (Address: 0x1800daac0)
- ReportEventW (Address: 0x1800daa60)
- SetSecurityInfo (Address: 0x1800daa70)
- SetThreadToken (Address: 0x1800daaa0)
api-ms-win-security-base-l1-1-0.dll
- AllocateAndInitializeSid (Address: 0x1800db078)
- CheckTokenMembership (Address: 0x1800db098)
- CopySid (Address: 0x1800db088)
- CreateWellKnownSid (Address: 0x1800db080)
- FreeSid (Address: 0x1800db090)
- GetAce (Address: 0x1800db070)
- GetAclInformation (Address: 0x1800db068)
- GetLengthSid (Address: 0x1800db060)
- GetTokenInformation (Address: 0x1800db050)
- InitializeAcl (Address: 0x1800db048)
- MapGenericMask (Address: 0x1800db058)
api-ms-win-security-base-l1-2-0.dll
- AddResourceAttributeAce (Address: 0x1800db0a8)
ATL.DLL
- (Address: 0x1800daad8)
- (Address: 0x1800daae0)
- (Address: 0x1800daae8)
- (Address: 0x1800daaf0)
- (Address: 0x1800daaf8)
- (Address: 0x1800dab00)
AUTHZ.dll
- AuthzReportSecurityEventFromParams (Address: 0x1800dab10)
CLUSAPI.dll
- CloseCluster (Address: 0x1800dab38)
- ClusterRegCloseKey (Address: 0x1800dab60)
- ClusterRegCreateKey (Address: 0x1800dab28)
- ClusterRegDeleteKey (Address: 0x1800dab30)
- ClusterRegEnumKey (Address: 0x1800dab40)
- ClusterRegOpenKey (Address: 0x1800dab70)
- ClusterRegQueryValue (Address: 0x1800dab58)
- ClusterRegSetValue (Address: 0x1800dab68)
- GetClusterKey (Address: 0x1800dab50)
- GetNodeClusterState (Address: 0x1800dab48)
- OpenCluster (Address: 0x1800dab20)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800dabe0)
- CheckRemoteDebuggerPresent (Address: 0x1800dadc0)
- CloseHandle (Address: 0x1800dac08)
- CloseThreadpoolTimer (Address: 0x1800dae08)
- CloseThreadpoolWait (Address: 0x1800dad18)
- CompareFileTime (Address: 0x1800dae18)
- CreateDirectoryW (Address: 0x1800dae40)
- CreateEventW (Address: 0x1800dad08)
- CreateFileW (Address: 0x1800dac10)
- CreateThread (Address: 0x1800dae30)
- CreateThreadpoolTimer (Address: 0x1800dadf8)
- CreateThreadpoolWait (Address: 0x1800dace8)
- DebugBreak (Address: 0x1800dadc8)
- DeleteCriticalSection (Address: 0x1800dac38)
- DeleteFileW (Address: 0x1800dace0)
- DeviceIoControl (Address: 0x1800dad50)
- DisableThreadLibraryCalls (Address: 0x1800dae58)
- DuplicateHandle (Address: 0x1800dad28)
- EnterCriticalSection (Address: 0x1800dae80)
- ExitProcess (Address: 0x1800dadd0)
- ExpandEnvironmentStringsW (Address: 0x1800dae78)
- FileTimeToLocalFileTime (Address: 0x1800dadd8)
- FileTimeToSystemTime (Address: 0x1800dade0)
- FindClose (Address: 0x1800dac88)
- FindFirstFileW (Address: 0x1800dac98)
- FindFirstVolumeMountPointW (Address: 0x1800dad78)
- FindNextFileW (Address: 0x1800dac90)
- FindNextVolumeMountPointW (Address: 0x1800dad68)
- FindVolumeMountPointClose (Address: 0x1800dad70)
- FlushFileBuffers (Address: 0x1800dacc0)
- FormatMessageW (Address: 0x1800dad98)
- FreeLibrary (Address: 0x1800dacb0)
- GetCommandLineW (Address: 0x1800daca8)
- GetComputerNameW (Address: 0x1800dabf8)
- GetCurrentProcess (Address: 0x1800dabc0)
- GetCurrentProcessId (Address: 0x1800dab90)
- GetCurrentThread (Address: 0x1800dacf0)
- GetCurrentThreadId (Address: 0x1800dab98)
- GetDateFormatW (Address: 0x1800dadb0)
- GetDriveTypeW (Address: 0x1800dacb8)
- GetFileAttributesW (Address: 0x1800dae38)
- GetFileInformationByHandle (Address: 0x1800dac58)
- GetFileInformationByHandleEx (Address: 0x1800dad60)
- GetFileSize (Address: 0x1800dac00)
- GetFileSizeEx (Address: 0x1800dad58)
- GetFileTime (Address: 0x1800dacc8)
- GetFileType (Address: 0x1800dac78)
- GetLastError (Address: 0x1800dabd0)
- GetOverlappedResult (Address: 0x1800dacd0)
- GetSystemInfo (Address: 0x1800dac40)
- GetSystemTime (Address: 0x1800dae20)
- GetSystemTimeAsFileTime (Address: 0x1800daba0)
- GetTickCount (Address: 0x1800daba8)
- GetTimeFormatW (Address: 0x1800dadb8)
- GetVolumeInformationW (Address: 0x1800dad90)
- GetVolumeNameForVolumeMountPointW (Address: 0x1800dac60)
- GetVolumePathNamesForVolumeNameW (Address: 0x1800dac50)
- GetVolumePathNameW (Address: 0x1800dad88)
- GlobalLock (Address: 0x1800dada8)
- GlobalUnlock (Address: 0x1800dada0)
- InitializeCriticalSection (Address: 0x1800dae60)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800dad80)
- LeaveCriticalSection (Address: 0x1800dae68)
- LoadLibraryExW (Address: 0x1800dade8)
- LocalAlloc (Address: 0x1800dad30)
- LocalFree (Address: 0x1800dae28)
- MoveFileExW (Address: 0x1800dac80)
- MoveFileW (Address: 0x1800dac70)
- OpenProcess (Address: 0x1800dad20)
- OutputDebugStringW (Address: 0x1800daca0)
- PrivCopyFileExW (Address: 0x1800dae50)
- QueryPerformanceCounter (Address: 0x1800dab88)
- ReadFile (Address: 0x1800dac28)
- ReleaseSRWLockExclusive (Address: 0x1800dabe8)
- ReOpenFile (Address: 0x1800dac48)
- SetEndOfFile (Address: 0x1800dac18)
- SetFileAttributesW (Address: 0x1800dad10)
- SetFileInformationByHandle (Address: 0x1800dacf8)
- SetFileTime (Address: 0x1800dac68)
- SetThreadpoolTimer (Address: 0x1800dae00)
- SetThreadpoolWait (Address: 0x1800dacd8)
- SetThreadPriority (Address: 0x1800dad40)
- SetUnhandledExceptionFilter (Address: 0x1800dabb8)
- Sleep (Address: 0x1800dabf0)
- SleepConditionVariableSRW (Address: 0x1800dab80)
- SystemTimeToFileTime (Address: 0x1800dadf0)
- TerminateProcess (Address: 0x1800dabc8)
- UnhandledExceptionFilter (Address: 0x1800dabb0)
- VirtualAlloc (Address: 0x1800dae70)
- VirtualProtect (Address: 0x1800dae48)
- VirtualQuery (Address: 0x1800dac30)
- WaitForMultipleObjects (Address: 0x1800dad48)
- WaitForSingleObject (Address: 0x1800dad38)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800dae10)
- WaitForThreadpoolWaitCallbacks (Address: 0x1800dad00)
- WakeAllConditionVariable (Address: 0x1800dabd8)
- WriteFile (Address: 0x1800dac20)
MPR.dll
- WNetGetUniversalNameW (Address: 0x1800dae90)
msvcrt.dll
- __C_specific_handler (Address: 0x1800db240)
- __CxxFrameHandler3 (Address: 0x1800db1e8)
- __dllonexit (Address: 0x1800db180)
- _amsg_exit (Address: 0x1800db1a8)
- _callnewh (Address: 0x1800db1f8)
- _CxxThrowException (Address: 0x1800db1b8)
- _errno (Address: 0x1800db248)
- _i64tow_s (Address: 0x1800db1d0)
- _initterm (Address: 0x1800db1a0)
- _itow_s (Address: 0x1800db0b8)
- _lock (Address: 0x1800db190)
- _onexit (Address: 0x1800db178)
- _purecall (Address: 0x1800db230)
- _snwscanf_s (Address: 0x1800db158)
- _ui64tow_s (Address: 0x1800db108)
- _unlock (Address: 0x1800db188)
- _vsnprintf (Address: 0x1800db160)
- _vsnwprintf (Address: 0x1800db0d0)
- _wcsicmp (Address: 0x1800db0c8)
- _wcsnicmp (Address: 0x1800db0e8)
- _wcstoui64 (Address: 0x1800db0f8)
- _wtoi (Address: 0x1800db0c0)
- _wtoi64 (Address: 0x1800db120)
- _wtol (Address: 0x1800db1d8)
- _XcptFilter (Address: 0x1800db1b0)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800db218)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800db1c0)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800db210)
- ??1exception@@UEAA@XZ (Address: 0x1800db220)
- ??1type_info@@UEAA@XZ (Address: 0x1800db170)
- ?terminate@@YAXXZ (Address: 0x1800db198)
- ?what@exception@@UEBAPEBDXZ (Address: 0x1800db228)
- free (Address: 0x1800db208)
- iswalpha (Address: 0x1800db118)
- iswdigit (Address: 0x1800db1c8)
- iswspace (Address: 0x1800db100)
- malloc (Address: 0x1800db200)
- memcmp (Address: 0x1800db128)
- memcpy (Address: 0x1800db130)
- memmove (Address: 0x1800db138)
- memset (Address: 0x1800db168)
- realloc (Address: 0x1800db238)
- swscanf (Address: 0x1800db0d8)
- towlower (Address: 0x1800db140)
- wcschr (Address: 0x1800db0e0)
- wcscmp (Address: 0x1800db250)
- wcscspn (Address: 0x1800db110)
- wcsncmp (Address: 0x1800db150)
- wcsrchr (Address: 0x1800db148)
- wcsstr (Address: 0x1800db1f0)
- wcstol (Address: 0x1800db0f0)
- wcstoul (Address: 0x1800db1e0)
NETAPI32.dll
- DsGetDcNameW (Address: 0x1800daeb0)
- NetApiBufferFree (Address: 0x1800daea8)
- NetGetJoinInformation (Address: 0x1800daea0)
ntdll.dll
- NtCreateFile (Address: 0x1800db2a0)
- NtOpenFile (Address: 0x1800db2d8)
- NtQueryInformationFile (Address: 0x1800db2e8)
- RtlAcquireResourceExclusive (Address: 0x1800db2b0)
- RtlAcquireResourceShared (Address: 0x1800db2c8)
- RtlCaptureContext (Address: 0x1800db260)
- RtlCompareMemory (Address: 0x1800db300)
- RtlCreateSystemVolumeInformationFolder (Address: 0x1800db2f8)
- RtlDeleteResource (Address: 0x1800db2d0)
- RtlDosPathNameToNtPathName_U (Address: 0x1800db308)
- RtlDosPathNameToRelativeNtPathName_U (Address: 0x1800db2a8)
- RtlFreeHeap (Address: 0x1800db2e0)
- RtlFreeUnicodeString (Address: 0x1800db310)
- RtlInitializeResource (Address: 0x1800db2b8)
- RtlInitializeSid (Address: 0x1800db288)
- RtlInitUnicodeString (Address: 0x1800db290)
- RtlLookupFunctionEntry (Address: 0x1800db268)
- RtlNtStatusToDosError (Address: 0x1800db298)
- RtlReleaseResource (Address: 0x1800db2c0)
- RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x1800db2f0)
- RtlVirtualUnwind (Address: 0x1800db270)
- WinSqmIsOptedIn (Address: 0x1800db280)
- WinSqmSetDWORD (Address: 0x1800db278)
ole32.dll
- CLSIDFromString (Address: 0x1800db340)
- CoCreateGuid (Address: 0x1800db348)
- CoCreateInstance (Address: 0x1800db378)
- CoCreateInstanceEx (Address: 0x1800db360)
- CoGetInterfaceAndReleaseStream (Address: 0x1800db320)
- CoImpersonateClient (Address: 0x1800db390)
- CoInitializeEx (Address: 0x1800db330)
- CoMarshalInterThreadInterfaceInStream (Address: 0x1800db380)
- CoRevertToSelf (Address: 0x1800db3a0)
- CoSetProxyBlanket (Address: 0x1800db398)
- CoTaskMemAlloc (Address: 0x1800db370)
- CoTaskMemFree (Address: 0x1800db368)
- CoTaskMemRealloc (Address: 0x1800db338)
- CoUninitialize (Address: 0x1800db328)
- CreateStreamOnHGlobal (Address: 0x1800db388)
- GetHGlobalFromStream (Address: 0x1800db358)
- StringFromGUID2 (Address: 0x1800db350)
OLEAUT32.dll
- CreateErrorInfo (Address: 0x1800daf48)
- GetErrorInfo (Address: 0x1800daf40)
- LoadRegTypeLib (Address: 0x1800daf58)
- SafeArrayCopy (Address: 0x1800daf30)
- SafeArrayCreate (Address: 0x1800daf18)
- SafeArrayCreateVector (Address: 0x1800daf10)
- SafeArrayDestroy (Address: 0x1800daf28)
- SafeArrayGetElement (Address: 0x1800daef8)
- SafeArrayGetLBound (Address: 0x1800daef0)
- SafeArrayGetUBound (Address: 0x1800daf68)
- SafeArrayGetVartype (Address: 0x1800daee8)
- SafeArrayPutElement (Address: 0x1800daf20)
- SetErrorInfo (Address: 0x1800daf50)
- SysAllocString (Address: 0x1800daed0)
- SysAllocStringLen (Address: 0x1800daf60)
- SysFreeString (Address: 0x1800daec0)
- SysStringLen (Address: 0x1800daf00)
- VariantChangeType (Address: 0x1800daf38)
- VariantClear (Address: 0x1800daec8)
- VariantCopy (Address: 0x1800daed8)
- VariantInit (Address: 0x1800daf08)
- VariantTimeToSystemTime (Address: 0x1800daee0)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x1800daf78)
SHLWAPI.dll
- (Address: 0x1800daf88)
- PathFindFileNameW (Address: 0x1800dafa0)
- PathIsUNCW (Address: 0x1800daf90)
- PathRemoveFileSpecW (Address: 0x1800daf98)
SrmTrace.DLL
- (Address: 0x1800daff0)
- (Address: 0x1800dafe0)
- (Address: 0x1800dafd8)
- (Address: 0x1800dafd0)
- (Address: 0x1800dafc8)
- (Address: 0x1800dafe8)
- (Address: 0x1800dafc0)
- (Address: 0x1800dafb8)
- (Address: 0x1800dafb0)
USER32.dll
- LoadStringW (Address: 0x1800db000)
VSSAPI.DLL
- CreateVssBackupComponentsInternal (Address: 0x1800db010)
- VssFreeSnapshotPropertiesInternal (Address: 0x1800db018)
XmlLite.dll
- CreateXmlReader (Address: 0x1800db028)
- CreateXmlWriter (Address: 0x1800db038)
- CreateXmlWriterOutputWithEncodingName (Address: 0x1800db030)