srmclient.dll

Description: Microsoft® File Server Resource Management Client Extensions

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 9c40b358ab9b45ab7b3fb613aa611bb0

File Size: 1.3 MB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 4

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x28e0)
  • DllGetClassObject (Ordinal: 2, Address: 0x2900)

Imported DLLs & Functions

ACTIVEDS.dll
  • (Address: 0x1800daa40)
ADVAPI32.dll
  • ConvertSidToStringSidW (Address: 0x1800daa78)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800daa88)
  • DeregisterEventSource (Address: 0x1800daab0)
  • GetSecurityInfo (Address: 0x1800daa80)
  • LookupAccountSidW (Address: 0x1800daa50)
  • OpenProcessToken (Address: 0x1800daaa8)
  • OpenThreadToken (Address: 0x1800daa90)
  • RegCloseKey (Address: 0x1800daa68)
  • RegCreateKeyExW (Address: 0x1800daab8)
  • RegisterEventSourceW (Address: 0x1800daa58)
  • RegOpenKeyExW (Address: 0x1800daa98)
  • RegQueryValueExW (Address: 0x1800daac8)
  • RegSetValueExW (Address: 0x1800daac0)
  • ReportEventW (Address: 0x1800daa60)
  • SetSecurityInfo (Address: 0x1800daa70)
  • SetThreadToken (Address: 0x1800daaa0)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x1800db078)
  • CheckTokenMembership (Address: 0x1800db098)
  • CopySid (Address: 0x1800db088)
  • CreateWellKnownSid (Address: 0x1800db080)
  • FreeSid (Address: 0x1800db090)
  • GetAce (Address: 0x1800db070)
  • GetAclInformation (Address: 0x1800db068)
  • GetLengthSid (Address: 0x1800db060)
  • GetTokenInformation (Address: 0x1800db050)
  • InitializeAcl (Address: 0x1800db048)
  • MapGenericMask (Address: 0x1800db058)
api-ms-win-security-base-l1-2-0.dll
  • AddResourceAttributeAce (Address: 0x1800db0a8)
ATL.DLL
  • (Address: 0x1800daad8)
  • (Address: 0x1800daae0)
  • (Address: 0x1800daae8)
  • (Address: 0x1800daaf0)
  • (Address: 0x1800daaf8)
  • (Address: 0x1800dab00)
AUTHZ.dll
  • AuthzReportSecurityEventFromParams (Address: 0x1800dab10)
CLUSAPI.dll
  • CloseCluster (Address: 0x1800dab38)
  • ClusterRegCloseKey (Address: 0x1800dab60)
  • ClusterRegCreateKey (Address: 0x1800dab28)
  • ClusterRegDeleteKey (Address: 0x1800dab30)
  • ClusterRegEnumKey (Address: 0x1800dab40)
  • ClusterRegOpenKey (Address: 0x1800dab70)
  • ClusterRegQueryValue (Address: 0x1800dab58)
  • ClusterRegSetValue (Address: 0x1800dab68)
  • GetClusterKey (Address: 0x1800dab50)
  • GetNodeClusterState (Address: 0x1800dab48)
  • OpenCluster (Address: 0x1800dab20)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800dabe0)
  • CheckRemoteDebuggerPresent (Address: 0x1800dadc0)
  • CloseHandle (Address: 0x1800dac08)
  • CloseThreadpoolTimer (Address: 0x1800dae08)
  • CloseThreadpoolWait (Address: 0x1800dad18)
  • CompareFileTime (Address: 0x1800dae18)
  • CreateDirectoryW (Address: 0x1800dae40)
  • CreateEventW (Address: 0x1800dad08)
  • CreateFileW (Address: 0x1800dac10)
  • CreateThread (Address: 0x1800dae30)
  • CreateThreadpoolTimer (Address: 0x1800dadf8)
  • CreateThreadpoolWait (Address: 0x1800dace8)
  • DebugBreak (Address: 0x1800dadc8)
  • DeleteCriticalSection (Address: 0x1800dac38)
  • DeleteFileW (Address: 0x1800dace0)
  • DeviceIoControl (Address: 0x1800dad50)
  • DisableThreadLibraryCalls (Address: 0x1800dae58)
  • DuplicateHandle (Address: 0x1800dad28)
  • EnterCriticalSection (Address: 0x1800dae80)
  • ExitProcess (Address: 0x1800dadd0)
  • ExpandEnvironmentStringsW (Address: 0x1800dae78)
  • FileTimeToLocalFileTime (Address: 0x1800dadd8)
  • FileTimeToSystemTime (Address: 0x1800dade0)
  • FindClose (Address: 0x1800dac88)
  • FindFirstFileW (Address: 0x1800dac98)
  • FindFirstVolumeMountPointW (Address: 0x1800dad78)
  • FindNextFileW (Address: 0x1800dac90)
  • FindNextVolumeMountPointW (Address: 0x1800dad68)
  • FindVolumeMountPointClose (Address: 0x1800dad70)
  • FlushFileBuffers (Address: 0x1800dacc0)
  • FormatMessageW (Address: 0x1800dad98)
  • FreeLibrary (Address: 0x1800dacb0)
  • GetCommandLineW (Address: 0x1800daca8)
  • GetComputerNameW (Address: 0x1800dabf8)
  • GetCurrentProcess (Address: 0x1800dabc0)
  • GetCurrentProcessId (Address: 0x1800dab90)
  • GetCurrentThread (Address: 0x1800dacf0)
  • GetCurrentThreadId (Address: 0x1800dab98)
  • GetDateFormatW (Address: 0x1800dadb0)
  • GetDriveTypeW (Address: 0x1800dacb8)
  • GetFileAttributesW (Address: 0x1800dae38)
  • GetFileInformationByHandle (Address: 0x1800dac58)
  • GetFileInformationByHandleEx (Address: 0x1800dad60)
  • GetFileSize (Address: 0x1800dac00)
  • GetFileSizeEx (Address: 0x1800dad58)
  • GetFileTime (Address: 0x1800dacc8)
  • GetFileType (Address: 0x1800dac78)
  • GetLastError (Address: 0x1800dabd0)
  • GetOverlappedResult (Address: 0x1800dacd0)
  • GetSystemInfo (Address: 0x1800dac40)
  • GetSystemTime (Address: 0x1800dae20)
  • GetSystemTimeAsFileTime (Address: 0x1800daba0)
  • GetTickCount (Address: 0x1800daba8)
  • GetTimeFormatW (Address: 0x1800dadb8)
  • GetVolumeInformationW (Address: 0x1800dad90)
  • GetVolumeNameForVolumeMountPointW (Address: 0x1800dac60)
  • GetVolumePathNamesForVolumeNameW (Address: 0x1800dac50)
  • GetVolumePathNameW (Address: 0x1800dad88)
  • GlobalLock (Address: 0x1800dada8)
  • GlobalUnlock (Address: 0x1800dada0)
  • InitializeCriticalSection (Address: 0x1800dae60)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800dad80)
  • LeaveCriticalSection (Address: 0x1800dae68)
  • LoadLibraryExW (Address: 0x1800dade8)
  • LocalAlloc (Address: 0x1800dad30)
  • LocalFree (Address: 0x1800dae28)
  • MoveFileExW (Address: 0x1800dac80)
  • MoveFileW (Address: 0x1800dac70)
  • OpenProcess (Address: 0x1800dad20)
  • OutputDebugStringW (Address: 0x1800daca0)
  • PrivCopyFileExW (Address: 0x1800dae50)
  • QueryPerformanceCounter (Address: 0x1800dab88)
  • ReadFile (Address: 0x1800dac28)
  • ReleaseSRWLockExclusive (Address: 0x1800dabe8)
  • ReOpenFile (Address: 0x1800dac48)
  • SetEndOfFile (Address: 0x1800dac18)
  • SetFileAttributesW (Address: 0x1800dad10)
  • SetFileInformationByHandle (Address: 0x1800dacf8)
  • SetFileTime (Address: 0x1800dac68)
  • SetThreadpoolTimer (Address: 0x1800dae00)
  • SetThreadpoolWait (Address: 0x1800dacd8)
  • SetThreadPriority (Address: 0x1800dad40)
  • SetUnhandledExceptionFilter (Address: 0x1800dabb8)
  • Sleep (Address: 0x1800dabf0)
  • SleepConditionVariableSRW (Address: 0x1800dab80)
  • SystemTimeToFileTime (Address: 0x1800dadf0)
  • TerminateProcess (Address: 0x1800dabc8)
  • UnhandledExceptionFilter (Address: 0x1800dabb0)
  • VirtualAlloc (Address: 0x1800dae70)
  • VirtualProtect (Address: 0x1800dae48)
  • VirtualQuery (Address: 0x1800dac30)
  • WaitForMultipleObjects (Address: 0x1800dad48)
  • WaitForSingleObject (Address: 0x1800dad38)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800dae10)
  • WaitForThreadpoolWaitCallbacks (Address: 0x1800dad00)
  • WakeAllConditionVariable (Address: 0x1800dabd8)
  • WriteFile (Address: 0x1800dac20)
MPR.dll
  • WNetGetUniversalNameW (Address: 0x1800dae90)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800db240)
  • __CxxFrameHandler3 (Address: 0x1800db1e8)
  • __dllonexit (Address: 0x1800db180)
  • _amsg_exit (Address: 0x1800db1a8)
  • _callnewh (Address: 0x1800db1f8)
  • _CxxThrowException (Address: 0x1800db1b8)
  • _errno (Address: 0x1800db248)
  • _i64tow_s (Address: 0x1800db1d0)
  • _initterm (Address: 0x1800db1a0)
  • _itow_s (Address: 0x1800db0b8)
  • _lock (Address: 0x1800db190)
  • _onexit (Address: 0x1800db178)
  • _purecall (Address: 0x1800db230)
  • _snwscanf_s (Address: 0x1800db158)
  • _ui64tow_s (Address: 0x1800db108)
  • _unlock (Address: 0x1800db188)
  • _vsnprintf (Address: 0x1800db160)
  • _vsnwprintf (Address: 0x1800db0d0)
  • _wcsicmp (Address: 0x1800db0c8)
  • _wcsnicmp (Address: 0x1800db0e8)
  • _wcstoui64 (Address: 0x1800db0f8)
  • _wtoi (Address: 0x1800db0c0)
  • _wtoi64 (Address: 0x1800db120)
  • _wtol (Address: 0x1800db1d8)
  • _XcptFilter (Address: 0x1800db1b0)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800db218)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800db1c0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800db210)
  • ??1exception@@UEAA@XZ (Address: 0x1800db220)
  • ??1type_info@@UEAA@XZ (Address: 0x1800db170)
  • ?terminate@@YAXXZ (Address: 0x1800db198)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x1800db228)
  • free (Address: 0x1800db208)
  • iswalpha (Address: 0x1800db118)
  • iswdigit (Address: 0x1800db1c8)
  • iswspace (Address: 0x1800db100)
  • malloc (Address: 0x1800db200)
  • memcmp (Address: 0x1800db128)
  • memcpy (Address: 0x1800db130)
  • memmove (Address: 0x1800db138)
  • memset (Address: 0x1800db168)
  • realloc (Address: 0x1800db238)
  • swscanf (Address: 0x1800db0d8)
  • towlower (Address: 0x1800db140)
  • wcschr (Address: 0x1800db0e0)
  • wcscmp (Address: 0x1800db250)
  • wcscspn (Address: 0x1800db110)
  • wcsncmp (Address: 0x1800db150)
  • wcsrchr (Address: 0x1800db148)
  • wcsstr (Address: 0x1800db1f0)
  • wcstol (Address: 0x1800db0f0)
  • wcstoul (Address: 0x1800db1e0)
NETAPI32.dll
  • DsGetDcNameW (Address: 0x1800daeb0)
  • NetApiBufferFree (Address: 0x1800daea8)
  • NetGetJoinInformation (Address: 0x1800daea0)
ntdll.dll
  • NtCreateFile (Address: 0x1800db2a0)
  • NtOpenFile (Address: 0x1800db2d8)
  • NtQueryInformationFile (Address: 0x1800db2e8)
  • RtlAcquireResourceExclusive (Address: 0x1800db2b0)
  • RtlAcquireResourceShared (Address: 0x1800db2c8)
  • RtlCaptureContext (Address: 0x1800db260)
  • RtlCompareMemory (Address: 0x1800db300)
  • RtlCreateSystemVolumeInformationFolder (Address: 0x1800db2f8)
  • RtlDeleteResource (Address: 0x1800db2d0)
  • RtlDosPathNameToNtPathName_U (Address: 0x1800db308)
  • RtlDosPathNameToRelativeNtPathName_U (Address: 0x1800db2a8)
  • RtlFreeHeap (Address: 0x1800db2e0)
  • RtlFreeUnicodeString (Address: 0x1800db310)
  • RtlInitializeResource (Address: 0x1800db2b8)
  • RtlInitializeSid (Address: 0x1800db288)
  • RtlInitUnicodeString (Address: 0x1800db290)
  • RtlLookupFunctionEntry (Address: 0x1800db268)
  • RtlNtStatusToDosError (Address: 0x1800db298)
  • RtlReleaseResource (Address: 0x1800db2c0)
  • RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x1800db2f0)
  • RtlVirtualUnwind (Address: 0x1800db270)
  • WinSqmIsOptedIn (Address: 0x1800db280)
  • WinSqmSetDWORD (Address: 0x1800db278)
ole32.dll
  • CLSIDFromString (Address: 0x1800db340)
  • CoCreateGuid (Address: 0x1800db348)
  • CoCreateInstance (Address: 0x1800db378)
  • CoCreateInstanceEx (Address: 0x1800db360)
  • CoGetInterfaceAndReleaseStream (Address: 0x1800db320)
  • CoImpersonateClient (Address: 0x1800db390)
  • CoInitializeEx (Address: 0x1800db330)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x1800db380)
  • CoRevertToSelf (Address: 0x1800db3a0)
  • CoSetProxyBlanket (Address: 0x1800db398)
  • CoTaskMemAlloc (Address: 0x1800db370)
  • CoTaskMemFree (Address: 0x1800db368)
  • CoTaskMemRealloc (Address: 0x1800db338)
  • CoUninitialize (Address: 0x1800db328)
  • CreateStreamOnHGlobal (Address: 0x1800db388)
  • GetHGlobalFromStream (Address: 0x1800db358)
  • StringFromGUID2 (Address: 0x1800db350)
OLEAUT32.dll
  • CreateErrorInfo (Address: 0x1800daf48)
  • GetErrorInfo (Address: 0x1800daf40)
  • LoadRegTypeLib (Address: 0x1800daf58)
  • SafeArrayCopy (Address: 0x1800daf30)
  • SafeArrayCreate (Address: 0x1800daf18)
  • SafeArrayCreateVector (Address: 0x1800daf10)
  • SafeArrayDestroy (Address: 0x1800daf28)
  • SafeArrayGetElement (Address: 0x1800daef8)
  • SafeArrayGetLBound (Address: 0x1800daef0)
  • SafeArrayGetUBound (Address: 0x1800daf68)
  • SafeArrayGetVartype (Address: 0x1800daee8)
  • SafeArrayPutElement (Address: 0x1800daf20)
  • SetErrorInfo (Address: 0x1800daf50)
  • SysAllocString (Address: 0x1800daed0)
  • SysAllocStringLen (Address: 0x1800daf60)
  • SysFreeString (Address: 0x1800daec0)
  • SysStringLen (Address: 0x1800daf00)
  • VariantChangeType (Address: 0x1800daf38)
  • VariantClear (Address: 0x1800daec8)
  • VariantCopy (Address: 0x1800daed8)
  • VariantInit (Address: 0x1800daf08)
  • VariantTimeToSystemTime (Address: 0x1800daee0)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x1800daf78)
SHLWAPI.dll
  • (Address: 0x1800daf88)
  • PathFindFileNameW (Address: 0x1800dafa0)
  • PathIsUNCW (Address: 0x1800daf90)
  • PathRemoveFileSpecW (Address: 0x1800daf98)
SrmTrace.DLL
  • (Address: 0x1800daff0)
  • (Address: 0x1800dafe0)
  • (Address: 0x1800dafd8)
  • (Address: 0x1800dafd0)
  • (Address: 0x1800dafc8)
  • (Address: 0x1800dafe8)
  • (Address: 0x1800dafc0)
  • (Address: 0x1800dafb8)
  • (Address: 0x1800dafb0)
USER32.dll
  • LoadStringW (Address: 0x1800db000)
VSSAPI.DLL
  • CreateVssBackupComponentsInternal (Address: 0x1800db010)
  • VssFreeSnapshotPropertiesInternal (Address: 0x1800db018)
XmlLite.dll
  • CreateXmlReader (Address: 0x1800db028)
  • CreateXmlWriter (Address: 0x1800db038)
  • CreateXmlWriterOutputWithEncodingName (Address: 0x1800db030)