srmscan.dll

Description: Microsoft® File Server Storage Reports Scan Engine

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 9761a9b55d85a602bee837cebddce517

File Size: 629.0 KB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 4

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • SrmIsNameInExpression (Ordinal: 1, Address: 0x5f90)
  • SrmCalculateCrcHash (Ordinal: 2, Address: 0x2370)
  • SrmEnsureSystemVolumeInformationFolder (Ordinal: 3, Address: 0x2380)
  • SrmIsInCluster (Ordinal: 4, Address: 0x2390)
  • SrmValidateNamespaceRoots (Ordinal: 5, Address: 0x24b0)
  • SrmCreateOrDeleteNotificationScheduledTask (Ordinal: 6, Address: 0x2600)
  • SrmUtcFileTimeToLocalFileTime (Ordinal: 7, Address: 0x28c0)
  • SrmLocalFileTimeToUtcFileTime (Ordinal: 8, Address: 0x2910)
  • DllCanUnloadNow (Ordinal: 9, Address: 0x2300)
  • DllGetClassObject (Ordinal: 10, Address: 0x2320)

Imported DLLs & Functions

ACTIVEDS.dll
  • (Address: 0x180062558)
  • (Address: 0x180062560)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x1800626e8)
  • CoCreateGuid (Address: 0x1800626f0)
  • CoCreateInstance (Address: 0x1800626c0)
  • CoGetInterfaceAndReleaseStream (Address: 0x1800626e0)
  • CoInitializeEx (Address: 0x1800626d0)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x180062700)
  • CoRevertToSelf (Address: 0x180062720)
  • CoTaskMemAlloc (Address: 0x1800626c8)
  • CoTaskMemFree (Address: 0x180062718)
  • CoTaskMemRealloc (Address: 0x1800626d8)
  • CoUninitialize (Address: 0x180062710)
  • PropVariantClear (Address: 0x180062708)
  • StringFromGUID2 (Address: 0x1800626f8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180062730)
  • OutputDebugStringW (Address: 0x180062738)
api-ms-win-core-debug-l1-1-1.dll
  • CheckRemoteDebuggerPresent (Address: 0x180062748)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180062760)
  • SetUnhandledExceptionFilter (Address: 0x180062768)
  • UnhandledExceptionFilter (Address: 0x180062758)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x1800627b0)
  • CreateDirectoryW (Address: 0x180062788)
  • CreateFileW (Address: 0x1800627e0)
  • DeleteFileW (Address: 0x180062790)
  • FileTimeToLocalFileTime (Address: 0x1800627a8)
  • FlushFileBuffers (Address: 0x180062798)
  • GetDriveTypeW (Address: 0x180062810)
  • GetFileAttributesW (Address: 0x180062808)
  • GetFileInformationByHandle (Address: 0x1800627d0)
  • GetFileSizeEx (Address: 0x1800627a0)
  • GetFileTime (Address: 0x1800627b8)
  • GetVolumeInformationW (Address: 0x1800627f8)
  • GetVolumePathNameW (Address: 0x1800627c0)
  • LocalFileTimeToFileTime (Address: 0x180062778)
  • ReadFile (Address: 0x180062800)
  • SetFileAttributesW (Address: 0x1800627f0)
  • SetFileInformationByHandle (Address: 0x1800627c8)
  • SetFilePointer (Address: 0x1800627e8)
  • SetFileTime (Address: 0x1800627d8)
  • WriteFile (Address: 0x180062780)
api-ms-win-core-file-l1-2-0.dll
  • GetVolumeNameForVolumeMountPointW (Address: 0x180062828)
  • GetVolumePathNamesForVolumeNameW (Address: 0x180062820)
api-ms-win-core-file-l2-1-0.dll
  • GetFileInformationByHandleEx (Address: 0x180062838)
  • ReOpenFile (Address: 0x180062840)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180062850)
  • DuplicateHandle (Address: 0x180062858)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180062870)
  • LocalFree (Address: 0x180062868)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x180062888)
  • GetOverlappedResult (Address: 0x180062880)
api-ms-win-core-kernel32-private-l1-1-1.dll
  • PrivCopyFileExW (Address: 0x180062898)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800628a8)
  • FreeLibrary (Address: 0x1800628c8)
  • GetProcAddress (Address: 0x1800628c0)
  • LoadLibraryExW (Address: 0x1800628b0)
  • LoadStringW (Address: 0x1800628b8)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x1800628d8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800628f0)
  • GetThreadLocale (Address: 0x1800628e8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x180062908)
  • GetCommandLineW (Address: 0x180062900)
api-ms-win-core-processthreads-l1-1-0.dll
  • ExitProcess (Address: 0x180062920)
  • GetCurrentProcess (Address: 0x180062950)
  • GetCurrentProcessId (Address: 0x180062940)
  • GetCurrentThread (Address: 0x180062918)
  • GetCurrentThreadId (Address: 0x180062930)
  • OpenProcessToken (Address: 0x180062938)
  • OpenThreadToken (Address: 0x180062960)
  • SetThreadPriority (Address: 0x180062928)
  • SetThreadToken (Address: 0x180062948)
  • TerminateProcess (Address: 0x180062958)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x180062970)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180062980)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800629a0)
  • RegOpenKeyExW (Address: 0x180062998)
  • RegQueryValueExW (Address: 0x180062990)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800629c0)
  • RtlCompareMemory (Address: 0x1800629c8)
  • RtlLookupFunctionEntry (Address: 0x1800629b8)
  • RtlVirtualUnwind (Address: 0x1800629b0)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFindExtensionW (Address: 0x1800629d8)
api-ms-win-core-synch-l1-1-0.dll
  • CreateEventW (Address: 0x180062a28)
  • CreateMutexW (Address: 0x180062a20)
  • DeleteCriticalSection (Address: 0x1800629f0)
  • EnterCriticalSection (Address: 0x1800629f8)
  • InitializeCriticalSection (Address: 0x180062a08)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180062a10)
  • LeaveCriticalSection (Address: 0x180062a00)
  • ReleaseMutex (Address: 0x180062a18)
  • SetEvent (Address: 0x1800629e8)
  • WaitForSingleObject (Address: 0x180062a30)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180062a40)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x180062a50)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x180062a70)
  • GetSystemTimeAsFileTime (Address: 0x180062a60)
  • GetTickCount (Address: 0x180062a68)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180062a88)
  • CloseThreadpoolWait (Address: 0x180062ab0)
  • CreateThreadpoolTimer (Address: 0x180062ab8)
  • CreateThreadpoolWait (Address: 0x180062a98)
  • SetThreadpoolTimer (Address: 0x180062a90)
  • SetThreadpoolWait (Address: 0x180062aa0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180062a80)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180062aa8)
api-ms-win-eventlog-legacy-l1-1-0.dll
  • DeregisterEventSource (Address: 0x180062ac8)
  • RegisterEventSourceW (Address: 0x180062ad0)
  • ReportEventW (Address: 0x180062ad8)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAceEx (Address: 0x180062b08)
  • AddAce (Address: 0x180062b20)
  • CopySid (Address: 0x180062b28)
  • CreateWellKnownSid (Address: 0x180062b30)
  • GetAce (Address: 0x180062b40)
  • GetAclInformation (Address: 0x180062b38)
  • GetLengthSid (Address: 0x180062b00)
  • GetTokenInformation (Address: 0x180062af0)
  • InitializeAcl (Address: 0x180062af8)
  • InitializeSecurityDescriptor (Address: 0x180062b18)
  • MapGenericMask (Address: 0x180062ae8)
  • SetSecurityDescriptorDacl (Address: 0x180062b10)
api-ms-win-security-base-l1-2-0.dll
  • AddResourceAttributeAce (Address: 0x180062b50)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountSidW (Address: 0x180062b60)
api-ms-win-security-provider-l1-1-0.dll
  • GetSecurityInfo (Address: 0x180062b78)
  • SetSecurityInfo (Address: 0x180062b70)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180062b88)
ATL.DLL
  • (Address: 0x180062570)
  • (Address: 0x180062578)
  • (Address: 0x180062580)
  • (Address: 0x180062588)
  • (Address: 0x180062590)
  • (Address: 0x180062598)
CLUSAPI.dll
  • GetNodeClusterState (Address: 0x1800625a8)
logoncli.dll
  • DsGetDcNameW (Address: 0x180062b98)
msdrm.dll
  • DRMAcquireIssuanceLicenseTemplate (Address: 0x180062c10)
  • DRMAcquireLicense (Address: 0x180062c40)
  • DRMActivate (Address: 0x180062c68)
  • DRMAddRightWithUser (Address: 0x180062bf0)
  • DRMCloseEnvironmentHandle (Address: 0x180062bd0)
  • DRMCloseHandle (Address: 0x180062ba8)
  • DRMClosePubHandle (Address: 0x180062bb0)
  • DRMCloseSession (Address: 0x180062bc0)
  • DRMCreateClientSession (Address: 0x180062be0)
  • DRMCreateIssuanceLicense (Address: 0x180062c58)
  • DRMCreateRight (Address: 0x180062c18)
  • DRMCreateUser (Address: 0x180062bc8)
  • DRMEnumerateLicense (Address: 0x180062bf8)
  • DRMGetIssuanceLicenseTemplate (Address: 0x180062c28)
  • DRMGetNameAndDescription (Address: 0x180062bb8)
  • DRMGetSecurityProvider (Address: 0x180062c08)
  • DRMGetServiceLocation (Address: 0x180062c50)
  • DRMInitEnvironment (Address: 0x180062c48)
  • DRMIsActivated (Address: 0x180062c00)
  • DRMpCloseFile (Address: 0x180062be8)
  • DRMpFileInitialize (Address: 0x180062c30)
  • DRMpFileIsProtected (Address: 0x180062c70)
  • DRMpFileProtect (Address: 0x180062c20)
  • DRMRepair (Address: 0x180062bd8)
  • DRMSetGlobalOptions (Address: 0x180062c60)
  • DRMSetMetaData (Address: 0x180062c38)
msvcrt.dll
  • __C_specific_handler (Address: 0x180062dc0)
  • __CxxFrameHandler3 (Address: 0x180062ce8)
  • __dllonexit (Address: 0x180062d10)
  • _amsg_exit (Address: 0x180062d50)
  • _callnewh (Address: 0x180062d68)
  • _CxxThrowException (Address: 0x180062d30)
  • _errno (Address: 0x180062d00)
  • _i64tow_s (Address: 0x180062ce0)
  • _initterm (Address: 0x180062cd0)
  • _lock (Address: 0x180062d20)
  • _onexit (Address: 0x180062d08)
  • _purecall (Address: 0x180062db8)
  • _snwscanf_s (Address: 0x180062d18)
  • _unlock (Address: 0x180062dc8)
  • _vsnprintf (Address: 0x180062cc0)
  • _vsnwprintf (Address: 0x180062d88)
  • _wcsicmp (Address: 0x180062d80)
  • _wcsnicmp (Address: 0x180062c80)
  • _wcstoui64 (Address: 0x180062cc8)
  • _wtoi64 (Address: 0x180062cf8)
  • _XcptFilter (Address: 0x180062d28)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180062da0)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180062d38)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180062d98)
  • ??1exception@@UEAA@XZ (Address: 0x180062da8)
  • ??1type_info@@UEAA@XZ (Address: 0x180062d48)
  • ?terminate@@YAXXZ (Address: 0x180062d58)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180062db0)
  • free (Address: 0x180062d60)
  • iswalpha (Address: 0x180062c98)
  • iswdigit (Address: 0x180062ca8)
  • malloc (Address: 0x180062d40)
  • memcmp (Address: 0x180062cb8)
  • memcpy (Address: 0x180062cb0)
  • memmove (Address: 0x180062ca0)
  • memset (Address: 0x180062cf0)
  • towlower (Address: 0x180062d90)
  • wcschr (Address: 0x180062d78)
  • wcscmp (Address: 0x180062dd0)
  • wcsncmp (Address: 0x180062c88)
  • wcsrchr (Address: 0x180062d70)
  • wcstol (Address: 0x180062c90)
  • wcstoul (Address: 0x180062cd8)
netutils.dll
  • NetApiBufferFree (Address: 0x180062de0)
ntdll.dll
  • NtCreateFile (Address: 0x180062e10)
  • RtlCreateSystemVolumeInformationFolder (Address: 0x180062e00)
  • RtlDosPathNameToRelativeNtPathName_U (Address: 0x180062e08)
  • RtlFreeHeap (Address: 0x180062df0)
  • RtlInitializeSid (Address: 0x180062e28)
  • RtlInitUnicodeString (Address: 0x180062e20)
  • RtlNtStatusToDosError (Address: 0x180062e18)
  • RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x180062df8)
OLEAUT32.dll
  • GetErrorInfo (Address: 0x1800625d0)
  • LoadRegTypeLib (Address: 0x180062610)
  • SafeArrayCopy (Address: 0x1800625e8)
  • SafeArrayCreateVector (Address: 0x180062630)
  • SafeArrayDestroy (Address: 0x180062620)
  • SafeArrayGetElement (Address: 0x1800625f8)
  • SafeArrayGetLBound (Address: 0x1800625f0)
  • SafeArrayGetUBound (Address: 0x180062608)
  • SafeArrayGetVartype (Address: 0x1800625d8)
  • SafeArrayPutElement (Address: 0x180062628)
  • SysAllocString (Address: 0x1800625c8)
  • SysAllocStringLen (Address: 0x180062638)
  • SysFreeString (Address: 0x1800625e0)
  • SysStringLen (Address: 0x1800625b8)
  • VariantClear (Address: 0x1800625c0)
  • VariantCopy (Address: 0x180062618)
  • VariantInit (Address: 0x180062600)
PROPSYS.dll
  • PropVariantToStringAlloc (Address: 0x180062648)
SrmTrace.DLL
  • (Address: 0x180062658)
  • (Address: 0x180062660)
  • (Address: 0x180062668)
  • (Address: 0x180062670)
  • (Address: 0x180062678)
  • (Address: 0x180062680)
  • (Address: 0x180062688)
  • (Address: 0x180062690)
  • (Address: 0x180062698)
XmlLite.dll
  • CreateXmlReader (Address: 0x1800626a8)
  • CreateXmlWriter (Address: 0x1800626b0)