srwmi.dll

Description: Microsoft® Windows System Restore WMI Provider

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1

Architecture: 64-bit

Operating System: Windows NT

SHA256: 1f9f1923d646aa28e27301125b901579

File Size: 27.0 KB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 5

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x26b0)
  • DllGetClassObject (Ordinal: 2, Address: 0x2600)
  • DllRegisterServer (Ordinal: 3, Address: 0x26f0)
  • DllUnregisterServer (Ordinal: 4, Address: 0x2770)

Imported DLLs & Functions

ADVAPI32.dll
  • AllocateAndInitializeSid (Address: 0x1800051b0)
  • CheckTokenMembership (Address: 0x1800051b8)
  • FreeSid (Address: 0x1800051c0)
  • GetTraceEnableFlags (Address: 0x1800051e8)
  • GetTraceEnableLevel (Address: 0x1800051f0)
  • GetTraceLoggerHandle (Address: 0x1800051f8)
  • RegCloseKey (Address: 0x1800051a8)
  • RegisterTraceGuidsW (Address: 0x1800051e0)
  • RegOpenKeyExW (Address: 0x1800051d0)
  • RegQueryValueExW (Address: 0x1800051c8)
  • TraceMessage (Address: 0x180005200)
  • UnregisterTraceGuids (Address: 0x1800051d8)
framedynos.dll
  • ??0Provider@@QEAA@PEBG0@Z (Address: 0x180005300)
  • ??0WBEMTime@@QEAA@AEBU_FILETIME@@@Z (Address: 0x180005328)
  • ??1Provider@@UEAA@XZ (Address: 0x180005308)
  • ?Commit@CInstance@@QEAAJXZ (Address: 0x180005338)
  • ?Create@CWbemGlueFactory@@SAPEAV1@PEAJ@Z (Address: 0x1800053a8)
  • ?CreateNewInstance@Provider@@IEAAPEAVCInstance@@PEAVMethodContext@@@Z (Address: 0x180005310)
  • ?Destroy@CWbemGlueFactory@@QEAAXXZ (Address: 0x1800053a0)
  • ?Flush@Provider@@MEAAXXZ (Address: 0x1800053c0)
  • ?FrameworkLoginDLL@CWbemProviderGlue@@SAHPEBGPEAJ@Z (Address: 0x180005390)
  • ?FrameworkLogoffDLL@CWbemProviderGlue@@SAHPEBGPEAJ@Z (Address: 0x180005398)
  • ?Getbool@CInstance@@QEBA_NPEBGAEA_N@Z (Address: 0x1800053b0)
  • ?GetBSTR@WBEMTime@@QEBAPEAGXZ (Address: 0x180005330)
  • ?GetDWORD@CInstance@@QEBA_NPEBGAEAK@Z (Address: 0x1800053b8)
  • ?GetObject@Provider@@MEAAJPEAVCInstance@@JAEAVCFrameworkQuery@@@Z (Address: 0x180005378)
  • ?GetWCHAR@CInstance@@QEBA_NPEBGPEAPEAG@Z (Address: 0x180005340)
  • ?OnFinalRelease@CThreadBase@@MEAAXXZ (Address: 0x180005380)
  • ?Release@CInstance@@QEAAJXZ (Address: 0x180005388)
  • ?SetCHString@CInstance@@QEAA_NPEBG0@Z (Address: 0x180005318)
  • ?SetDWORD@CInstance@@QEAA_NPEBGK@Z (Address: 0x180005320)
  • ?ValidateDeletionFlags@Provider@@MEAAJJ@Z (Address: 0x180005350)
  • ?ValidateEnumerationFlags@Provider@@MEAAJJ@Z (Address: 0x180005370)
  • ?ValidateGetObjFlags@Provider@@MEAAJJ@Z (Address: 0x180005368)
  • ?ValidateMethodFlags@Provider@@MEAAJJ@Z (Address: 0x180005360)
  • ?ValidatePutInstanceFlags@Provider@@MEAAJJ@Z (Address: 0x180005348)
  • ?ValidateQueryFlags@Provider@@MEAAJJ@Z (Address: 0x180005358)
KERNEL32.dll
  • CompareStringW (Address: 0x180005288)
  • DisableThreadLibraryCalls (Address: 0x180005270)
  • GetCurrentProcess (Address: 0x180005228)
  • GetCurrentProcessId (Address: 0x180005258)
  • GetCurrentThreadId (Address: 0x180005298)
  • GetLastError (Address: 0x180005238)
  • GetSystemTimeAsFileTime (Address: 0x180005250)
  • GetTickCount (Address: 0x180005248)
  • LocalFree (Address: 0x1800052a0)
  • lstrcmpiW (Address: 0x180005278)
  • lstrlenW (Address: 0x180005280)
  • QueryPerformanceCounter (Address: 0x180005260)
  • RtlCaptureContext (Address: 0x180005240)
  • RtlLookupFunctionEntry (Address: 0x180005290)
  • RtlVirtualUnwind (Address: 0x180005210)
  • SetUnhandledExceptionFilter (Address: 0x180005220)
  • Sleep (Address: 0x180005268)
  • TerminateProcess (Address: 0x180005230)
  • UnhandledExceptionFilter (Address: 0x180005218)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800053f8)
  • __CxxFrameHandler3 (Address: 0x1800053d0)
  • __dllonexit (Address: 0x1800053e0)
  • _amsg_exit (Address: 0x180005408)
  • _initterm (Address: 0x180005400)
  • _lock (Address: 0x1800053f0)
  • _onexit (Address: 0x1800053d8)
  • _unlock (Address: 0x1800053e8)
  • _XcptFilter (Address: 0x180005410)
  • free (Address: 0x180005420)
  • malloc (Address: 0x180005418)
  • memset (Address: 0x180005428)
ntdll.dll
  • EtwTraceMessage (Address: 0x180005438)
  • RtlGetLastNtStatus (Address: 0x180005448)
  • RtlNtStatusToDosError (Address: 0x180005440)
ole32.dll
  • CoCreateInstance (Address: 0x180005458)
  • CoImpersonateClient (Address: 0x180005460)
  • CoTaskMemFree (Address: 0x180005468)
OLEAUT32.dll
  • SysFreeString (Address: 0x1800052b0)
SPP.dll
  • SxTracerDebuggerBreak (Address: 0x1800052c8)
  • SxTracerGetThreadContextRetail (Address: 0x1800052c0)
  • SxTracerShouldTrackFailure (Address: 0x1800052d0)
SRCLIENT.dll
  • DisableSRInternal (Address: 0x1800052e8)
  • EnableSRInternal (Address: 0x1800052f0)
  • SRSetRestorePointInternal (Address: 0x1800052e0)