srclient.dll
Description: Microsoft® Windows System Restore Client Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4529
Architecture: 32-bit
Operating System: Windows NT
SHA256: d88664cc604598bf35ceab8da562c8f9
File Size: 60.0 KB
Uploaded At: Dec. 1, 2025, 8:04 a.m.
Views: 6
Exported Functions
- SysprepCleanup (Ordinal: 1, Address: 0x79e0)
- SysprepGeneralize (Ordinal: 2, Address: 0x7a00)
- DisableSR (Ordinal: 3, Address: 0x4320)
- DisableSRInternal (Ordinal: 4, Address: 0x4390)
- EnableSR (Ordinal: 5, Address: 0x4240)
- EnableSREx (Ordinal: 6, Address: 0x41d0)
- EnableSRInternal (Ordinal: 7, Address: 0x42b0)
- SRNewSystemId (Ordinal: 8, Address: 0x4640)
- SRRemoveRestorePoint (Ordinal: 9, Address: 0x45d0)
- SRSetRestorePointA (Ordinal: 10, Address: 0x44e0)
- SRSetRestorePointInternal (Ordinal: 11, Address: 0x4550)
- SRSetRestorePointW (Ordinal: 12, Address: 0x4460)
- SetSRStateAfterSetup (Ordinal: 13, Address: 0x4400)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x1000f050)
- AllocateAndInitializeSid (Address: 0x1000f068)
- CheckTokenMembership (Address: 0x1000f064)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1000f024)
- CreateWellKnownSid (Address: 0x1000f028)
- DeregisterEventSource (Address: 0x1000f04c)
- FreeSid (Address: 0x1000f060)
- GetSecurityDescriptorDacl (Address: 0x1000f030)
- GetTraceEnableFlags (Address: 0x1000f000)
- GetTraceEnableLevel (Address: 0x1000f004)
- GetTraceLoggerHandle (Address: 0x1000f008)
- LookupPrivilegeValueW (Address: 0x1000f054)
- OpenProcessToken (Address: 0x1000f058)
- OpenThreadToken (Address: 0x1000f05c)
- RegCloseKey (Address: 0x1000f020)
- RegCreateKeyExW (Address: 0x1000f01c)
- RegDeleteTreeW (Address: 0x1000f03c)
- RegDeleteValueW (Address: 0x1000f040)
- RegisterEventSourceW (Address: 0x1000f044)
- RegisterTraceGuidsW (Address: 0x1000f00c)
- RegOpenKeyExW (Address: 0x1000f018)
- RegQueryValueExW (Address: 0x1000f034)
- RegSetValueExW (Address: 0x1000f038)
- ReportEventW (Address: 0x1000f048)
- SetNamedSecurityInfoW (Address: 0x1000f02c)
- TraceMessage (Address: 0x1000f014)
- UnregisterTraceGuids (Address: 0x1000f010)
KERNEL32.dll
- CloseHandle (Address: 0x1000f0c0)
- CreateFileW (Address: 0x1000f07c)
- DeleteFileW (Address: 0x1000f098)
- DeviceIoControl (Address: 0x1000f0a0)
- DisableThreadLibraryCalls (Address: 0x1000f0f0)
- ExpandEnvironmentStringsW (Address: 0x1000f094)
- FindClose (Address: 0x1000f0c4)
- FindFirstFileW (Address: 0x1000f0d0)
- FindNextFileW (Address: 0x1000f0cc)
- GetCommandLineW (Address: 0x1000f0e8)
- GetCurrentProcess (Address: 0x1000f074)
- GetCurrentProcessId (Address: 0x1000f0b4)
- GetCurrentThread (Address: 0x1000f080)
- GetCurrentThreadId (Address: 0x1000f0b0)
- GetDiskFreeSpaceExW (Address: 0x1000f0f4)
- GetDriveTypeW (Address: 0x1000f088)
- GetLastError (Address: 0x1000f0c8)
- GetModuleFileNameW (Address: 0x1000f0ec)
- GetSystemDirectoryW (Address: 0x1000f09c)
- GetSystemTimeAsFileTime (Address: 0x1000f0d4)
- GetTickCount (Address: 0x1000f090)
- GetVolumeInformationW (Address: 0x1000f08c)
- GetVolumeNameForVolumeMountPointW (Address: 0x1000f0a8)
- GetVolumePathNameW (Address: 0x1000f0a4)
- IsWow64Process (Address: 0x1000f084)
- LocalFree (Address: 0x1000f0d8)
- MultiByteToWideChar (Address: 0x1000f0e0)
- QueryDosDeviceW (Address: 0x1000f0ac)
- QueryPerformanceCounter (Address: 0x1000f0b8)
- SetLastError (Address: 0x1000f0dc)
- SetUnhandledExceptionFilter (Address: 0x1000f070)
- Sleep (Address: 0x1000f0bc)
- TerminateProcess (Address: 0x1000f078)
- UnhandledExceptionFilter (Address: 0x1000f0e4)
msvcrt.dll
- _amsg_exit (Address: 0x1000f134)
- _callnewh (Address: 0x1000f13c)
- _except_handler4_common (Address: 0x1000f12c)
- _initterm (Address: 0x1000f130)
- _vscwprintf (Address: 0x1000f124)
- _vsnwprintf (Address: 0x1000f148)
- _wcsicmp (Address: 0x1000f150)
- _wcsnicmp (Address: 0x1000f11c)
- _XcptFilter (Address: 0x1000f138)
- free (Address: 0x1000f14c)
- malloc (Address: 0x1000f140)
- memcpy (Address: 0x1000f128)
- memset (Address: 0x1000f120)
- strchr (Address: 0x1000f144)
- wcschr (Address: 0x1000f154)
- wcsrchr (Address: 0x1000f118)
ntdll.dll
- EtwTraceMessage (Address: 0x1000f190)
- NtClose (Address: 0x1000f170)
- NtCreateFile (Address: 0x1000f160)
- NtOpenKey (Address: 0x1000f1a4)
- NtQueryInformationFile (Address: 0x1000f180)
- NtQueryValueKey (Address: 0x1000f15c)
- NtQueryVolumeInformationFile (Address: 0x1000f164)
- NtSetInformationFile (Address: 0x1000f17c)
- RtlDeleteCriticalSection (Address: 0x1000f19c)
- RtlGetCurrentTransaction (Address: 0x1000f194)
- RtlGetLastNtStatus (Address: 0x1000f188)
- RtlGetNtSystemRoot (Address: 0x1000f16c)
- RtlGetSuiteMask (Address: 0x1000f168)
- RtlInitializeCriticalSection (Address: 0x1000f1a0)
- RtlNtStatusToDosError (Address: 0x1000f18c)
- RtlRunOnceExecuteOnce (Address: 0x1000f174)
- RtlSetCurrentTransaction (Address: 0x1000f198)
- RtlSetThreadErrorMode (Address: 0x1000f184)
- WinSqmAddToStreamEx (Address: 0x1000f178)
ole32.dll
- CoCreateInstance (Address: 0x1000f1b8)
- CoInitializeEx (Address: 0x1000f1b0)
- CoTaskMemAlloc (Address: 0x1000f1c0)
- CoTaskMemFree (Address: 0x1000f1ac)
- CoTaskMemRealloc (Address: 0x1000f1bc)
- CoUninitialize (Address: 0x1000f1b4)
- StringFromGUID2 (Address: 0x1000f1c4)
POWRPROF.dll
- CallNtPowerInformation (Address: 0x1000f0fc)
SPP.dll
- SppFreeGroupPropArray (Address: 0x1000f110)
- SxTracerDebuggerBreak (Address: 0x1000f108)
- SxTracerGetThreadContextRetail (Address: 0x1000f10c)
- SxTracerShouldTrackFailure (Address: 0x1000f104)