srclient.dll

Description: Microsoft® Windows System Restore Client Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4529

Architecture: 32-bit

Operating System: Windows NT

SHA256: d88664cc604598bf35ceab8da562c8f9

File Size: 60.0 KB

Uploaded At: Dec. 1, 2025, 8:04 a.m.

Views: 6

Exported Functions

  • SysprepCleanup (Ordinal: 1, Address: 0x79e0)
  • SysprepGeneralize (Ordinal: 2, Address: 0x7a00)
  • DisableSR (Ordinal: 3, Address: 0x4320)
  • DisableSRInternal (Ordinal: 4, Address: 0x4390)
  • EnableSR (Ordinal: 5, Address: 0x4240)
  • EnableSREx (Ordinal: 6, Address: 0x41d0)
  • EnableSRInternal (Ordinal: 7, Address: 0x42b0)
  • SRNewSystemId (Ordinal: 8, Address: 0x4640)
  • SRRemoveRestorePoint (Ordinal: 9, Address: 0x45d0)
  • SRSetRestorePointA (Ordinal: 10, Address: 0x44e0)
  • SRSetRestorePointInternal (Ordinal: 11, Address: 0x4550)
  • SRSetRestorePointW (Ordinal: 12, Address: 0x4460)
  • SetSRStateAfterSetup (Ordinal: 13, Address: 0x4400)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x1000f050)
  • AllocateAndInitializeSid (Address: 0x1000f068)
  • CheckTokenMembership (Address: 0x1000f064)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1000f024)
  • CreateWellKnownSid (Address: 0x1000f028)
  • DeregisterEventSource (Address: 0x1000f04c)
  • FreeSid (Address: 0x1000f060)
  • GetSecurityDescriptorDacl (Address: 0x1000f030)
  • GetTraceEnableFlags (Address: 0x1000f000)
  • GetTraceEnableLevel (Address: 0x1000f004)
  • GetTraceLoggerHandle (Address: 0x1000f008)
  • LookupPrivilegeValueW (Address: 0x1000f054)
  • OpenProcessToken (Address: 0x1000f058)
  • OpenThreadToken (Address: 0x1000f05c)
  • RegCloseKey (Address: 0x1000f020)
  • RegCreateKeyExW (Address: 0x1000f01c)
  • RegDeleteTreeW (Address: 0x1000f03c)
  • RegDeleteValueW (Address: 0x1000f040)
  • RegisterEventSourceW (Address: 0x1000f044)
  • RegisterTraceGuidsW (Address: 0x1000f00c)
  • RegOpenKeyExW (Address: 0x1000f018)
  • RegQueryValueExW (Address: 0x1000f034)
  • RegSetValueExW (Address: 0x1000f038)
  • ReportEventW (Address: 0x1000f048)
  • SetNamedSecurityInfoW (Address: 0x1000f02c)
  • TraceMessage (Address: 0x1000f014)
  • UnregisterTraceGuids (Address: 0x1000f010)
KERNEL32.dll
  • CloseHandle (Address: 0x1000f0c0)
  • CreateFileW (Address: 0x1000f07c)
  • DeleteFileW (Address: 0x1000f098)
  • DeviceIoControl (Address: 0x1000f0a0)
  • DisableThreadLibraryCalls (Address: 0x1000f0f0)
  • ExpandEnvironmentStringsW (Address: 0x1000f094)
  • FindClose (Address: 0x1000f0c4)
  • FindFirstFileW (Address: 0x1000f0d0)
  • FindNextFileW (Address: 0x1000f0cc)
  • GetCommandLineW (Address: 0x1000f0e8)
  • GetCurrentProcess (Address: 0x1000f074)
  • GetCurrentProcessId (Address: 0x1000f0b4)
  • GetCurrentThread (Address: 0x1000f080)
  • GetCurrentThreadId (Address: 0x1000f0b0)
  • GetDiskFreeSpaceExW (Address: 0x1000f0f4)
  • GetDriveTypeW (Address: 0x1000f088)
  • GetLastError (Address: 0x1000f0c8)
  • GetModuleFileNameW (Address: 0x1000f0ec)
  • GetSystemDirectoryW (Address: 0x1000f09c)
  • GetSystemTimeAsFileTime (Address: 0x1000f0d4)
  • GetTickCount (Address: 0x1000f090)
  • GetVolumeInformationW (Address: 0x1000f08c)
  • GetVolumeNameForVolumeMountPointW (Address: 0x1000f0a8)
  • GetVolumePathNameW (Address: 0x1000f0a4)
  • IsWow64Process (Address: 0x1000f084)
  • LocalFree (Address: 0x1000f0d8)
  • MultiByteToWideChar (Address: 0x1000f0e0)
  • QueryDosDeviceW (Address: 0x1000f0ac)
  • QueryPerformanceCounter (Address: 0x1000f0b8)
  • SetLastError (Address: 0x1000f0dc)
  • SetUnhandledExceptionFilter (Address: 0x1000f070)
  • Sleep (Address: 0x1000f0bc)
  • TerminateProcess (Address: 0x1000f078)
  • UnhandledExceptionFilter (Address: 0x1000f0e4)
msvcrt.dll
  • _amsg_exit (Address: 0x1000f134)
  • _callnewh (Address: 0x1000f13c)
  • _except_handler4_common (Address: 0x1000f12c)
  • _initterm (Address: 0x1000f130)
  • _vscwprintf (Address: 0x1000f124)
  • _vsnwprintf (Address: 0x1000f148)
  • _wcsicmp (Address: 0x1000f150)
  • _wcsnicmp (Address: 0x1000f11c)
  • _XcptFilter (Address: 0x1000f138)
  • free (Address: 0x1000f14c)
  • malloc (Address: 0x1000f140)
  • memcpy (Address: 0x1000f128)
  • memset (Address: 0x1000f120)
  • strchr (Address: 0x1000f144)
  • wcschr (Address: 0x1000f154)
  • wcsrchr (Address: 0x1000f118)
ntdll.dll
  • EtwTraceMessage (Address: 0x1000f190)
  • NtClose (Address: 0x1000f170)
  • NtCreateFile (Address: 0x1000f160)
  • NtOpenKey (Address: 0x1000f1a4)
  • NtQueryInformationFile (Address: 0x1000f180)
  • NtQueryValueKey (Address: 0x1000f15c)
  • NtQueryVolumeInformationFile (Address: 0x1000f164)
  • NtSetInformationFile (Address: 0x1000f17c)
  • RtlDeleteCriticalSection (Address: 0x1000f19c)
  • RtlGetCurrentTransaction (Address: 0x1000f194)
  • RtlGetLastNtStatus (Address: 0x1000f188)
  • RtlGetNtSystemRoot (Address: 0x1000f16c)
  • RtlGetSuiteMask (Address: 0x1000f168)
  • RtlInitializeCriticalSection (Address: 0x1000f1a0)
  • RtlNtStatusToDosError (Address: 0x1000f18c)
  • RtlRunOnceExecuteOnce (Address: 0x1000f174)
  • RtlSetCurrentTransaction (Address: 0x1000f198)
  • RtlSetThreadErrorMode (Address: 0x1000f184)
  • WinSqmAddToStreamEx (Address: 0x1000f178)
ole32.dll
  • CoCreateInstance (Address: 0x1000f1b8)
  • CoInitializeEx (Address: 0x1000f1b0)
  • CoTaskMemAlloc (Address: 0x1000f1c0)
  • CoTaskMemFree (Address: 0x1000f1ac)
  • CoTaskMemRealloc (Address: 0x1000f1bc)
  • CoUninitialize (Address: 0x1000f1b4)
  • StringFromGUID2 (Address: 0x1000f1c4)
POWRPROF.dll
  • CallNtPowerInformation (Address: 0x1000f0fc)
SPP.dll
  • SppFreeGroupPropArray (Address: 0x1000f110)
  • SxTracerDebuggerBreak (Address: 0x1000f108)
  • SxTracerGetThreadContextRetail (Address: 0x1000f10c)
  • SxTracerShouldTrackFailure (Address: 0x1000f104)