Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.1.7600.16385 (win7_rtm.090713-1255) 53.19%
6.1.7600.16385 (win7_rtm.090713-1255) 7.55%
6.1.7600.16385 (win7_rtm.090713-1255) 0.19%
6.1.7600.16385 (win7_rtm.090713-1255) 24.17%
6.1.7600.16385 (win7_rtm.090713-1255) 4.86%
6.0.6000.16386 (vista_rtm.061101-2205) 0.56%
6.0.6000.16386 (vista_rtm.061101-2205) 7.81%
6.0.6000.16386 (vista_rtm.061101-2205) 1.68%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
StartTraceW, EnableTrace, ControlTraceW, InitializeSecurityDescriptor, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, RegCreateKeyExW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegSetValueExW, RegQueryValueExW, CreateWellKnownSid, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, RegOpenKeyExW, CloseTrace, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegCloseKey, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage
comctl32.dll
CreatePropertySheetPageW, ImageList_Create, ImageList_ReplaceIcon, ImageList_Destroy
gdi32.dll
SetBkColor, CreateFontIndirectW, DeleteObject, ExtTextOutW, SetTextColor
kernel32.dll
GetProcAddress, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, LoadLibraryW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, QueryPerformanceCounter, InterlockedCompareExchange, Sleep, InterlockedExchange, GetExitCodeThread, FreeLibraryAndExitThread, CreateThread, CreateProcessW, SetLastError, CreateFileW, CloseHandle, InterlockedDecrement, InterlockedIncrement, HeapSetInformation, GetModuleHandleExW, FreeLibrary, GetFileAttributesW, DeleteFileW, GetLastError, LocalFree, GetSystemTimeAsFileTime, DisableThreadLibraryCalls, GetNumberFormatW, FormatMessageW, LoadLibraryExW, GetModuleHandleW, GetVolumeInformationW, GetDriveTypeW, GetVolumePathNameW, FindFirstFileW, FindNextFileW, DeviceIoControl, MoveFileExW, FindClose, GetVolumeNameForVolumeMountPointW, GetVolumePathNamesForVolumeNameW, ExpandEnvironmentStringsW, CreateDirectoryW
msvcrt.dll
DllMain
ntdll.dll
WinSqmAddToStream, RtlGetLastNtStatus, RtlNtStatusToDosError, NtSetInformationFile, NtQueryInformationFile, EtwTraceMessage, NtSetInformationProcess, NtQueryVolumeInformationFile, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlDeleteElementGenericTableAvl, RtlEnumerateGenericTableAvl, RtlInitializeGenericTableAvl, WinSqmSetDWORD
ole32.dll
CoInitializeEx, CoUninitialize, CoCreateInstance, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, CoWaitForMultipleHandles, CoGetMalloc, CoInitializeSecurity
shell32.dll
SHParseDisplayName, SHGetDesktopFolder, SHGetStockIconInfo, SHGetFileInfoW
shlwapi.dll
StrRetToBufW
spp.dll
SppFreeGroupPropArray, SxTracerDebuggerBreak, SxTracerShouldTrackFailure, SxTracerGetThreadContextRetail
srclient.dll
SRSetRestorePointW
user32.dll
EndPaint, MapWindowPoints, GetWindowRect, BeginPaint, SetWindowPos, OffsetRect, CopyRect, GetDesktopWindow, MsgWaitForMultipleObjectsEx, IsWindow, SetWindowLongW, GetWindowTextW, GetDlgItem, SendMessageW, SetFocus, EnableWindow, SystemParametersInfoW, GetWindowLongW, GetSysColor, GetSysColorBrush, DestroyIcon, LoadStringW, DialogBoxParamW, LoadCursorW, GetParent, SetCursor, MessageBoxW, SetDlgItemTextW, PeekMessageW, EndDialog, IsDlgButtonChecked, IsWindowEnabled, DispatchMessageW, SetWindowTextW, CheckRadioButton, PostMessageW, GetSystemMetrics, GetClientRect, CreateDialogParamW, ShowWindow, DestroyWindow, DestroyCursor
vssapi.dll
VssFreeSnapshotPropertiesInternal, CreateVssBackupComponentsInternal
Export table
ExecuteScheduledSPPCreationW
SRGetCplPropPage

srrstr.dll

Microsoft Windows System Protection Configuration Library by Microsoft

Remove srrstr.dll
Version:   6.0.6000.16386 (vista_rtm.061101-2205)
MD5:   63e2e63fb1973fb9903d154fbd79c777
SHA1:   12fa34eef4d95eb4a62d854c38dc366cb21a3523
SHA256:   03b48f5ffb1a6ddac86022b5fa5d7edb8fb3745ff32f9d004adc8b569e537ec1
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

srrstr.dll executes as a process with the local user's privileges. It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows Vista.

DetailsDetails

File name:srrstr.dll
Publisher:Microsoft Corporation
Product name:Microsoft® Windows System Protection Configuration Library
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srrstr.dll
Original name:srprop.dll.mui
File version:6.0.6000.16386 (vista_rtm.061101-2205)
Product version:6.0.6000.16386
Size:263 KB (269,312 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The job 'SR' runs daily in the path '\Microsoft\Windows\SystemRestore\SR'
  • Entry path '\Microsoft\Windows\SystemRestore\SR'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\Microsoft\Windows\SystemRestore\SR'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 56.00%
Windows 7 Ultimate 26.50%
Windows 7 Professional 11.50%
Windows 7 Home Basic 3.00%
Windows Vista Home Premium 2.00%
Windows Seven Black Edition 1.00%

Distribution by countryDistribution by country

United States installs about 44.95% of Microsoft® Windows System Protection Configuration Library.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 23.58%
Hewlett-Packard 19.92%
ASUS 17.89%
Acer 13.41%
Toshiba 11.38%
Sony 6.50%
GIGABYTE 2.44%
Alienware 1.63%
Samsung 1.63%
Lenovo 1.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE