Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.1.7600.16385 (win7_rtm.090713-1255) 53.19%
6.1.7600.16385 (win7_rtm.090713-1255) 7.55%
6.1.7600.16385 (win7_rtm.090713-1255) 0.19%
6.1.7600.16385 (win7_rtm.090713-1255) 24.17%
6.1.7600.16385 (win7_rtm.090713-1255) 4.86%
6.0.6000.16386 (vista_rtm.061101-2205) 0.56%
6.0.6000.16386 (vista_rtm.061101-2205) 7.81%
6.0.6000.16386 (vista_rtm.061101-2205) 1.68%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
StartTraceW, EnableTrace, ControlTraceW, InitializeSecurityDescriptor, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, RegCreateKeyExW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegSetValueExW, RegQueryValueExW, CreateWellKnownSid, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, RegOpenKeyExW, CloseTrace, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegCloseKey, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage
comctl32.dll
CreatePropertySheetPageW, ImageList_Create, ImageList_ReplaceIcon, ImageList_Destroy
gdi32.dll
SetBkColor, CreateFontIndirectW, DeleteObject, ExtTextOutW, SetTextColor
kernel32.dll
GetProcAddress, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, LoadLibraryW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, QueryPerformanceCounter, InterlockedCompareExchange, Sleep, InterlockedExchange, GetExitCodeThread, FreeLibraryAndExitThread, CreateThread, CreateProcessW, SetLastError, CreateFileW, CloseHandle, InterlockedDecrement, InterlockedIncrement, HeapSetInformation, GetModuleHandleExW, FreeLibrary, GetFileAttributesW, DeleteFileW, GetLastError, LocalFree, GetSystemTimeAsFileTime, DisableThreadLibraryCalls, GetNumberFormatW, FormatMessageW, LoadLibraryExW, GetModuleHandleW, GetVolumeInformationW, GetDriveTypeW, GetVolumePathNameW, FindFirstFileW, FindNextFileW, DeviceIoControl, MoveFileExW, FindClose, GetVolumeNameForVolumeMountPointW, GetVolumePathNamesForVolumeNameW, ExpandEnvironmentStringsW, CreateDirectoryW
msvcrt.dll
DllMain
ntdll.dll
WinSqmAddToStream, RtlGetLastNtStatus, RtlNtStatusToDosError, NtSetInformationFile, NtQueryInformationFile, EtwTraceMessage, NtSetInformationProcess, NtQueryVolumeInformationFile, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlDeleteElementGenericTableAvl, RtlEnumerateGenericTableAvl, RtlInitializeGenericTableAvl, WinSqmSetDWORD
ole32.dll
CoInitializeEx, CoUninitialize, CoCreateInstance, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, CoWaitForMultipleHandles, CoGetMalloc, CoInitializeSecurity
shell32.dll
SHParseDisplayName, SHGetDesktopFolder, SHGetStockIconInfo, SHGetFileInfoW
shlwapi.dll
StrRetToBufW
spp.dll
SppFreeGroupPropArray, SxTracerDebuggerBreak, SxTracerShouldTrackFailure, SxTracerGetThreadContextRetail
srclient.dll
SRSetRestorePointW
user32.dll
EndPaint, MapWindowPoints, GetWindowRect, BeginPaint, SetWindowPos, OffsetRect, CopyRect, GetDesktopWindow, MsgWaitForMultipleObjectsEx, IsWindow, SetWindowLongW, GetWindowTextW, GetDlgItem, SendMessageW, SetFocus, EnableWindow, SystemParametersInfoW, GetWindowLongW, GetSysColor, GetSysColorBrush, DestroyIcon, LoadStringW, DialogBoxParamW, LoadCursorW, GetParent, SetCursor, MessageBoxW, SetDlgItemTextW, PeekMessageW, EndDialog, IsDlgButtonChecked, IsWindowEnabled, DispatchMessageW, SetWindowTextW, CheckRadioButton, PostMessageW, GetSystemMetrics, GetClientRect, CreateDialogParamW, ShowWindow, DestroyWindow, DestroyCursor
vssapi.dll
VssFreeSnapshotPropertiesInternal, CreateVssBackupComponentsInternal
Export table
ExecuteScheduledSPPCreationW
SRGetCplPropPage

srrstr.dll

Microsoft Windows System Protection Configuration Library by Microsoft

Remove srrstr.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   ae09bfcedba8ad3e02a5f221666af769
SHA1:   ed7b85f90f291da1e591e7dbe808814edf64a033
SHA256:   402b81bd1e98cac2bc605136fcaadac38dbc0da148c6ec6b173361283be646bc
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

srrstr.dll executes as a process with the local user's privileges. It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7.

DetailsDetails

File name:srrstr.dll
Publisher:Microsoft Corporation
Product name:Microsoft® Windows System Protection Configuration Library
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srrstr.dll
Original name:srprop.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:264.5 KB (270,848 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The job 'SR' runs daily in the path '\Microsoft\Windows\SystemRestore\SR'
  • Entry path '\Microsoft\Windows\SystemRestore\SR'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\Microsoft\Windows\SystemRestore\SR'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 56.00%
Windows 7 Ultimate 26.50%
Windows 7 Professional 11.50%
Windows 7 Home Basic 3.00%
Windows Vista Home Premium 2.00%
Windows Seven Black Edition 1.00%

Distribution by countryDistribution by country

United States installs about 44.95% of Microsoft® Windows System Protection Configuration Library.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 23.58%
Hewlett-Packard 19.92%
ASUS 17.89%
Acer 13.41%
Toshiba 11.38%
Sony 6.50%
GIGABYTE 2.44%
Alienware 1.63%
Samsung 1.63%
Lenovo 1.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE