Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.1.7600.16385 (win7_rtm.090713-1255) 53.19%
6.1.7600.16385 (win7_rtm.090713-1255) 7.55%
6.1.7600.16385 (win7_rtm.090713-1255) 0.19%
6.1.7600.16385 (win7_rtm.090713-1255) 24.17%
6.1.7600.16385 (win7_rtm.090713-1255) 4.86%
6.0.6000.16386 (vista_rtm.061101-2205) 0.56%
6.0.6000.16386 (vista_rtm.061101-2205) 7.81%
6.0.6000.16386 (vista_rtm.061101-2205) 1.68%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
StartTraceW, EnableTrace, ControlTraceW, InitializeSecurityDescriptor, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, RegCreateKeyExW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegSetValueExW, RegQueryValueExW, CreateWellKnownSid, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, RegOpenKeyExW, CloseTrace, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegCloseKey, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage
comctl32.dll
CreatePropertySheetPageW, ImageList_Create, ImageList_ReplaceIcon, ImageList_Destroy
gdi32.dll
SetBkColor, CreateFontIndirectW, DeleteObject, ExtTextOutW, SetTextColor
kernel32.dll
GetProcAddress, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, LoadLibraryW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, QueryPerformanceCounter, InterlockedCompareExchange, Sleep, InterlockedExchange, GetExitCodeThread, FreeLibraryAndExitThread, CreateThread, CreateProcessW, SetLastError, CreateFileW, CloseHandle, InterlockedDecrement, InterlockedIncrement, HeapSetInformation, GetModuleHandleExW, FreeLibrary, GetFileAttributesW, DeleteFileW, GetLastError, LocalFree, GetSystemTimeAsFileTime, DisableThreadLibraryCalls, GetNumberFormatW, FormatMessageW, LoadLibraryExW, GetModuleHandleW, GetVolumeInformationW, GetDriveTypeW, GetVolumePathNameW, FindFirstFileW, FindNextFileW, DeviceIoControl, MoveFileExW, FindClose, GetVolumeNameForVolumeMountPointW, GetVolumePathNamesForVolumeNameW, ExpandEnvironmentStringsW, CreateDirectoryW
msvcrt.dll
DllMain
ntdll.dll
WinSqmAddToStream, RtlGetLastNtStatus, RtlNtStatusToDosError, NtSetInformationFile, NtQueryInformationFile, EtwTraceMessage, NtSetInformationProcess, NtQueryVolumeInformationFile, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlDeleteElementGenericTableAvl, RtlEnumerateGenericTableAvl, RtlInitializeGenericTableAvl, WinSqmSetDWORD
ole32.dll
CoInitializeEx, CoUninitialize, CoCreateInstance, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, CoWaitForMultipleHandles, CoGetMalloc, CoInitializeSecurity
shell32.dll
SHParseDisplayName, SHGetDesktopFolder, SHGetStockIconInfo, SHGetFileInfoW
shlwapi.dll
StrRetToBufW
spp.dll
SppFreeGroupPropArray, SxTracerDebuggerBreak, SxTracerShouldTrackFailure, SxTracerGetThreadContextRetail
srclient.dll
SRSetRestorePointW
user32.dll
EndPaint, MapWindowPoints, GetWindowRect, BeginPaint, SetWindowPos, OffsetRect, CopyRect, GetDesktopWindow, MsgWaitForMultipleObjectsEx, IsWindow, SetWindowLongW, GetWindowTextW, GetDlgItem, SendMessageW, SetFocus, EnableWindow, SystemParametersInfoW, GetWindowLongW, GetSysColor, GetSysColorBrush, DestroyIcon, LoadStringW, DialogBoxParamW, LoadCursorW, GetParent, SetCursor, MessageBoxW, SetDlgItemTextW, PeekMessageW, EndDialog, IsDlgButtonChecked, IsWindowEnabled, DispatchMessageW, SetWindowTextW, CheckRadioButton, PostMessageW, GetSystemMetrics, GetClientRect, CreateDialogParamW, ShowWindow, DestroyWindow, DestroyCursor
vssapi.dll
VssFreeSnapshotPropertiesInternal, CreateVssBackupComponentsInternal
Export table
ExecuteScheduledSPPCreationW
SRGetCplPropPage

srrstr.dll

Microsoft Windows System Protection Configuration Library by Microsoft

Remove srrstr.dll
Version:   6.0.6000.16386 (vista_rtm.061101-2205)
MD5:   c46ccbe300d76b2597bb02bdfc31deb4
SHA1:   2aefb6b2f4f0e5b6d5c1ab1a02a785a7dda75bb3
SHA256:   c0ec8e36d2793626c41d7a4110b8af9b4c81dcab3cac78b29b714e34b12d5562
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

srrstr.dll executes as a process with the local user's privileges. It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows Vista.

DetailsDetails

File name:srrstr.dll
Publisher:Microsoft Corporation
Product name:Microsoft® Windows System Protection Configuration Library
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srrstr.dll
Original name:srprop.dll.mui
File version:6.0.6000.16386 (vista_rtm.061101-2205)
Product version:6.0.6000.16386
Size:276.5 KB (283,136 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The job 'SR' runs daily in the path '\Microsoft\Windows\SystemRestore\SR'
  • Entry path '\Microsoft\Windows\SystemRestore\SR'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\Microsoft\Windows\SystemRestore\SR'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 56.00%
Windows 7 Ultimate 26.50%
Windows 7 Professional 11.50%
Windows 7 Home Basic 3.00%
Windows Vista Home Premium 2.00%
Windows Seven Black Edition 1.00%

Distribution by countryDistribution by country

United States installs about 44.95% of Microsoft® Windows System Protection Configuration Library.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 23.58%
Hewlett-Packard 19.92%
ASUS 17.89%
Acer 13.41%
Toshiba 11.38%
Sony 6.50%
GIGABYTE 2.44%
Alienware 1.63%
Samsung 1.63%
Lenovo 1.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE