Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.1.7600.16385 (win7_rtm.090713-1255) 53.19%
6.1.7600.16385 (win7_rtm.090713-1255) 7.55%
6.1.7600.16385 (win7_rtm.090713-1255) 0.19%
6.1.7600.16385 (win7_rtm.090713-1255) 24.17%
6.1.7600.16385 (win7_rtm.090713-1255) 4.86%
6.0.6000.16386 (vista_rtm.061101-2205) 0.56%
6.0.6000.16386 (vista_rtm.061101-2205) 7.81%
6.0.6000.16386 (vista_rtm.061101-2205) 1.68%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
StartTraceW, EnableTrace, ControlTraceW, InitializeSecurityDescriptor, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, RegCreateKeyExW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegSetValueExW, RegQueryValueExW, CreateWellKnownSid, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, RegOpenKeyExW, CloseTrace, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegCloseKey, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage
comctl32.dll
CreatePropertySheetPageW, ImageList_Create, ImageList_ReplaceIcon, ImageList_Destroy
gdi32.dll
SetBkColor, CreateFontIndirectW, DeleteObject, ExtTextOutW, SetTextColor
kernel32.dll
GetProcAddress, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, LoadLibraryW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, QueryPerformanceCounter, InterlockedCompareExchange, Sleep, InterlockedExchange, GetExitCodeThread, FreeLibraryAndExitThread, CreateThread, CreateProcessW, SetLastError, CreateFileW, CloseHandle, InterlockedDecrement, InterlockedIncrement, HeapSetInformation, GetModuleHandleExW, FreeLibrary, GetFileAttributesW, DeleteFileW, GetLastError, LocalFree, GetSystemTimeAsFileTime, DisableThreadLibraryCalls, GetNumberFormatW, FormatMessageW, LoadLibraryExW, GetModuleHandleW, GetVolumeInformationW, GetDriveTypeW, GetVolumePathNameW, FindFirstFileW, FindNextFileW, DeviceIoControl, MoveFileExW, FindClose, GetVolumeNameForVolumeMountPointW, GetVolumePathNamesForVolumeNameW, ExpandEnvironmentStringsW, CreateDirectoryW
msvcrt.dll
DllMain
ntdll.dll
WinSqmAddToStream, RtlGetLastNtStatus, RtlNtStatusToDosError, NtSetInformationFile, NtQueryInformationFile, EtwTraceMessage, NtSetInformationProcess, NtQueryVolumeInformationFile, RtlInsertElementGenericTableAvl, RtlLookupElementGenericTableAvl, RtlDeleteElementGenericTableAvl, RtlEnumerateGenericTableAvl, RtlInitializeGenericTableAvl, WinSqmSetDWORD
ole32.dll
CoInitializeEx, CoUninitialize, CoCreateInstance, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, CoWaitForMultipleHandles, CoGetMalloc, CoInitializeSecurity
shell32.dll
SHParseDisplayName, SHGetDesktopFolder, SHGetStockIconInfo, SHGetFileInfoW
shlwapi.dll
StrRetToBufW
spp.dll
SppFreeGroupPropArray, SxTracerDebuggerBreak, SxTracerShouldTrackFailure, SxTracerGetThreadContextRetail
srclient.dll
SRSetRestorePointW
user32.dll
EndPaint, MapWindowPoints, GetWindowRect, BeginPaint, SetWindowPos, OffsetRect, CopyRect, GetDesktopWindow, MsgWaitForMultipleObjectsEx, IsWindow, SetWindowLongW, GetWindowTextW, GetDlgItem, SendMessageW, SetFocus, EnableWindow, SystemParametersInfoW, GetWindowLongW, GetSysColor, GetSysColorBrush, DestroyIcon, LoadStringW, DialogBoxParamW, LoadCursorW, GetParent, SetCursor, MessageBoxW, SetDlgItemTextW, PeekMessageW, EndDialog, IsDlgButtonChecked, IsWindowEnabled, DispatchMessageW, SetWindowTextW, CheckRadioButton, PostMessageW, GetSystemMetrics, GetClientRect, CreateDialogParamW, ShowWindow, DestroyWindow, DestroyCursor
vssapi.dll
VssFreeSnapshotPropertiesInternal, CreateVssBackupComponentsInternal
Export table
ExecuteScheduledSPPCreationW
SRGetCplPropPage

srrstr.dll

Microsoft Windows System Protection Configuration Library by Microsoft

Remove srrstr.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   e2864df592832883151a8d5500a7eaaa
SHA1:   f0bc45c590ed9c0937a01619588d8e40430b5450
SHA256:   c6973e008da4aadb924ed4f389eea1f48409eedc335b9cdc0a2e6c4d041613fa
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

srrstr.dll executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges) typically within the context of its parent services.exe (Services and Controller app by Microsoft). It is an auto-starting process that used the Windows Task Scheduler service to load when the user logs into Windows (sometimes this is required to bypass the UAC protection). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7 and is compiled as a 32 bit program.

DetailsDetails

File name:srrstr.dll
Publisher:Microsoft Corporation
Product name:Microsoft® Windows System Protection Configuration Library
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srrstr.dll
Original name:srprop.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:251 KB (257,024 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Scheduled tasks
  • The job 'SR' runs daily in the path '\Microsoft\Windows\SystemRestore\SR'
  • Entry path '\Microsoft\Windows\SystemRestore\SR'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path '\Microsoft\Windows\SystemRestore\SR'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.20255076%
0.028634%
Kernel CPU:0.07396819%
0.013761%
User CPU:0.12858257%
0.014873%
Kernel CPU time:11,860,038 ms/min
100,923,805ms/min
CPU cycles:1,640,355/sec
17,470,203/sec
Memory
Private memory:9.46 MB
21.59 MB
Private (maximum):12.37 MB
Private (minimum):6.85 MB
Non-paged memory:9.46 MB
21.59 MB
Virtual memory:64.63 MB
140.96 MB
Virtual memory (peak):66.72 MB
169.69 MB
Working set:9.06 MB
18.61 MB
Working set (peak):14.77 MB
37.95 MB
Page faults:62,130/min
2,039/min
I/O
I/O read transfer:937.41 KB/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:471.94 KB/sec
274.99 KB/min
I/O write operations:7/sec
227/min
I/O other transfer:695 Bytes/sec
448.09 KB/min
I/O other operations:52/sec
1,671/min
Resource allocations
Threads:5
12
Handles:134
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:C:\Windows\System32\rundll32.exe /d srrstr.dll,executescheduledsppcreation
Owner:SYSTEM
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 56.00%
Windows 7 Ultimate 26.50%
Windows 7 Professional 11.50%
Windows 7 Home Basic 3.00%
Windows Vista Home Premium 2.00%
Windows Seven Black Edition 1.00%

Distribution by countryDistribution by country

United States installs about 44.95% of Microsoft® Windows System Protection Configuration Library.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 23.58%
Hewlett-Packard 19.92%
ASUS 17.89%
Acer 13.41%
Toshiba 11.38%
Sony 6.50%
GIGABYTE 2.44%
Alienware 1.63%
Samsung 1.63%
Lenovo 1.63%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE