Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 0.87%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.87%
6.2.9200.16384 (win8_rtm.120725-1247) 1.74%
6.2.9200.16384 (win8_rtm.120725-1247) 10.43%
6.1.7600.16385 (win7_rtm.090713-1255) 50.43%
6.1.7600.16385 (win7_rtm.090713-1255) 24.35%
6.0.6000.16386 (vista_rtm.061101-2205) 0.87%
6.0.6000.16386 (vista_rtm.061101-2205) 1.74%
6.0.6000.16386 (vista_rtm.061101-2205) 8.70%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, AddAccessDeniedAceEx, AddAccessAllowedAceEx, OpenProcessToken, OpenThreadToken, SetSecurityDescriptorDacl, DuplicateToken, RegOpenKeyExW, RegQueryValueExW, RegDeleteValueW, RegSetValueExW, RegEnumKeyExW, RegEnumValueW, RegQueryInfoKeyW, InitializeSecurityDescriptor, CopySid, GetLengthSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, LookupAccountNameW, AddAce, GetAce, GetAclInformation, FreeSid, CheckTokenMembership, AllocateAndInitializeSid, CreateWellKnownSid, RegisterServiceCtrlHandlerExW, OpenServiceW, DeleteService, OpenSCManagerW, CreateServiceW, ChangeServiceConfig2W, CloseServiceHandle, SetServiceStatus, LookupAccountSidW, ConvertSidToStringSidW, InitializeAcl
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
RaiseException, GetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter, RaiseException
api-ms-win-core-file-l1-1-0.dll
CreateFileW, GetDiskFreeSpaceExW, GetDriveTypeW, GetVolumeInformationW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW
api-ms-win-core-file-l1-2-0.dll
GetVolumePathNameW, GetDiskFreeSpaceExW, ReadFile, GetDriveTypeW, CreateFileW, GetVolumeInformationW, GetVolumeNameForVolumeMountPointW, FindVolumeClose, FindNextVolumeW, GetFileAttributesW, FindFirstVolumeW, GetVolumePathNamesForVolumeNameW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapDestroy
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedExchange, InterlockedIncrement, InterlockedCompareExchange, InterlockedDecrement
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedDecrement, InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-io-l1-1-0.dll
GetOverlappedResult, DeviceIoControl
api-ms-win-core-io-l1-1-1.dll
DeviceIoControl, GetOverlappedResult
api-ms-win-core-libraryloader-l1-1-0.dll
LoadStringW, DisableThreadLibraryCalls, GetProcAddress, FreeLibrary, LoadLibraryExA
api-ms-win-core-libraryloader-l1-1-1.dll
FindResourceExW, GetModuleFileNameW, DisableThreadLibraryCalls, LoadResource, LoadLibraryExW, LoadStringW, SizeofResource, FreeLibrary, GetModuleHandleW, GetProcAddress
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW
api-ms-win-core-memory-l1-1-1.dll
VirtualQuery, VirtualAlloc, VirtualProtect, VirtualFree
api-ms-win-core-misc-l1-1-0.dll
LocalFree, Sleep, LocalAlloc
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
GetCommandLineW, ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-0.dll
ResumeThread, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetCurrentProcess, OpenProcessToken, OpenThreadToken, SetThreadToken
api-ms-win-core-processthreads-l1-1-1.dll
TerminateProcess, ResumeThread, GetCurrentProcessId, SetThreadToken, OpenProcessToken, OpenThreadToken, GetCurrentThreadId, GetCurrentThread, GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteTreeW, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW, RegEnumValueW, RegDeleteValueW, RegCloseKey
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar
api-ms-win-core-string-l2-1-0.dll
CharPrevW, CharNextW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcpynW, lstrcmpiW
api-ms-win-core-synch-l1-1-0.dll
LeaveCriticalSection, WaitForSingleObject, ResetEvent, CreateEventW, SetWaitableTimer, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, CancelWaitableTimer
api-ms-win-core-synch-l1-2-0.dll
InitializeCriticalSection, LeaveCriticalSection, DeleteCriticalSection, WaitForSingleObject, ResetEvent, CancelWaitableTimer, CreateEventW, Sleep, CreateWaitableTimerExW, EnterCriticalSection, SetWaitableTimer
api-ms-win-core-sysinfo-l1-1-0.dll
GetSystemTimeAsFileTime, GetTickCount, GetComputerNameExW
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemInfo, GetComputerNameExW, GetWindowsDirectoryW, GetVersionExW, GetTickCount, GetSystemWindowsDirectoryW, GetSystemDirectoryW, GetSystemTimeAsFileTime
api-ms-win-security-base-l1-1-0.dll
AdjustTokenPrivileges, DuplicateTokenEx, GetTokenInformation, CopySid, GetLengthSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, AddAce, GetAce, GetAclInformation, AddAccessDeniedAceEx, InitializeAcl, AddAccessAllowedAceEx, SetSecurityDescriptorDacl, IsValidSid, CreateWellKnownSid, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, DuplicateToken, InitializeSecurityDescriptor
api-ms-win-security-base-l1-2-0.dll
InitializeAcl, AddAce, GetAce, GetAclInformation, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, CopySid, GetLengthSid, AddAccessDeniedAceEx, InitializeSecurityDescriptor, CreateWellKnownSid, AddAccessAllowedAceEx, FreeSid, IsValidSid, DuplicateTokenEx, AdjustTokenPrivileges, CheckTokenMembership, AllocateAndInitializeSid, GetTokenInformation, SetSecurityDescriptorOwner
clusapi.dll
AddClusterResourceDependency, OpenClusterResource, ClusterCloseEnum, OpenCluster, RemoveClusterResourceDependency, CloseClusterResource, ClusterResourceControl, CanResourceBeDependent, ClusterOpenEnum, ClusterGetEnumCount, GetClusterResourceState, OnlineClusterResource, OfflineClusterResource, ClusterResourceCloseEnum, ClusterResourceEnum, ClusterResourceGetEnumCount, ClusterResourceOpenEnum, ClusterEnum
kernel32.dll
GetVersionExW, GetSystemDirectoryW, RegCloseKey, GetCommandLineW, GetSystemWindowsDirectoryW, GetVolumePathNameW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, RegQueryValueExW, CreateWaitableTimerW, GetVolumeNameForVolumeMountPointW, GetVolumePathNamesForVolumeNameW, DelayLoadFailureHook, LoadLibraryW, LoadLibraryExW, GetCurrentThread, GetFileAttributesW, VirtualFree, ReadFile, VirtualAlloc, MultiByteToWideChar, FormatMessageW, RegOpenKeyExW, GetDiskFreeSpaceExW, DeviceIoControl, GetComputerNameExW, GetVolumeInformationW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, ExpandEnvironmentStringsW, InterlockedExchange, InterlockedCompareExchange, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, RaiseException, GetProcAddress, FreeLibrary, GetComputerNameW, GetDriveTypeW, lstrlenW, GetOverlappedResult, LocalAlloc, InterlockedDecrement, LeaveCriticalSection, EnterCriticalSection, InterlockedIncrement, DeleteCriticalSection, InitializeCriticalSection, LocalFree, WaitForSingleObject, ResumeThread, GetLastError, CloseHandle, SetLastError, CancelWaitableTimer, GetCurrentThreadId, DisableThreadLibraryCalls, SetWaitableTimer, Sleep, CreateFileW, CreateEventW, ResetEvent
msvcrt.dll
DllMain
netapi32.dll
NetApiBufferFree, NetLocalGroupGetMembers
ntdll.dll
WinSqmAddToStream, NtQuerySystemInformation, RtlInitializeBitMap, RtlNtStatusToDosError, RtlTimeToElapsedTimeFields, NtQueryVolumeInformationFile, RtlNtStatusToDosErrorNoTeb, RtlCompareMemory
ole32.dll
CoInitializeSecurity, CoCreateInstance, CLSIDFromString, CoDisconnectContext, CoInitializeEx, CoGetObjectContext, CoUninitialize, CoTaskMemAlloc, CoRevertToSelf, CoCreateGuid, CoImpersonateClient, CoTaskMemFree
setupapi.dll
SetupDiGetClassDevsW, SetupDiGetDeviceInterfaceDetailW, SetupDiEnumDeviceInterfaces, SetupDiGetDeviceRegistryPropertyW, SetupDiDestroyDeviceInfoList
shlwapi.dll
SHDeleteKeyW
user32.dll
LoadStringW
virtdisk.dll
GetStorageDependencyInformation
vssapi.dll
VssFreeSnapshotPropertiesInternal
Export table
DllCanUnloadNow
DllGetClassObject
DllInstall
DllRegisterServer
DllUnregisterServer
ServiceMain

swprv.dll

Microsoft Volume Shadow Copy Service software provider by Microsoft

Remove swprv.dll
Version:   6.3.9431.0 (winmain_bluemp.130615-1214)
MD5:   86b3db80acb4fcf20bc629c897343dea
SHA1:   a2b72567c414ac3b7c0364e8f82066f334ce294f
SHA256:   3cb9493fced99a2203a1bf450100da860214f9f4a7396c721426b5c4d1ab4349
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is swprv.dll?

The Volume Shadow Copy Service provides the backup infrastructure for the Microsoft Windows, as well as a mechanism for creating consistent point-in-time copies of data known as shadow copies. The Volume Shadow Copy Service can produce consistent shadow copies by coordinating with business applications, file-system services, backup applications, fast-recovery solutions, and storage hardware.

About swprv.dll (from Microsoft)

The Volume Shadow Copy Service (VSS) is a set of COM APIs that implements a framework to allow volume backups to be performed while applications on a system continue to write to the volumes. VSS provi

DetailsDetails

File name:swprv.dll
Publisher:Microsoft Corporation
Product name:Microsoft® Volume Shadow Copy Service software provider
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\swprv.dll
Original name:SWPRV.DLL.MUI
File version:6.3.9431.0 (winmain_bluemp.130615-1214)
Product version:6.3.9431.0
Size:699 KB (715,776 bytes)
Build date:6/15/2013 3:19 PM
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'
  • Shared name is 'swprv'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 45.19%
Windows 7 Ultimate 14.42%
Windows 7 Ultimate N 10.58%
Windows 8 7.69%
Windows 7 Professional 6.73%
Windows 7 Home Basic 2.88%
Windows Vista Home Premium 2.88%
Windows 8 Pro 1.92%
Windows 8 Pro with Media Center 1.92%
Windows 8.1 Pro 0.96%
Windows 8 Enterprise N 0.96%
Windows Vista Ultimate 0.96%
Windows 8.1 Pro Preview with Media Center 0.96%
Windows 8 Enterprise 0.96%
Windows 7 Enterprise 0.96%

Distribution by countryDistribution by country

United States installs about 69.31% of Microsoft® Volume Shadow Copy Service software provider.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 20.00%
Dell 20.00%
Toshiba 15.00%
Acer 13.75%
Lenovo 10.00%
Intel 5.00%
GIGABYTE 3.75%
Gateway 2.50%
MSI 2.50%
ASUS 2.50%
Sony 2.50%
American Megatrends 1.25%
Samsung 1.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE