Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 66.67%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 3.92%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 2.94%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 1.96%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 0.98%
5.1.2600.5512 (xpsp.080413-2108) 1.96%
5.1.2600.5512 (xpsp.080413-2108) 0.98%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.3311 (xpsp.080212-0003) 0.65%
5.1.2600.3300 (xpsp.080125-2027) 0.33%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 15.03%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.33%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.65%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExW, RegReplaceKeyW, OpenThreadToken, DuplicateTokenEx, LookupPrivilegeValueW, AdjustTokenPrivileges, RegEnumValueW, RegLoadKeyW, RegUnLoadKeyW, RegDeleteKeyW, RegSaveKeyExW, SetThreadToken, InitializeAcl, AddAccessAllowedAce, CheckTokenMembership, ReportEventW, RegCreateKeyExW, GetNamedSecurityInfoW, GetAclInformation, GetAce, EqualSid, SetNamedSecurityInfoW, AllocateAndInitializeSid, SetEntriesInAclW, SetSecurityInfo, LsaQueryInformationPolicy, LsaOpenPolicy, LsaClose, QueryServiceConfigW, ChangeServiceConfigW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetFileSecurityW, FreeSid, OpenSCManagerW, OpenServiceW, CloseServiceHandle, StartServiceA, RegSetValueExW, RegisterIdleTask, UnregisterIdleTask, RegDeleteValueW, RegOpenKeyW, RegQueryValueExW, RegisterServiceCtrlHandlerW, RegOpenKeyExW, RegCloseKey, SetServiceStatus, OpenEncryptedFileRawW, ReadEncryptedFileRaw, CloseEncryptedFileRaw, WriteEncryptedFileRaw, RegisterEventSourceW, DeregisterEventSource
kernel32.dll
WaitForSingleObject, FindClose, FindNextFileW, CreateDirectoryW, GetEnvironmentVariableW, SetEnvironmentVariableW, QueryDosDeviceW, HeapDestroy, HeapCreate, DuplicateHandle, lstrcmpW, FindFirstFileW, BackupRead, BackupWrite, SetFileTime, GetFileTime, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, QueryPerformanceCounter, GetSystemPowerStatus, GetFileAttributesW, GetCurrentThreadId, lstrlenW, BindIoCompletionCallback, lstrcpyW, LoadLibraryW, UnregisterWaitEx, FreeLibrary, QueueUserWorkItem, GetSystemTimeAsFileTime, GetTickCount, DeleteTimerQueueEx, CreateTimerQueue, CreateTimerQueueTimer, GetDiskFreeSpaceExW, GetDriveTypeW, CreateFileW, ExpandEnvironmentStringsW, lstrcatW, SetFileAttributesW, lstrcmpiW, CopyFileW, lstrcpynW, HeapFree, GetProcessHeap, HeapAlloc, RegisterWaitForSingleObject, DisableThreadLibraryCalls, InterlockedDecrement, SetEvent, InterlockedIncrement, ResetEvent, CloseHandle, CreateEventW, GetLastError, SetFilePointer, GetTempFileNameW, DeviceIoControl, GetLongPathNameW, GetWindowsDirectoryW, GetVolumeNameForVolumeMountPointW, CreateThread, GetCurrentThread, WriteFile, GetProcAddress, GetCompressedFileSizeW, FindFirstVolumeW, FindNextVolumeW, FindVolumeClose, FlushFileBuffers, GetFileSize, GetVolumePathNamesForVolumeNameW, SetLastError, ReadFile, ReleaseMutex, OpenMutexW, CreateMutexW, RemoveDirectoryW, MoveFileW, GetVolumeInformationW, GetSystemDirectoryW, LoadLibraryExW, FormatMessageW, DeleteFileW, OpenEventW, LocalAlloc, LocalFree, GetComputerNameW
msvcrt.dll
DllMain
ntdll.dll
NtDeviceIoControlFile, NtQueryObject, NtWaitForSingleObject, NtClose, NtCreateEvent, RtlInitUnicodeString, NtCreateFile, RtlNtStatusToDosError
ole32.dll
CoInitializeEx, CoSetProxyBlanket, CoUninitialize, CoCreateInstance, StringFromGUID2, CoInitialize
powrprof.dll
GetCurrentPowerPolicies
rpcrt4.dll
UuidCreate, RpcRevertToSelf, RpcImpersonateClient, NdrServerCall2, RpcBindingInqAuthClientW, RpcServerRegisterAuthInfoW, RpcServerUseProtseqEpW, RpcServerRegisterIfEx, I_RpcBindingIsClientLocal, RpcServerUnregisterIf
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathCombineW
user32.dll
GetThreadDesktop, SetProcessWindowStation, GetDesktopWindow, GetSystemMetrics, OpenDesktopW, GetProcessWindowStation, OpenWindowStationW, CharUpperW, LoadStringW, PostMessageW, SetThreadDesktop, RegisterWindowMessageW, CloseDesktop, CloseWindowStation, wsprintfW
Export table
DllMain
ServiceMain

srsvc.dll

System Restore Service by Microsoft

Remove srsvc.dll
Version:   5.1.2600.5512 (xpsp.080413-2108)
MD5:   0c486e769d9f0bd558edf1028d5b3a97
SHA1:   a6bfa43b24576b2c215e4dc37c96710605dfcd3e
SHA256:   b7c9135f88c6a2e54fd4c5fca6b830cd4fc8b41a340864b0fd5681e0eb9b145d
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is srsvc.dll?

System Restore is a component of Microsoft's Windows that allows for the rolling back of system files, registry keys, installed programs, etc., to a previous state in the event of system malfunction or failure. System Restore backs up system files of certain extensions (.exe, .dll, etc.) and saves them for later recovery and use.

Overview

srsvc.dll is loaded as dynamic link library that runs in the context of a process. This version is installed on Windows XP.

DetailsDetails

File name:srsvc.dll
Publisher:Microsoft Corporation
Product name:System Restore Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srsvc.dll
Original name:SERVICE.DLL
File version:5.1.2600.5512 (xpsp.080413-2108)
Product version:5.1.2600.5512
Size:166.5 KB (170,496 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 49.47% of System Restore Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 43.18%
Intel 12.50%
Toshiba 7.95%
Compaq 6.82%
American Megatrends 6.25%
Hewlett-Packard 5.68%
GIGABYTE 4.55%
Sahara 3.41%
ASUS 3.41%
Gateway 2.27%
Acer 1.70%
Lenovo 1.14%
Sony 1.14%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE