Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 66.67%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 3.92%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 2.94%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 1.96%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 0.98%
5.1.2600.5512 (xpsp.080413-2108) 1.96%
5.1.2600.5512 (xpsp.080413-2108) 0.98%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.3311 (xpsp.080212-0003) 0.65%
5.1.2600.3300 (xpsp.080125-2027) 0.33%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 15.03%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.33%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.65%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExW, RegReplaceKeyW, OpenThreadToken, DuplicateTokenEx, LookupPrivilegeValueW, AdjustTokenPrivileges, RegEnumValueW, RegLoadKeyW, RegUnLoadKeyW, RegDeleteKeyW, RegSaveKeyExW, SetThreadToken, InitializeAcl, AddAccessAllowedAce, CheckTokenMembership, ReportEventW, RegCreateKeyExW, GetNamedSecurityInfoW, GetAclInformation, GetAce, EqualSid, SetNamedSecurityInfoW, AllocateAndInitializeSid, SetEntriesInAclW, SetSecurityInfo, LsaQueryInformationPolicy, LsaOpenPolicy, LsaClose, QueryServiceConfigW, ChangeServiceConfigW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetFileSecurityW, FreeSid, OpenSCManagerW, OpenServiceW, CloseServiceHandle, StartServiceA, RegSetValueExW, RegisterIdleTask, UnregisterIdleTask, RegDeleteValueW, RegOpenKeyW, RegQueryValueExW, RegisterServiceCtrlHandlerW, RegOpenKeyExW, RegCloseKey, SetServiceStatus, OpenEncryptedFileRawW, ReadEncryptedFileRaw, CloseEncryptedFileRaw, WriteEncryptedFileRaw, RegisterEventSourceW, DeregisterEventSource
kernel32.dll
WaitForSingleObject, FindClose, FindNextFileW, CreateDirectoryW, GetEnvironmentVariableW, SetEnvironmentVariableW, QueryDosDeviceW, HeapDestroy, HeapCreate, DuplicateHandle, lstrcmpW, FindFirstFileW, BackupRead, BackupWrite, SetFileTime, GetFileTime, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, QueryPerformanceCounter, GetSystemPowerStatus, GetFileAttributesW, GetCurrentThreadId, lstrlenW, BindIoCompletionCallback, lstrcpyW, LoadLibraryW, UnregisterWaitEx, FreeLibrary, QueueUserWorkItem, GetSystemTimeAsFileTime, GetTickCount, DeleteTimerQueueEx, CreateTimerQueue, CreateTimerQueueTimer, GetDiskFreeSpaceExW, GetDriveTypeW, CreateFileW, ExpandEnvironmentStringsW, lstrcatW, SetFileAttributesW, lstrcmpiW, CopyFileW, lstrcpynW, HeapFree, GetProcessHeap, HeapAlloc, RegisterWaitForSingleObject, DisableThreadLibraryCalls, InterlockedDecrement, SetEvent, InterlockedIncrement, ResetEvent, CloseHandle, CreateEventW, GetLastError, SetFilePointer, GetTempFileNameW, DeviceIoControl, GetLongPathNameW, GetWindowsDirectoryW, GetVolumeNameForVolumeMountPointW, CreateThread, GetCurrentThread, WriteFile, GetProcAddress, GetCompressedFileSizeW, FindFirstVolumeW, FindNextVolumeW, FindVolumeClose, FlushFileBuffers, GetFileSize, GetVolumePathNamesForVolumeNameW, SetLastError, ReadFile, ReleaseMutex, OpenMutexW, CreateMutexW, RemoveDirectoryW, MoveFileW, GetVolumeInformationW, GetSystemDirectoryW, LoadLibraryExW, FormatMessageW, DeleteFileW, OpenEventW, LocalAlloc, LocalFree, GetComputerNameW
msvcrt.dll
DllMain
ntdll.dll
NtDeviceIoControlFile, NtQueryObject, NtWaitForSingleObject, NtClose, NtCreateEvent, RtlInitUnicodeString, NtCreateFile, RtlNtStatusToDosError
ole32.dll
CoInitializeEx, CoSetProxyBlanket, CoUninitialize, CoCreateInstance, StringFromGUID2, CoInitialize
powrprof.dll
GetCurrentPowerPolicies
rpcrt4.dll
UuidCreate, RpcRevertToSelf, RpcImpersonateClient, NdrServerCall2, RpcBindingInqAuthClientW, RpcServerRegisterAuthInfoW, RpcServerUseProtseqEpW, RpcServerRegisterIfEx, I_RpcBindingIsClientLocal, RpcServerUnregisterIf
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathCombineW
user32.dll
GetThreadDesktop, SetProcessWindowStation, GetDesktopWindow, GetSystemMetrics, OpenDesktopW, GetProcessWindowStation, OpenWindowStationW, CharUpperW, LoadStringW, PostMessageW, SetThreadDesktop, RegisterWindowMessageW, CloseDesktop, CloseWindowStation, wsprintfW
Export table
DllMain
ServiceMain

srsvc.dll

System Restore Service by Microsoft

Remove srsvc.dll
Version:   5.1.2600.3300 (xpsp.080125-2027)
MD5:   bf3dd2b41260c8b977e38e619cb4dab7
SHA1:   905dfd059b4c38895b0aade63129e81a73bc7eb6
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is srsvc.dll?

System Restore is a component of Microsoft's Windows that allows for the rolling back of system files, registry keys, installed programs, etc., to a previous state in the event of system malfunction or failure. System Restore backs up system files of certain extensions (.exe, .dll, etc.) and saves them for later recovery and use.

Overview

srsvc.dll is loaded as dynamic link library that runs in the context of a process. This version is installed on Windows XP.

DetailsDetails

File name:srsvc.dll
Publisher:Microsoft Corporation
Product name:System Restore Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srsvc.dll
Original name:SERVICE.DLL
File version:5.1.2600.3300 (xpsp.080125-2027)
Product version:5.1.2600.3300
Size:167 KB (171,008 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 49.47% of System Restore Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 43.18%
Intel 12.50%
Toshiba 7.95%
Compaq 6.82%
American Megatrends 6.25%
Hewlett-Packard 5.68%
GIGABYTE 4.55%
Sahara 3.41%
ASUS 3.41%
Gateway 2.27%
Acer 1.70%
Lenovo 1.14%
Sony 1.14%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE