Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 66.67%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 3.92%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 2.94%
5.1.2600.5512 (xpsp.080413-2108) 0.65%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 1.96%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.5512 (xpsp.080413-2108) 0.98%
5.1.2600.5512 (xpsp.080413-2108) 1.96%
5.1.2600.5512 (xpsp.080413-2108) 0.98%
5.1.2600.5512 (xpsp.080413-2108) 0.33%
5.1.2600.3311 (xpsp.080212-0003) 0.65%
5.1.2600.3300 (xpsp.080125-2027) 0.33%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 15.03%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.33%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.65%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExW, RegReplaceKeyW, OpenThreadToken, DuplicateTokenEx, LookupPrivilegeValueW, AdjustTokenPrivileges, RegEnumValueW, RegLoadKeyW, RegUnLoadKeyW, RegDeleteKeyW, RegSaveKeyExW, SetThreadToken, InitializeAcl, AddAccessAllowedAce, CheckTokenMembership, ReportEventW, RegCreateKeyExW, GetNamedSecurityInfoW, GetAclInformation, GetAce, EqualSid, SetNamedSecurityInfoW, AllocateAndInitializeSid, SetEntriesInAclW, SetSecurityInfo, LsaQueryInformationPolicy, LsaOpenPolicy, LsaClose, QueryServiceConfigW, ChangeServiceConfigW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetFileSecurityW, FreeSid, OpenSCManagerW, OpenServiceW, CloseServiceHandle, StartServiceA, RegSetValueExW, RegisterIdleTask, UnregisterIdleTask, RegDeleteValueW, RegOpenKeyW, RegQueryValueExW, RegisterServiceCtrlHandlerW, RegOpenKeyExW, RegCloseKey, SetServiceStatus, OpenEncryptedFileRawW, ReadEncryptedFileRaw, CloseEncryptedFileRaw, WriteEncryptedFileRaw, RegisterEventSourceW, DeregisterEventSource
kernel32.dll
WaitForSingleObject, FindClose, FindNextFileW, CreateDirectoryW, GetEnvironmentVariableW, SetEnvironmentVariableW, QueryDosDeviceW, HeapDestroy, HeapCreate, DuplicateHandle, lstrcmpW, FindFirstFileW, BackupRead, BackupWrite, SetFileTime, GetFileTime, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, QueryPerformanceCounter, GetSystemPowerStatus, GetFileAttributesW, GetCurrentThreadId, lstrlenW, BindIoCompletionCallback, lstrcpyW, LoadLibraryW, UnregisterWaitEx, FreeLibrary, QueueUserWorkItem, GetSystemTimeAsFileTime, GetTickCount, DeleteTimerQueueEx, CreateTimerQueue, CreateTimerQueueTimer, GetDiskFreeSpaceExW, GetDriveTypeW, CreateFileW, ExpandEnvironmentStringsW, lstrcatW, SetFileAttributesW, lstrcmpiW, CopyFileW, lstrcpynW, HeapFree, GetProcessHeap, HeapAlloc, RegisterWaitForSingleObject, DisableThreadLibraryCalls, InterlockedDecrement, SetEvent, InterlockedIncrement, ResetEvent, CloseHandle, CreateEventW, GetLastError, SetFilePointer, GetTempFileNameW, DeviceIoControl, GetLongPathNameW, GetWindowsDirectoryW, GetVolumeNameForVolumeMountPointW, CreateThread, GetCurrentThread, WriteFile, GetProcAddress, GetCompressedFileSizeW, FindFirstVolumeW, FindNextVolumeW, FindVolumeClose, FlushFileBuffers, GetFileSize, GetVolumePathNamesForVolumeNameW, SetLastError, ReadFile, ReleaseMutex, OpenMutexW, CreateMutexW, RemoveDirectoryW, MoveFileW, GetVolumeInformationW, GetSystemDirectoryW, LoadLibraryExW, FormatMessageW, DeleteFileW, OpenEventW, LocalAlloc, LocalFree, GetComputerNameW
msvcrt.dll
DllMain
ntdll.dll
NtDeviceIoControlFile, NtQueryObject, NtWaitForSingleObject, NtClose, NtCreateEvent, RtlInitUnicodeString, NtCreateFile, RtlNtStatusToDosError
ole32.dll
CoInitializeEx, CoSetProxyBlanket, CoUninitialize, CoCreateInstance, StringFromGUID2, CoInitialize
powrprof.dll
GetCurrentPowerPolicies
rpcrt4.dll
UuidCreate, RpcRevertToSelf, RpcImpersonateClient, NdrServerCall2, RpcBindingInqAuthClientW, RpcServerRegisterAuthInfoW, RpcServerUseProtseqEpW, RpcServerRegisterIfEx, I_RpcBindingIsClientLocal, RpcServerUnregisterIf
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathCombineW
user32.dll
GetThreadDesktop, SetProcessWindowStation, GetDesktopWindow, GetSystemMetrics, OpenDesktopW, GetProcessWindowStation, OpenWindowStationW, CharUpperW, LoadStringW, PostMessageW, SetThreadDesktop, RegisterWindowMessageW, CloseDesktop, CloseWindowStation, wsprintfW
Export table
DllMain
ServiceMain

srsvc.dll

System Restore Service by Microsoft

Remove srsvc.dll
Version:   5.1.2600.3311 (xpsp.080212-0003)
MD5:   c48c9775adf79320de07a354d3f2fa48
SHA1:   e63ac8845ba053d327a1b840917588ebd7618967
SHA256:   d6cae90ed5149de44071b7d115ee6a686081d0ac519d5613d4e2bdc80d300445
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is srsvc.dll?

System Restore is a component of Microsoft's Windows that allows for the rolling back of system files, registry keys, installed programs, etc., to a previous state in the event of system malfunction or failure. System Restore backs up system files of certain extensions (.exe, .dll, etc.) and saves them for later recovery and use.

Overview

srsvc.dll is loaded as dynamic link library that runs in the context of a process. This version is installed on Windows XP.

DetailsDetails

File name:srsvc.dll
Publisher:Microsoft Corporation
Product name:System Restore Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\srsvc.dll
Original name:SERVICE.DLL
File version:5.1.2600.3311 (xpsp.080212-0003)
Product version:5.1.2600.3311
Size:167 KB (171,008 bytes)
Build date:2/12/2008 1:28 AM
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'
  • Shared name is 'srservice'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 49.47% of System Restore Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 43.18%
Intel 12.50%
Toshiba 7.95%
Compaq 6.82%
American Megatrends 6.25%
Hewlett-Packard 5.68%
GIGABYTE 4.55%
Sahara 3.41%
ASUS 3.41%
Gateway 2.27%
Acer 1.70%
Lenovo 1.14%
Sony 1.14%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE