File details
File name: AppleMobileDeviceService.exe
Description: MobileDeviceService
Version: 17.96.2.2
Product version: 3.3.0.0
Size: 55.67 KB
Original file name: AppleMobileDeviceService.exe
Digital certificate
Certificate authority:
VeriSign
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0016941166%
Privileged CPU:
0.0009181193%

User CPU:
0.00077599733547%

Privileged CPU time: 10659289.66 ms
Privileged CPU time /min: 1,211 ms
CPU cycle count:
104,339,081
CPU cycle count /min: 83,669,291
Context switches /sec:
7
 | Memory utilization averages |
Committed memory:
90.03 MB
Peak committed memory: 94.62 MB
Paged memory:
4.57 MB
Peak paged memory: 4.71 MB
Paged system memory:
152.43 KB
Non-paged system memory: 19.67 KB
Working set memory:
8.23 MB
Peak working set memory: 11.95 MB
Min working set memory: 6.44 MB
Private memory:
4.57 MB
Page faults:
15,430
Page faults /min: 27
 | Process I/O averages |
Total read operations:
241
Read operations /min: 1
Total read transfer: 2.02 MB
Read transfer /min: 737 Bytes
Total write operations:
342
Write operations /min: 1
Total write transfer: 46.43 KB
Write transfer /min: 53 Bytes
Total other operations:
16,348
Other operations /min: 7
Other Transfer /min: 9.63 KB
 | GUI Object Averages |
GDI objects:
4
USER objects:
2
Resources
Handle count average: 232
Thread count average: 11
Thread resource averages
msvcr80.dll

Total CPU: 0.051527506088%
Privileged CPU: 0.012228080970%
User CPU: 0.039299425118%
CPU Cycle count /sec: 1,229,139
Context switches /sec: 1
Module memory size: 620 KB
Total CPU: 0.012880642851%
Privileged CPU: 0.008610446285%
User CPU: 0.004270196566%
CPU Cycle count /sec: 301,024
Module memory size: 368 KB
ntdll.dll

Total CPU: 0.009665116180%
Privileged CPU: 0.009665116180%
User CPU: 0.000000000000%
CPU Cycle count /sec: 14,942
Module memory size: 1.23 MB
Total CPU: 0.005409665521%
Privileged CPU: 0.002575054131%
User CPU: 0.002834611390%
CPU Cycle count /sec: 345,252
Module memory size: 252 KB
Total CPU: 0.004899174746%
Privileged CPU: 0.002296220713%
User CPU: 0.002602954033%
CPU Cycle count /sec: 93,358
Context switches /sec: 1
Module memory size: 220 KB
msvcr80.dll

Total CPU: 0.003861513353%
Privileged CPU: 0.001813102168%
User CPU: 0.002048411185%
CPU Cycle count /sec: 199,418
Context switches /sec: 2
Module memory size: 620 KB
Total CPU: 0.003210690894%
Privileged CPU: 0.001481961416%
User CPU: 0.001728729478%
CPU Cycle count /sec: 152,236
Context switches /sec: 1
Module memory size: 48 KB
msvcr80.dll

Total CPU: 0.002982874091%
Privileged CPU: 0.001412831599%
User CPU: 0.001570042492%
CPU Cycle count /sec: 208,035
Context switches /sec: 1
Module memory size: 620 KB
ntdll.dll

Total CPU: 0.000206254738%
Privileged CPU: 0.000000000000%
User CPU: 0.000206254738%
CPU Cycle count /sec: 427
Module memory size: 1.66 MB
wow64cpu.dll

Total CPU: 0.000006119546%
Privileged CPU: 0.000006119546%
User CPU: 0.000000000000%
CPU Cycle count /sec: 27
Module memory size: 32 KB
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Programas\Ficheiros comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
Service details
Name: Apple Mobile Device
Service type:
Win32OwnProcess
Description: “Provides the interface to Apple mobile devices.”
Network connectivity
UDP: LISTENING on port 52281
TCP: localhost on port 27015
UDP: LISTENING on port 55017
TCP: localhost on port 27015
UDP: LISTENING on port 49153
TCP: localhost on port 49155
UDP: LISTENING on port 58565
TCP: localhost on port 49156
UDP: LISTENING on port 64297
TCP: localhost on port 49634
UDP: LISTENING on port 63708
TCP: localhost on port 27015
Image hashes
MD5: 4fe5c6d40664ae07be5105874357d2ed
SHA-1: 131fbf9c3e5aade1a0f64f3b4f640e82856fdab4
SHA-256: 70dd05ee80b77eb2f781e0919885d1bbb1119ea1a8955935af5aecd05e30f14a
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++ 8.0
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegCreateKeyW
RegOpenKeyExW
RegQueryValueExW
kernel32.dll

GetLastError
GetModuleFileNameW
GetEnvironmentVariableW
SetDllDirectoryW
GetFileAttributesW
WideCharToMultiByte
Process32Next
Process32First
FreeEnvironmentStringsW
CloseHandle
GetEnvironmentStringsW
GetCommandLineW
GetCurrentThreadId
GetCurrentProcessId
LoadLibraryW
DebugBreak
GetProcAddress
SetUnhandledExceptionFilter
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
lstrlenW
OutputDebugStringA
LoadLibraryA
FreeLibrary
LocalAlloc
GetSystemTimeAsFileTime
GetTickCount
QueryPerformanceCounter
IsDebuggerPresent
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
InterlockedCompareExchange
Sleep
InterlockedExchange
RaiseException
msvcp80.dll
msvcr80.dll
shlwapi.dll

PathRemoveFileSpecW
PathFindExtensionW
PathFindFileNameW