File details
File name: dfdwiz.exe
Name: Windows Disk Diagnostic User Resolver
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 67 KB
Original file name: DFDWiz.exe.mui
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0130141207%
Privileged CPU:
0.0083389271%

User CPU:
0.00467519361172%

Privileged CPU time: 4742.43 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,837,742,527
 | Memory utilization averages |
Committed memory:
129.45 MB
Peak committed memory: 225.63 MB
Paged memory:
8.66 MB
Peak paged memory: 13.02 MB
Paged system memory:
235.84 KB
Non-paged system memory: 10.47 KB
Working set memory:
520 KB
Peak working set memory: 24.71 MB
Min working set memory: 200 KB
Private memory:
8.66 MB
Page faults:
14,285
Page faults /min: 0
 | Process I/O averages |
Total read operations:
250
Total read transfer: 260.08 KB
Total write operations:
3
Total write transfer: 304 Bytes
Total other operations:
8,238
Total other transfer: 102.51 KB
 | GUI Object Averages |
GDI objects:
86
Peak GDI objects: 256
USER objects:
20
Peak USER objects: 148
Resources
Handle count average: 306
Thread count average: 4
Thread resource averages
Total CPU: 0.110091426816%
Privileged CPU: 0.052773985553%
User CPU: 0.057317441263%
CPU Cycle count /sec: 2,153,683
Module memory size: 80 KB
shlwapi.dll

Total CPU: 0.009159535578%
Privileged CPU: 0.005343062421%
User CPU: 0.003816473158%
CPU Cycle count /sec: 149,393
Module memory size: 348 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\system32\DFDWiz.exe
Scheduled tasks startup details
Name: \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
Scheduled task details
Name: Microsoft-Windows-DiskDiagnosticResolver
Command: \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
Image hashes
MD5: 0facc053baff107027cbd1f48885fd4a
SHA-1: 5c302518efc58ae706d052f4f860893439551419
SHA-256: 867b8cbe2831f1782e1a77a6b5c71bdbcaee69e363d15691df3f9006abbd2f99
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

TraceMessage
OpenProcessToken
RegEnumKeyExW
EventWrite
RegDeleteKeyW
RegCloseKey
RegQueryInfoKeyW
RegOpenKeyExW
ConvertStringSecurityDescriptorToSecurityDescriptorW
AdjustTokenPrivileges
LookupPrivilegeValueW
FreeSid
CheckTokenMembership
AllocateAndInitializeSid
InitiateShutdownW
RegQueryValueExW
RegSetValueExW
RegCreateKeyExW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
EventUnregister
EventRegister
RegEnumValueW
gdi32.dll

DeleteObject
SetAbortProc
SetMapMode
GetDeviceCaps
CreateFontIndirectW
SelectObject
StartDocW
StartPage
EndPage
EndDoc
AbortDoc
DeleteDC
kernel32.dll

GlobalFree
MulDiv
HeapFree
HeapAlloc
WriteFile
CreateFileW
GetCurrentProcess
GetCurrentThreadId
CreateMutexW
CreateEventW
GetVersionExW
FormatMessageW
GetProcessHeap
RegisterApplicationRestart
HeapSetInformation
GetSystemTime
SystemTimeToFileTime
CloseHandle
LoadLibraryA
OutputDebugStringA
GetModuleFileNameW
SetLastError
GetLastError
GetVersion
GetFileAttributesW
GetProcAddress
GetModuleHandleW
LoadLibraryW
GetModuleHandleA
OpenMutexW
InterlockedExchange
Sleep
InterlockedCompareExchange
GetStartupInfoA
FindFirstVolumeW
FindNextVolumeW
FindVolumeClose
GetVolumePathNamesForVolumeNameW
DeviceIoControl
UnhandledExceptionFilter
TerminateProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
SetUnhandledExceptionFilter
LocalFree
msvcrt.dll
ntdll.dll

WinSqmAddToStream
WinSqmSetDWORD
WinSqmEndSession
NtQuerySystemTime
WinSqmStartSession
ole32.dll

CoInitializeEx
CoCreateInstance
CoInitialize
CoUninitialize
CoCreateGuid
StringFromGUID2
setupapi.dll

SetupDiDestroyDeviceInfoList
SetupDiGetDeviceInterfaceDetailW
SetupDiEnumDeviceInterfaces
SetupDiGetDeviceRegistryPropertyW
SetupDiGetClassDevsW
user32.dll

DialogBoxParamW
EndDialog
DefWindowProcW
SetWindowLongW
DestroyWindow
SetDlgItemTextW
LoadStringW
MessageBoxW
SetCursor
SendMessageW
DrawTextW
EnumThreadWindows
GetWindowLongW
SetWindowPos
LoadIconW
CreateWindowExW
MsgWaitForMultipleObjects
DispatchMessageW
PeekMessageW
LoadCursorW
PostMessageW
GetParent
ShowWindow
GetDlgItem
IsDialogMessageW
SetFocus
EnableWindow
CreateDialogParamW
TranslateMessage
userenv.dll
