File details
File name: mDNSResponder.exe
Name: Bonjour
Description: Bonjour Service
Version: 3,0,0,10
Size: 381.35 KB
Original file name: mDNSResponder.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 6/27/2011
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0023134665%
Privileged CPU:
0.0015546118%

User CPU:
0.00075885467348%

Privileged CPU time: 1346830.2 ms
Privileged CPU time /min: 791 ms
CPU cycle count:
274,563,051
CPU cycle count /min: 15,845,644
Context switches /sec:
47
 | Memory utilization averages |
Committed memory:
31.41 MB
Peak committed memory: 33.03 MB
Paged memory:
1.88 MB
Peak paged memory: 1.92 MB
Paged system memory:
53.24 KB
Non-paged system memory: 7.42 KB
Working set memory:
2.77 MB
Peak working set memory: 4.47 MB
Min working set memory: 2.33 MB
Private memory:
1.88 MB
Page faults:
17,067
Page faults /min: 7
 | Process I/O averages |
Total read operations:
49
Read operations /min: 1
Total read transfer: 15.36 KB
Read transfer /min: 11 Bytes
Total write operations:
43
Write operations /min: 1
Total write transfer: 1.83 KB
Write transfer /min: 2 Bytes
Total other operations:
838,047
Other operations /min: 171
Total other transfer: 14.38 MB
Other Transfer /min: 4.21 KB
 | GUI Object Averages |
GDI objects:
4
USER objects:
2
Resources
Handle count average: 118
Thread count average: 3
Thread resource averages
sechost.dll

Total CPU: 0.023305332851%
Privileged CPU: 0.017357211875%
User CPU: 0.005948120976%
CPU Cycle count /sec: 486,163
Module memory size: 100 KB
advapi32.dll

Total CPU: 0.007344275183%
Privileged CPU: 0.005137405303%
User CPU: 0.002206869881%
CPU Cycle count /sec: 157,057
Module memory size: 792 KB
advapi32.dll

Total CPU: 0.005236815780%
Privileged CPU: 0.004101044316%
User CPU: 0.001135771464%
CPU Cycle count /sec: 101,779
Module memory size: 792 KB
advapi32.dll

Total CPU: 0.005065188288%
Privileged CPU: 0.004149143598%
User CPU: 0.000916044690%
CPU Cycle count /sec: 123,536
Module memory size: 764 KB
advapi32.dll

Total CPU: 0.004537052349%
Privileged CPU: 0.003658913185%
User CPU: 0.000878139164%
Context switches /sec: 2
Module memory size: 620 KB
advapi32.dll

Total CPU: 0.002277413491%
Privileged CPU: 0.001397452596%
User CPU: 0.000879960895%
Context switches /sec: 8
Module memory size: 620 KB
sechost.dll

Total CPU: 0.001798992932%
Privileged CPU: 0.001316073466%
User CPU: 0.000482919466%
CPU Cycle count /sec: 31,936
Module memory size: 208 KB
advapi32.dll

Total CPU: 0.001437209055%
Privileged CPU: 0.001221627697%
User CPU: 0.000215581358%
Module memory size: 620 KB
ntdll.dll

Total CPU: 0.001006326180%
Privileged CPU: 0.001006326180%
User CPU: 0.000000000000%
CPU Cycle count /sec: 967
Module memory size: 1.23 MB
advapi32.dll

Total CPU: 0.000967477992%
Privileged CPU: 0.000793953914%
User CPU: 0.000173524079%
Module memory size: 688 KB
Total CPU: 0.000546946099%
Privileged CPU: 0.000434941758%
User CPU: 0.000112004341%
CPU Cycle count /sec: 7,566
Module memory size: 556 KB
advapi32.dll

Total CPU: 0.000364675191%
Privileged CPU: 0.000182337595%
User CPU: 0.000182337595%
Module memory size: 620 KB
rpcrt4.dll

Total CPU: 0.000188039953%
Privileged CPU: 0.000188039953%
User CPU: 0.000000000000%
CPU Cycle count /sec: 200
Module memory size: 780 KB
ntdll.dll

Total CPU: 0.000121671776%
Privileged CPU: 0.000121671776%
User CPU: 0.000000000000%
CPU Cycle count /sec: 241
Module memory size: 1.4 MB
ntdll.dll

Total CPU: 0.000010995272%
Privileged CPU: 0.000010995272%
User CPU: 0.000000000000%
CPU Cycle count /sec: 884
Module memory size: 1.23 MB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Child Processes
Process Command
"C:\Program Files\Bonjour\mDNSResponder.exe"
Service details
Name: Служба Bonjour
Service name: Bonjour Service
Service type:
Win32OwnProcess
Description: “Позволяет аппаратным устройствам и программным службам выполнять автоматическую самоконфигурацию в сети и оповещать о своем присутствии.”
Network connectivity
UDP: LISTENING on port 5353
TCP: localhost on port 5354
UDP: LISTENING on port 5353
TCP: localhost on port 5354
UDP: LISTENING on port 5353
TCP: localhost on port 5354
UDP: LISTENING on port 5353
UDP: LISTENING on port 5353
TCP: localhost on port 5354
UDP: LISTENING on port 5353
TCP: localhost on port 5354
TCP: localhost on port 5354
Windows Firewall allowed program: Yes
Image hashes
MD5: db5bea73edaf19ac68b2c0fad0f92b1a
SHA-1: 74bb0197763e386036751bf30c5bbf4c389fa24e
SHA-256: 10f21999ff6b1d410ebf280f7f27deaca5289739cf12f4293b614b8fc6c88dcc
PE image details
CLR assembly: Yes
CLR NGENed: No
Subsystem: Windows Console
Langauge*: Microsoft Visual C# / Basic .NET
File packed: No
Import Table
advapi32.dll

LsaNtStatusToWinError
RegisterServiceCtrlHandlerExW
DeregisterEventSource
StartServiceCtrlDispatcherW
SetServiceStatus
QueryServiceStatus
ControlService
DeleteService
CreateServiceW
StartServiceW
RegNotifyChangeKeyValue
RegisterEventSourceW
ReportEventA
LockServiceDatabase
OpenServiceW
ChangeServiceConfig2W
UnlockServiceDatabase
OpenSCManagerW
EnumServicesStatusW
CloseServiceHandle
LsaOpenPolicy
LsaRetrievePrivateData
LsaFreeMemory
LsaClose
RegOpenKeyExW
RegCreateKeyA
RegQueryInfoKeyW
RegEnumKeyExA
RegOpenKeyExA
RegQueryValueExA
RegQueryValueExW
RegCreateKeyW
RegSetValueExW
RegCloseKey
iphlpapi.dll

GetIpForwardTable
GetAdaptersInfo
GetNetworkParams
GetPerAdapterInfo
GetBestInterface
CreateIpForwardEntry
DeleteIpForwardEntry
GetIpAddrTable
kernel32.dll

GetLastError
GetComputerNameExA
WideCharToMultiByte
SetEvent
WaitForMultipleObjects
CreateEventW
GetProcAddress
LoadLibraryW
SetWaitableTimer
CloseHandle
DeviceIoControl
CreateFileA
GetComputerNameExW
GetTickCount
GlobalFree
GlobalAlloc
Sleep
WaitForSingleObject
GetVersionExW
CreateWaitableTimerW
OpenThread
GetCurrentThreadId
ResetEvent
TerminateThread
MultiByteToWideChar
GetModuleFileNameW
CancelWaitableTimer
GetSystemPowerStatus
GetFullPathNameW
SetConsoleCtrlHandler
GetModuleHandleW
HeapSetInformation
TlsFree
TlsSetValue
FormatMessageA
SetLastError
ExitProcess
WriteFile
GetStdHandle
FreeLibrary
HeapCreate
GetConsoleCP
GetConsoleMode
FlushFileBuffers
InitializeCriticalSectionAndSpinCount
CreateFileW
DeleteCriticalSection
SetHandleCount
GetFileType
GetStartupInfoW
LCMapStringW
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetCurrentProcessId
GetStringTypeW
WriteConsoleW
SetFilePointer
SetStdHandle
RtlUnwind
HeapSize
QueueUserAPC
TlsGetValue
TlsAlloc
IsValidCodePage
GetOEMCP
GetACP
InterlockedDecrement
InterlockedIncrement
GetCPInfo
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
InterlockedExchange
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
HeapReAlloc
ExitThread
CreateThread
ResumeThread
GetCommandLineW
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
IsProcessorFeaturePresent
SleepEx
WaitForMultipleObjectsEx
LCMapStringA
GetCommandLineA
FreeEnvironmentStringsA
GetEnvironmentStrings
GetStringTypeA
GetLocaleInfoA
InitializeCriticalSection
LoadLibraryA
WriteConsoleA
GetConsoleOutputCP
GetStartupInfoA
GetModuleFileNameA
GetVersionExA
GetProcessHeap
GetModuleHandleA
VirtualFree
VirtualAlloc
HeapDestroy
netapi32.dll

NetGetJoinInformation
NetShareEnum
NetApiBufferFree
ole32.dll

CoInitializeEx
CoUninitialize
CoCreateInstance
powrprof.dll

user32.dll

ws2_32.dll

WSAStringToAddressA
WSACreateEvent
WSAEventSelect
WSACloseEvent
WSAEnumNetworkEvents
WSAAddressToStringA
WSARecvFrom
WSAIoctl
WSARecv