File details
File name: msdtc.exe
Name: Microsoft Distributed Transaction Coordinator Service
Description: Microsoft® Windows® Operating System
Version: 2001.12.8530.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 138.5 KB
Original file name: MSDTC.EXE.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0007232109%
Privileged CPU:
0.0006100501%

User CPU:
0.00011316082523%

Privileged CPU time: 6767.74 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
387,665,302
CPU cycle count /min: 1,800,074
 | Memory utilization averages |
Committed memory:
61.7 MB
Peak committed memory: 63.27 MB
Paged memory:
3.76 MB
Peak paged memory: 4.07 MB
Paged system memory:
67.88 KB
Non-paged system memory: 17.84 KB
Working set memory:
5.72 MB
Peak working set memory: 8.41 MB
Min working set memory: 5.61 MB
Private memory:
3.76 MB
Page faults:
2,807
Page faults /min: 19
 | Process I/O averages |
Total read operations:
1
Read operations /min: 1
Total read transfer: 54.99 KB
Read transfer /min: 68 Bytes
Total write operations:
341
Write operations /min: 1
Total write transfer: 1.84 MB
Write transfer /min: 4.06 KB
Total other operations:
978
Other operations /min: 3
Total other transfer: 56.3 KB
Other Transfer /min: 56 Bytes
Resources
Handle count average: 149
Thread count average: 12
Thread resource averages
msdtctm.dll

Total CPU: 0.001318530106%
Privileged CPU: 0.001013640187%
User CPU: 0.000304889919%
CPU Cycle count /sec: 21,408
Module memory size: 1.52 MB
Total CPU: 0.000887253933%
Privileged CPU: 0.000887253933%
User CPU: 0.000000000000%
CPU Cycle count /sec: 9,381
Module memory size: 124 KB
Total CPU: 0.000388484123%
Privileged CPU: 0.000329187404%
User CPU: 0.000059296719%
CPU Cycle count /sec: 7,729
Module memory size: 160 KB
msdtctm.dll

Total CPU: 0.000102622196%
Privileged CPU: 0.000102622196%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,359
Module memory size: 1.52 MB
msdtcprx.dll

Total CPU: 0.000070614485%
Privileged CPU: 0.000070614485%
User CPU: 0.000000000000%
CPU Cycle count /sec: 544
Module memory size: 752 KB
Process details
Runs as (owner): Network Service
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Process
Process Command
C:\Windows\System32\msdtc.exe
Service details
Name: MSDTC
Image hashes
MD5: de0ece52236cfa3ed2dbfc03f28253a8
SHA-1: 84bbd2495c1809fcd19b535d41114e4fb101466c
SHA-256: 2fbbec4cacb5161f68d7c2935852a5888945ca0f107cf8a1c01f4528ce407de3
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.06093
File packed: No
Import Table
advapi32.dll

RegSetValueExW
RegQueryValueExW
OpenProcessToken
GetTokenInformation
RegisterEventSourceW
ReportEventW
DeregisterEventSource
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
RegOpenKeyExW
api-ms-win-core-com-l1-1-0.dll

CoInitializeEx
CoUninitialize
CoCreateInstance
StringFromGUID2
CoGetObjectContext
api-ms-win-core-debug-l1-1-1.dll

IsDebuggerPresent
DebugBreak
OutputDebugStringW
api-ms-win-core-delayload-l1-1-1.dll

DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll

GetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll

DeleteFileW
SetFileAttributesW
FindNextFileW
GetFullPathNameW
FindFirstFileW
CreateFileW
CreateDirectoryW
FindClose
api-ms-win-core-handle-l1-1-0.dll

api-ms-win-core-heap-obsolete-l1-1-0.dll

api-ms-win-core-interlocked-l1-2-0.dll

InterlockedCompareExchange
InterlockedExchange
api-ms-win-core-libraryloader-l1-1-1.dll

FreeLibrary
LoadStringW
GetModuleFileNameW
LockResource
GetModuleHandleA
FindResourceExW
GetProcAddress
GetModuleHandleW
LoadLibraryExW
LoadResource
api-ms-win-core-localization-l1-2-0.dll

api-ms-win-core-processenvironment-l1-2-0.dll

GetCommandLineW
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll

GetCurrentThread
TlsFree
TlsGetValue
CreateProcessW
TlsAlloc
GetStartupInfoW
TerminateProcess
GetCurrentProcess
GetExitCodeProcess
GetCurrentThreadId
OpenProcessToken
GetThreadContext
GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll

api-ms-win-core-psapi-l1-1-0.dll

QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll

RegSetValueExW
RegQueryValueExA
RegQueryValueExW
RegOpenKeyExA
RegOpenKeyExW
RegCloseKey
api-ms-win-core-synch-l1-2-0.dll

LeaveCriticalSection
CreateEventA
InitializeCriticalSectionAndSpinCount
ResetEvent
WaitForSingleObjectEx
SetEvent
DeleteCriticalSection
EnterCriticalSection
WaitForSingleObject
Sleep
api-ms-win-core-sysinfo-l1-2-0.dll

GetTickCount
GetLocalTime
GetSystemWindowsDirectoryA
GetSystemTimeAsFileTime
api-ms-win-core-version-l1-1-0.dll

api-ms-win-security-base-l1-2-0.dll

kernel32.dll

GetCommandLineW
UnregisterWait
TlsFree
TlsAlloc
TlsGetValue
LocalAlloc
LocalFree
IsDebuggerPresent
GetCurrentThread
GetThreadContext
DebugBreak
ExpandEnvironmentStringsW
CreateDirectoryW
CreateProcessW
GetExitCodeProcess
FindFirstFileW
FindNextFileW
SetFileAttributesW
DeleteFileW
FindClose
GetModuleHandleW
FindResourceW
LoadResource
LockResource
FormatMessageW
GetModuleFileNameW
LoadLibraryExW
DeleteCriticalSection
WaitForSingleObject
LeaveCriticalSection
EnterCriticalSection
InterlockedExchange
Sleep
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
CreateEventA
CloseHandle
WaitForSingleObjectEx
SetEvent
ResetEvent
FreeLibrary
CreateFileW
GetProcAddress
LoadLibraryA
GetFullPathNameW
GetLastError
QueryFullProcessImageNameW
GetLocalTime
QueueUserWorkItem
OutputDebugStringW
GetSystemWindowsDirectoryA
InitializeCriticalSectionAndSpinCount
UnregisterWaitEx
msvcrt.dll
ntdll.dll

RtlCaptureContext
RtlReportException
ole32.dll

CoGetObjectContext
StringFromGUID2
CoInitializeEx
CoCreateInstance
CoUninitialize
user32.dll

EndDialog
SetDlgItemTextW
CloseWindowStation
CloseDesktop
GetProcessWindowStation
GetThreadDesktop
OpenWindowStationW
DialogBoxParamW
OpenDesktopW
SetThreadDesktop
GetDesktopWindow
GetWindowRect
GetClientRect
MapWindowPoints
SetWindowPos
LoadStringW
SetProcessWindowStation
version.dll
