File details
File name: AppleMobileDeviceService.exe
Description: MobileDeviceService
Version: 17.96.0.8
Product version: 3.3.0.0
Size: 53.89 KB
Original file name: AppleMobileDeviceService.exe
Digital certificate
Certificate authority:
VeriSign
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0020153953%
Privileged CPU:
0.0010991076%

User CPU:
0.00091628773759%

Privileged CPU time: 5777686.31 ms
Privileged CPU time /min: 38 ms
CPU cycle count:
246,498,517
CPU cycle count /min: 41,210,414
Context switches /sec:
6
 | Memory utilization averages |
Committed memory:
88.5 MB
Peak committed memory: 96.12 MB
Paged memory:
4.99 MB
Peak paged memory: 5.28 MB
Paged system memory:
146.03 KB
Non-paged system memory: 19.04 KB
Working set memory:
6.15 MB
Peak working set memory: 11.12 MB
Min working set memory: 5.58 MB
Private memory:
4.99 MB
Page faults:
24,759
Page faults /min: 18
 | Process I/O averages |
Total read operations:
109
Read operations /min: 1
Total read transfer: 974.69 KB
Read transfer /min: 442 Bytes
Total write operations:
1,313
Write operations /min: 1
Total write transfer: 186.78 KB
Write transfer /min: 40 Bytes
Total other operations:
8,126,878
Other operations /min: 22,507
Total other transfer: 46.11 MB
Other Transfer /min: 1.05 MB
 | GUI Object Averages |
GDI objects:
4
USER objects:
2
Resources
Handle count average: 228
Thread count average: 11
Thread resource averages
Total CPU: 0.019932397311%
Privileged CPU: 0.009242756492%
User CPU: 0.010689640818%
CPU Cycle count /sec: 723,230
Context switches /sec: 1
Module memory size: 48 KB
Total CPU: 0.005134087493%
Privileged CPU: 0.002321309066%
User CPU: 0.002812778427%
CPU Cycle count /sec: 92,844
Context switches /sec: 1
Module memory size: 220 KB
wow64.dll

Total CPU: 0.004860742492%
Privileged CPU: 0.001269923714%
User CPU: 0.003590818778%
CPU Cycle count /sec: 105,507
Context switches /sec: 1
Module memory size: 252 KB
msvcr80.dll

Total CPU: 0.002536331812%
Privileged CPU: 0.001416546632%
User CPU: 0.001119785180%
CPU Cycle count /sec: 96,142
Context switches /sec: 1
Module memory size: 620 KB
msvcr80.dll

Total CPU: 0.000393091313%
Privileged CPU: 0.000169928930%
User CPU: 0.000223162383%
CPU Cycle count /sec: 37,610
Module memory size: 620 KB
ntdll.dll

Total CPU: 0.000164259107%
Privileged CPU: 0.000000000000%
User CPU: 0.000164259107%
CPU Cycle count /sec: 188
Module memory size: 1.23 MB
wow64.dll

Total CPU: 0.000015443259%
Privileged CPU: 0.000005718927%
User CPU: 0.000009724332%
CPU Cycle count /sec: 46
Module memory size: 276 KB
wow64win.dll

Total CPU: 0.000005573088%
Privileged CPU: 0.000005573088%
User CPU: 0.000000000000%
CPU Cycle count /sec: 50
Module memory size: 360 KB
wow64cpu.dll

Total CPU: 0.000002275229%
Privileged CPU: 0.000002275229%
User CPU: 0.000000000000%
CPU Cycle count /sec: 16
Module memory size: 32 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Child Processes
Process Commands
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Programas\Ficheiros comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
Service details
Name: Apple Mobile Device
Service type:
Win32OwnProcess
Description: “Provides the interface to Apple mobile devices.”
Network connectivity
UDP: LISTENING on port 59827
TCP: localhost on port 27015
UDP: LISTENING on port 61354
TCP: localhost on port 27015
UDP: LISTENING on port 56352
TCP: localhost on port 49156
UDP: LISTENING on port 49153
UDP: LISTENING on port 50785
TCP: localhost on port 49186
UDP: LISTENING on port 52813
TCP: localhost on port 49155
UDP: LISTENING on port 58010
Image hashes
MD5: a5299d04ed225d64cf07a568a3e1bf8c
SHA-1: c85c9638702b5f6642ef7031b245e86925d47a5f
SHA-256: 6f7e73893127badc8c9815e9bcc0eb5f6584e254d0d09a0b6a680704c71e0a90
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++ 8.0
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegCreateKeyW
RegOpenKeyExW
RegQueryValueExW
kernel32.dll

GetLastError
GetModuleFileNameW
GetEnvironmentVariableW
SetDllDirectoryW
GetFileAttributesW
WideCharToMultiByte
Process32Next
Process32First
FreeEnvironmentStringsW
CloseHandle
GetEnvironmentStringsW
GetCommandLineW
GetCurrentThreadId
GetCurrentProcessId
LoadLibraryW
DebugBreak
GetProcAddress
SetUnhandledExceptionFilter
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
lstrlenW
OutputDebugStringA
LoadLibraryA
FreeLibrary
LocalAlloc
GetSystemTimeAsFileTime
GetTickCount
QueryPerformanceCounter
IsDebuggerPresent
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
InterlockedCompareExchange
Sleep
InterlockedExchange
RaiseException
msvcp80.dll
msvcr80.dll
shlwapi.dll

PathRemoveFileSpecW
PathFindExtensionW
PathFindFileNameW