Bonjour Service Removal


Recommended Posts

Hello,

I've suffered a few nasty experiences when trying to remove the Bonjour Service which is installed by Adobe/Apple products. Unlike a lot of services, the Bonjour Service has many nasty tentacles buried into critical system/registry settings and removing it without following the below instructions can do a few things like:

1. Disabling your network connection fatally (can only be resolved with a WinSock fix and only under certain circumstances)

2. Prevent the start-up of many important Windows Services like Event Viewer or System Event Notification. This has a drastic impact on your start-up/shut-down times.

Basically, removing the Bonjour Service can be an utter nightmare and the below instructions are the only ones that work 100% for me.

To remove the Bonjour Service:

  • Stop Bonjour Service by opening a command prompt (remember to open the command prompt with Administrator privileges in Vista) and type:
    sc stop ?bonjour service?
  • Once that is done, in the same command prompt typsc delete ?bonjour service?e?
  • Now we need to disable the Bonjour socket driver.
  • Start regedit.exe (with Administrator privileges in Vista) and go to tHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004ze (please note: the final digit in this key may vary depending on your circumstances - look through all the entries under Catalog_Entries - the key you're dealing with shoulLibraryPath = C:\Program Files\Bonjour\mdnsNSP.dll)P.dll)l)
  • Within that key find the entry:
    Enabled=REG_DWORD:00000001 - change it from 1 to 0.
  • Exit out of the command prompt and reboot your PC.
  • Once you have logged back in, delete the C:\Program Files\Bonjour (with the files mDNSResponder.exe and mdnsNSP.dll).

There you have it - these instructions will work for Windows XP and Vista.

Link to comment
https://www.neowin.net/forum/topic/632296-bonjour-service-removal/
Share on other sites

What exactly does the bonjour service do? And since you're removing it I'm assuming that it is not necessary in order for Adobe/Apple software to run correctly?
Adobe newest Creative Suite 3 installs Apple?s Bonjour service even if you don?t install Version Cue. Its main goal is to provide zero-configuration connectivity between Version Cue server and the suite?s applications.

When installed by Creative Suite 3 applications, the name used by Bonjour for Windows in the services control panel is:

##Id_String2.6844F930_1628_4223_B5CC_5BB94B879762##

http://www.ajuaonline.com/2007/10/02/how-t...onjour-service/

i recently installed adobe dreamweaver cs3 and found this was installed too. apparantly all cs3 products install this without asking, whether u need/want it or not. after reading a bit i found some interesting discussion & the source of the removal script here

http://blogs.adobe.com/jnack/2007/01/cs3_doesnt_inst.html

i guess the thing even talks to 2o7.net (a data collector) thru a deceptive IP looking site name 192.168.112.2o7.net.

i dont use cue servers, so i removed it. here's the script if u dont want to wander the net looking - save as a .bat file

echo Bounjour service killer...(cmd-bat file)

"%ProgramFiles%\Bonjour\mDNSResponder.exe" -remove
sc stop "Bonjour Service"
sc delete "Bonjour Service"
sc stop "B"
sc delete "B"

regsvr32 /u/s "%ProgramFiles%\Bonjour\mdnsNSP.dll"

reg delete "HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" /va /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" /va /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\864614E012A08774EB1646AA5AEB0193" /va /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\413EF6387A735094090FFA2EF513C53A" /va /f
reg delete "HKLM\SYSTEM\ControlSet001\Services\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\Eventlog\Application\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "D:\\Program Files\\Bonjour\\mDNSResponder.exe" /f
reg delete "HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "D:\\Program Files\\Bonjour\\mDNSResponder.exe" /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "D:\\Program Files\\Bonjour\\mDNSResponder.exe" /f

ren "%ProgramFiles%\Bonjour\mdnsNSP.dll" "%ProgramFiles%\Bonjour\virus.vir"
del /q/f "%ProgramFiles%\Bonjour\*.*"
rd /q "%ProgramFiles%\Bonjour"

echo ...
echo please, reboot your computer and 
echo then you can delete the folder:
echo "%ProgramFiles%\Bonjour"
pause

i recently installed adobe dreamweaver cs3 and found this was installed too. apparantly all cs3 products install this without asking, whether u need/want it or not. after reading a bit i found some interesting discussion & the source of the removal script here

http://blogs.adobe.com/jnack/2007/01/cs3_doesnt_inst.html

i guess the thing even talks to 2o7.net (a data collector) thru a deceptive IP looking site name 192.168.112.2o7.net.

i dont use cue servers, so i removed it. here's the script if u dont want to wander the net looking - save as a .bat file

echo Bounjour service killer...(cmd-bat file)

"%ProgramFiles%\Bonjour\mDNSResponder.exe" -remove
sc stop "Bonjour Service"
sc delete "Bonjour Service"
sc stop "B"
sc delete "B"

regsvr32 /u/s "%ProgramFiles%\Bonjour\mdnsNSP.dll"

reg delete "HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" /va /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" /va /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\864614E012A08774EB1646AA5AEB0193" /va /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\413EF6387A735094090FFA2EF513C53A" /va /f
reg delete "HKLM\SYSTEM\ControlSet001\Services\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\Eventlog\Application\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Bonjour Service" /va /f
reg delete "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "D:\\Program Files\\Bonjour\\mDNSResponder.exe" /f
reg delete "HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "D:\\Program Files\\Bonjour\\mDNSResponder.exe" /f
reg delete "HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "D:\\Program Files\\Bonjour\\mDNSResponder.exe" /f

ren "%ProgramFiles%\Bonjour\mdnsNSP.dll" "%ProgramFiles%\Bonjour\virus.vir"
del /q/f "%ProgramFiles%\Bonjour\*.*"
rd /q "%ProgramFiles%\Bonjour"

echo ...
echo please, reboot your computer and 
echo then you can delete the folder:
echo "%ProgramFiles%\Bonjour"
pause

That guide relies on the Name Catalog in your registry being 4. As posters above have said, theirs has been 7.

  • 1 month later...

I actually removed the whole entry at first which was for me Catalog_Entries\000000000005.

I rebooted and I was like WTF, I had no internet, no sound, no visual styles. I go back and there's Num_Catalog_Entries which I reduced by one at NameSpace_Catalog5

fiew! :cool:

  • 3 weeks later...
I actually removed the whole entry at first which was for me Catalog_Entries\000000000005.

I rebooted and I was like WTF, I had no internet, no sound, no visual styles. I go back and there's Num_Catalog_Entries which I reduced by one at NameSpace_Catalog5

fiew! :cool:

I have the same problems and somewhat did the same thing. I didn't realize this was a part of adobe photoshop cs3 and thought it was some leftover from apple. I searched regedit and deleted all bonjour references without realizing how effed up things were going to get. Complacency meant no registry backup...

So I am curious, how did you resolve your issue?

  • 2 weeks later...
Did you ever try just preventing the service from starting in the first place, in the Services.msc control panel? It gets installed with iTunes now, and I just disable it.

Same here, just disabled the services so it wouldn't start up anymore. But I do thank the OP, cause it helped me remove it completely, thanks! :)

Odd.

I've always went to Add/Remove Programs, and I've always had successful uninstalls.

Yea, I know. It gets install by default with itunes but I just uninstall from there, just like Mobile support. Bonjour is not in services .msc any more.

Surprised people are having problems.

I wish Apple would stop stuffing so much extra crap and services with each itunes release. Programs that aren't antiviruses which add new processes can feck off. It's so pointless.

  • 2 weeks later...

I don't think it's the apple flavor, rather the photoshop cs3 one. With the apple one, I was able to add/remove like anything else... and perhaps if I'd installed photoshop and then did the add/remove, maybe there wouldn't have been an issue. Instead, I see bonjour running knowing full well I had uninstalled that sucker some time ago and so went to the registry to force the issue. Major screwup on my part, especially with no registry backup. Removing all bonjour entries in the registry killed my internet, sound and desktop effects. And it killed the internet hard... after many hours I came upon a winsockfix utility that saved my hide... yeesh. Not even a repair install fixed things before that. And that was an ugly repair install with no internet and it kept asking for drivers...

Anyhow, tread lightly with this photoshop cs3 bonjour... indeed, the tentacles run deep.

With behavior such as this, it is broken. Developers writing software this nasty should be taken out and shot. And I'm saying this as a developer.

Indeed. A proper installer/setup will ask for what the user needs and install accordingly. I guess that's too complicated for the average OSX user, seeing how many of them use Apple because they fled away from Windows.

Indeed. A proper installer/setup will ask for what the user needs and install accordingly. I guess that's too complicated for the average OSX user, seeing how many of them use Apple because they fled away from Windows.

:blink:

Yes that is why OSX users fled windows.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • NASA: This asteroid may not kill us but it probably won't be far off either by Sayan Sen Image by Zelch Csaba via Pexels New observations by NASA's James Webb Space Telescope have eliminated the last remaining impact threat posed by asteroid 2024 YR4, ruling out the possibility that the near-Earth object could strike the Moon in December 2032. NASA said observations collected by Webb on February 18 and 26, 2026, enabled scientists to refine the asteroid's orbit enough to "rule out a chance of lunar impact on Dec. 22, 2032." Instead, asteroid 2024 YR4 is now expected to pass the Moon at a distance of about 13,200 miles (21,200 km). The agency stressed that the update "reflects improved precision in our understanding of where the asteroid is expected to be in 2032 rather than a shift in its orbital path." The announcement closes a remarkable chapter in planetary defence that began in late 2024, when the approximately 60-metre-wide asteroid briefly became the most closely watched near-Earth object in the world. Discovered on December 27, 2024, by the ATLAS telescope in Chile, 2024 YR4 initially appeared to have a small chance of colliding with Earth on December 22, 2032. As astronomers gathered more observations, the impact probability briefly climbed to around 3%—the highest ever recorded for an asteroid of its size—before steadily falling as its orbit became better understood. By early 2025, international observations had ruled out any significant risk to Earth. However, astronomers were left with another possibility: a roughly 4% chance that the asteroid could instead strike the Moon. "The probability that asteroid 2024 YR4 will strike the Moon on 22 December 2032 is now approximately 4%," the European Space Agency (ESA) had said last year, noting that "there is a 96% chance that the asteroid will not impact the Moon." ESA said such an impact, while unlikely, would have presented an extraordinary scientific opportunity. "It is a very rare event for an asteroid this large to impact the Moon – and it is rarer still that we know about it in advance. The impact would likely be visible from Earth, and so scientists will be very excited by the prospect of observing and analysing it," said Richard Moissl, Head of ESA's Planetary Defence Office. "It would certainly leave a new crater on the surface. However, we wouldn't be able to accurately predict in advance how much material would be thrown into space, or whether any would reach Earth," he added. The asteroid also exposed an important blind spot in planetary defence. Because 2024 YR4 approached Earth from the direction of the Sun, it remained hidden from ground-based telescopes until after its closest approach. "We looked into how Neomir would have performed in this situation, and the simulations surprised even us," Moissl said. "Neomir would have detected asteroid 2024 YR4 about a month earlier than ground-based telescopes did. This would have given astronomers more time to study the asteroid's trajectory and allowed them to much sooner rule out any chance of Earth impact in 2032." He added, "As an infrared telescope, like Webb, Neomir would have also immediately given us a much better estimate for the asteroid's size, which is very important for assessing the significance of the hazard." The latest NASA observations underscore the value of space-based infrared telescopes in tracking faint asteroids. According to NASA, Webb made "among the faintest ever observations of an asteroid," extending the object's observational record by nearly eight months at a time when it had become too faint for other telescopes. That additional data allowed scientists to eliminate the remaining uncertainty surrounding its 2032 flyby. Although asteroid 2024 YR4 is now confirmed to pose no threat to either Earth or the Moon, scientists say its discovery remains one of the most significant real-world tests of the international planetary defence system, demonstrating how continued observations can rapidly transform an object once considered hazardous into one whose future path is known with high confidence. Source: NASA, ESA This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
    • Yup. Google is just scraping the entire internet for their own ad profits without sharing revenue with the sources. It's obviously stealing, but since these sites depend upon Google's search scraps to survive... As for me, I just stopped using Google for anything except Reddit searches. If Reddit's own search wasn't complete crapola, I'd never use Google search again.
    • I had a feeling this was coming. Picked up my first Mac ever last Saturday. Glad I did.
    • In a major surprise there is actually some good deals for the first time in years. At least for me.
  • Recent Achievements

    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
    • Apprentice
      daryld went up a rank
      Apprentice
    • Contributor
      Carltonbar went up a rank
      Contributor
    • One Month Later
      The_Focal_Point earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      419
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      130
    4. 4
      Xenon
      69
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!