File details
File name: armsvc.exe
Name: Adobe Acrobat Update Service
Description: Adobe Acrobat Update Service
Version: 1, 7, 0, 0
Size: 63.66 KB
Original file name: armsvc.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 9/20/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0008481312%
Privileged CPU:
0.0001125770%

User CPU:
0.00073555419482%

Privileged CPU time: 12014.48 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
52,672,491
CPU cycle count /min: 47,830
 | Memory utilization averages |
Committed memory:
40.97 MB
Peak committed memory: 43.12 MB
Paged memory:
1.19 MB
Peak paged memory: 1.27 MB
Paged system memory:
73.95 KB
Non-paged system memory: 6.52 KB
Working set memory:
1.96 MB
Peak working set memory: 3.91 MB
Min working set memory: 1.78 MB
Private memory:
1.19 MB
Page faults:
2,292
Page faults /min: 2
 | Process I/O averages |
Total read operations:
9
Total read transfer: 33 Bytes
Total other operations:
216
Other operations /min: 1
Total other transfer: 4.47 KB
Other Transfer /min: 4 Bytes
Resources
Handle count average: 82
Thread count average: 4
Thread resource averages
Total CPU: 0.000246550199%
Privileged CPU: 0.000104815668%
User CPU: 0.000141734531%
CPU Cycle count /sec: 4,459
Module memory size: 64 KB
sechost.dll

Total CPU: 0.000205627157%
Privileged CPU: 0.000080636830%
User CPU: 0.000124990327%
CPU Cycle count /sec: 742
Module memory size: 100 KB
wow64.dll

Total CPU: 0.000022524174%
Privileged CPU: 0.000022524174%
User CPU: 0.000000000000%
CPU Cycle count /sec: 53
Module memory size: 252 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
Service details
Name: Adobe Acrobat Update Service
Service name: AdobeARMservice
Service type:
Win32OwnProcess
Description: “Adobe Acrobat Updater keeps your Adobe software up to date.”
Image hashes
MD5: b1ea9681502ee57f87db71d726288a5b
SHA-1: 285a7dc6b1e5ca4c40b94d8f0af102928ca1d201
SHA-256: d17bd2cfae72e92c77d183331d5cba0fea893bf54875920870e271940f40a8bb
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

OpenSCManagerW
RegisterEventSourceW
CloseServiceHandle
DeleteService
StartServiceCtrlDispatcherW
OpenServiceW
RegCreateKeyExW
RegQueryValueExW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegSetValueExW
RegCloseKey
RegEnumKeyExW
ControlService
ReportEventW
RegisterServiceCtrlHandlerW
RegOpenKeyExW
SetServiceStatus
RegDeleteValueW
RegDeleteKeyW
DeregisterEventSource
CreateServiceW
crypt32.dll

CryptDecodeObject
CryptQueryObject
CertGetNameStringW
CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CryptMsgGetParam
CryptMsgClose
kernel32.dll

UnmapViewOfFile
FormatMessageW
GetLocalTime
CreateFileMappingW
OpenFileMappingW
GetVolumeInformationW
GetTickCount
QueryPerformanceCounter
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
MapViewOfFile
LocalFree
CloseHandle
GetCurrentThreadId
DeleteCriticalSection
lstrcmpiW
LocalAlloc
FindClose
GetProcAddress
GetLastError
RaiseException
lstrlenW
MultiByteToWideChar
lstrcmpW
GetModuleFileNameW
GetFileAttributesW
SizeofResource
InitializeCriticalSection
GetModuleHandleW
InterlockedDecrement
InterlockedIncrement
LoadLibraryExW
TerminateProcess
GetStartupInfoW
GetSystemTimeAsFileTime
Sleep
InterlockedExchange
GetCurrentProcessId
lstrcmpA
FindFirstFileW
FindResourceW
FreeLibrary
LoadResource
InterlockedCompareExchange
msvcr90.dll
ole32.dll

CoRevokeClassObject
CoTaskMemAlloc
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoTaskMemRealloc
CoRegisterClassObject
StringFromGUID2
CoInitialize
shell32.dll

ShellExecuteExW
SHGetFolderPathW
user32.dll

DispatchMessageW
PostThreadMessageW
LoadStringW
CharNextW
GetMessageW
wintrust.dll
