File details
File name: armsvc.exe
Name: Adobe Acrobat Update Service
Description: Adobe Acrobat Update Service
Version: 1, 7, 2, 0
Size: 63.66 KB
Original file name: armsvc.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 9/20/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0025508114%
Privileged CPU:
0.0001198812%

User CPU:
0.00243093021310%

Privileged CPU time: 407624.58 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
117,391,765
CPU cycle count /min: 396,167
 | Memory utilization averages |
Committed memory:
39.65 MB
Peak committed memory: 42.19 MB
Paged memory:
1.28 MB
Peak paged memory: 1.45 MB
Paged system memory:
70.89 KB
Non-paged system memory: 5.54 KB
Working set memory:
3.54 MB
Peak working set memory: 4.41 MB
Min working set memory: 2.83 MB
Private memory:
1.28 MB
Page faults:
1,767
Page faults /min: 13
 | Process I/O averages |
Total read operations:
7
Read operations /min: 1
Total read transfer: 64 Bytes
Read transfer /min: 0 Bytes
Total write operations:
2
Write operations /min: 1
Total write transfer: 28 Bytes
Write transfer /min: 0 Bytes
Total other operations:
188
Other operations /min: 2
Total other transfer: 3.82 KB
Other Transfer /min: 6 Bytes
Resources
Handle count average: 74
Thread count average: 4
Thread resource averages
Total CPU: 0.000867759506%
Privileged CPU: 0.000420954241%
User CPU: 0.000446805265%
CPU Cycle count /sec: 14,896
Module memory size: 64 KB
sechost.dll

Total CPU: 0.000319398570%
Privileged CPU: 0.000319398570%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,850
Module memory size: 208 KB
ntdll.dll

Total CPU: 0.000005719803%
Privileged CPU: 0.000005719803%
User CPU: 0.000000000000%
CPU Cycle count /sec: 87
Module memory size: 1.66 MB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
Service details
Name: Adobe Acrobat Update Service
Service name: AdobeARMservice
Service type:
Win32OwnProcess
Description: “Adobe Acrobat Updater keeps your Adobe software up to date.”
Image hashes
MD5: 3927397ac60d943daf8808affed582b7
SHA-1: d95d0163cb309ee15a36ecfe5cb0680d01993b5c
SHA-256: 2688254085c219e8ca9c5494abdad8fae52533cef7fa3c152715e0b78d591bcf
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

OpenSCManagerW
RegisterEventSourceW
CloseServiceHandle
DeleteService
StartServiceCtrlDispatcherW
OpenServiceW
RegCreateKeyExW
RegQueryValueExW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegSetValueExW
RegCloseKey
RegEnumKeyExW
ControlService
ReportEventW
RegisterServiceCtrlHandlerW
RegOpenKeyExW
SetServiceStatus
RegDeleteValueW
RegDeleteKeyW
DeregisterEventSource
CreateServiceW
crypt32.dll

CryptDecodeObject
CryptQueryObject
CertGetNameStringW
CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CryptMsgGetParam
CryptMsgClose
kernel32.dll

UnmapViewOfFile
FormatMessageW
GetLocalTime
CreateFileMappingW
OpenFileMappingW
GetVolumeInformationW
GetTickCount
QueryPerformanceCounter
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
MapViewOfFile
LocalFree
CloseHandle
GetCurrentThreadId
DeleteCriticalSection
lstrcmpiW
LocalAlloc
FindClose
GetProcAddress
GetLastError
RaiseException
lstrlenW
MultiByteToWideChar
lstrcmpW
GetModuleFileNameW
GetFileAttributesW
SizeofResource
InitializeCriticalSection
GetModuleHandleW
InterlockedDecrement
InterlockedIncrement
LoadLibraryExW
TerminateProcess
GetStartupInfoW
GetSystemTimeAsFileTime
Sleep
InterlockedExchange
GetCurrentProcessId
lstrcmpA
FindFirstFileW
FindResourceW
FreeLibrary
LoadResource
InterlockedCompareExchange
msvcr90.dll
ole32.dll

CoRevokeClassObject
CoTaskMemAlloc
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoTaskMemRealloc
CoRegisterClassObject
StringFromGUID2
CoInitialize
shell32.dll

ShellExecuteExW
SHGetFolderPathW
user32.dll

DispatchMessageW
PostThreadMessageW
LoadStringW
CharNextW
GetMessageW
wintrust.dll
