File details
File name: armsvc.exe
Name: Adobe Acrobat Update Service
Description: Adobe Acrobat Update Service
Version: 1, 7, 4, 0
Size: 64.1 KB
Original file name: armsvc.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 9/20/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0005324183%
Privileged CPU:
0.0000385618%

User CPU:
0.00049385641849%

Privileged CPU time: 52012.22 ms
Privileged CPU time /min: 77 ms
CPU cycle count:
42,867,196
CPU cycle count /min: 254,347
 | Memory utilization averages |
Committed memory:
40.09 MB
Peak committed memory: 42.23 MB
Paged memory:
1.26 MB
Peak paged memory: 1.35 MB
Paged system memory:
70.24 KB
Non-paged system memory: 5.82 KB
Working set memory:
2.83 MB
Peak working set memory: 4.36 MB
Min working set memory: 2.12 MB
Private memory:
1.26 MB
Page faults:
1,905
Page faults /min: 3
 | Process I/O averages |
Total read operations:
7
Read operations /min: 1
Total read transfer: 12.99 KB
Read transfer /min: 10 Bytes
Total write operations:
2
Write operations /min: 1
Total write transfer: 28 Bytes
Write transfer /min: 0 Bytes
Total other operations:
146
Other operations /min: 1
Total other transfer: 1.55 KB
Other Transfer /min: 2 Bytes
Resources
Handle count average: 75
Thread count average: 4
Thread resource averages
sechost.dll

Total CPU: 0.000196646722%
Privileged CPU: 0.000196646722%
User CPU: 0.000000000000%
CPU Cycle count /sec: 696
Module memory size: 100 KB
Total CPU: 0.000056275622%
Privileged CPU: 0.000034989428%
User CPU: 0.000021286194%
CPU Cycle count /sec: 847
Module memory size: 64 KB
advapi32.dll

Total CPU: 0.000013573006%
Privileged CPU: 0.000013573006%
User CPU: 0.000000000000%
CPU Cycle count /sec: 28
Module memory size: 792 KB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Process Commands
"C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
Service details
Name: Adobe Acrobat Update Service
Service name: AdobeARMservice
Service type:
Win32OwnProcess
Description: “Adobe Acrobat Updater keeps your Adobe software up to date.”
Image hashes
MD5: adda5e1951b90d3d23c56d3cf0622adc
SHA-1: e2d0df9db9bedfb5866efb3f9aa1c09562e51730
SHA-256: e85e7bfd29f00ed34bf5be8bd4da93cbb14278e16809bb55406875f0da88551e
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

OpenSCManagerW
RegisterEventSourceW
CloseServiceHandle
DeleteService
StartServiceCtrlDispatcherW
OpenServiceW
RegCreateKeyExW
RegQueryValueExW
RegQueryInfoKeyW
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegSetValueExW
RegCloseKey
RegEnumKeyExW
ControlService
ReportEventW
RegisterServiceCtrlHandlerW
RegOpenKeyExW
SetServiceStatus
RegDeleteValueW
RegDeleteKeyW
DeregisterEventSource
CreateServiceW
crypt32.dll

CryptDecodeObject
CryptQueryObject
CertGetNameStringW
CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CryptMsgGetParam
CryptMsgClose
kernel32.dll

UnmapViewOfFile
FormatMessageW
GetLocalTime
CreateFileMappingW
OpenFileMappingW
GetVolumeInformationW
GetTickCount
QueryPerformanceCounter
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
MapViewOfFile
LocalFree
CloseHandle
GetCurrentThreadId
DeleteCriticalSection
lstrcmpiW
LocalAlloc
FindClose
GetProcAddress
GetLastError
RaiseException
lstrlenW
MultiByteToWideChar
lstrcmpW
GetModuleFileNameW
GetFileAttributesW
SizeofResource
InitializeCriticalSection
GetModuleHandleW
InterlockedDecrement
InterlockedIncrement
LoadLibraryExW
TerminateProcess
GetStartupInfoW
GetSystemTimeAsFileTime
Sleep
InterlockedExchange
GetCurrentProcessId
lstrcmpA
FindFirstFileW
FindResourceW
FreeLibrary
LoadResource
InterlockedCompareExchange
msvcr90.dll
ole32.dll

CoRevokeClassObject
CoTaskMemAlloc
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoTaskMemRealloc
CoRegisterClassObject
StringFromGUID2
CoInitialize
shell32.dll

ShellExecuteExW
SHGetFolderPathW
user32.dll

DispatchMessageW
PostThreadMessageW
LoadStringW
CharNextW
GetMessageW
wintrust.dll
