PE Compile Time

2002-07-11 07:39:26

PE Imphash

da610ca700d3fcd07221889fd01b5be9

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000a000 0x00009800 6.61574232071
.rdata 0x0000b000 0x00002000 0x00001200 5.16609076535
.data 0x0000d000 0x00003000 0x00001200 3.92108672765
.rsrc 0x00010000 0x00001000 0x00000c00 0.528995785846
.aspack 0x00011000 0x00002000 0x00001a00 5.72171694451
.adata 0x00013000 0x00001000 0x00001000 4.29351729868

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x000109f0 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000120c8 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Device independent bitmap graphic, 48 x 96 x 4, image size 1152
RT_GROUP_CURSOR 0x00010b28 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x000120b4 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library WS2_32.dll:
0x40b1b4 WSAStartup
0x40b1b8 getsockname
0x40b1bc ntohs
0x40b1c0 listen
0x40b1c4 closesocket
0x40b1c8 WSACleanup
0x40b1cc accept
0x40b1d0 select
0x40b1d4 recvfrom
0x40b1d8 inet_ntoa
0x40b1dc sendto
0x40b1e0 htons
0x40b1e4 socket
0x40b1e8 bind
0x40b1ec recv
0x40b1f0 inet_addr
0x40b1f4 gethostname
0x40b1f8 gethostbyname
Library KERNEL32.dll:
0x40b020 WaitForSingleObject
0x40b024 HeapAlloc
0x40b028 SetErrorMode
0x40b02c GetProcAddress
0x40b034 LoadLibraryA
0x40b038 CompareStringA
0x40b03c FlushFileBuffers
0x40b040 GetStringTypeW
0x40b044 GetStringTypeA
0x40b048 SetStdHandle
0x40b04c CreateFileA
0x40b050 GetModuleFileNameA
0x40b054 ReadFile
0x40b058 SetFilePointer
0x40b05c GetFileSize
0x40b060 LocalFree
0x40b064 CloseHandle
0x40b068 WriteFile
0x40b06c LocalAlloc
0x40b074 GetTempFileNameA
0x40b078 Process32Next
0x40b07c TerminateProcess
0x40b080 OpenProcess
0x40b084 Process32First
0x40b08c GetCurrentProcess
0x40b090 GetVersionExA
0x40b094 DeleteFileA
0x40b098 WinExec
0x40b09c UnmapViewOfFile
0x40b0a0 MapViewOfFile
0x40b0a4 CreateFileMappingA
0x40b0a8 LockResource
0x40b0ac SizeofResource
0x40b0b0 LoadResource
0x40b0b4 FindResourceA
0x40b0b8 FreeLibrary
0x40b0bc EnumResourceNamesA
0x40b0c0 FlushViewOfFile
0x40b0c4 LoadLibraryExA
0x40b0c8 SetFileTime
0x40b0cc Sleep
0x40b0d0 CopyFileA
0x40b0d4 GetFileTime
0x40b0d8 SetFileAttributesA
0x40b0dc GetFileAttributesA
0x40b0e0 GetComputerNameA
0x40b0e4 CreateThread
0x40b0e8 TerminateThread
0x40b0ec GetOEMCP
0x40b0f0 LCMapStringA
0x40b0f4 FindClose
0x40b0f8 FindNextFileA
0x40b0fc FindFirstFileA
0x40b100 HeapDestroy
0x40b104 CreateProcessA
0x40b108 GetModuleHandleA
0x40b10c GetCurrentProcessId
0x40b110 CompareStringW
0x40b118 GetSystemTime
0x40b11c GetLocalTime
0x40b120 GetStartupInfoA
0x40b124 GetCommandLineA
0x40b128 GetVersion
0x40b12c ExitProcess
0x40b130 HeapFree
0x40b134 WideCharToMultiByte
0x40b138 MultiByteToWideChar
0x40b140 LCMapStringW
0x40b148 HeapCreate
0x40b14c VirtualFree
0x40b150 VirtualAlloc
0x40b154 HeapReAlloc
0x40b160 GetFileType
0x40b168 SetHandleCount
0x40b16c GetStdHandle
0x40b170 GetCPInfo
0x40b174 RtlUnwind
0x40b178 GetLastError
0x40b17c GetACP
Library USER32.dll:
0x40b184 ExitWindowsEx
0x40b188 GetDesktopWindow
0x40b18c GetWindow
0x40b190 SendMessageA
0x40b194 GetWindowTextA
0x40b19c IsWindow
Library ADVAPI32.dll:
0x40b000 OpenProcessToken
0x40b00c RegOpenKeyA
0x40b010 RegCreateKeyA
0x40b014 RegSetValueExA
0x40b018 RegCloseKey
Library VERSION.dll:
0x40b1a8 GetFileVersionInfoA
0x40b1ac VerQueryValueA

!This program cannot be run in DOS mode.
.rdata
.aspack
.adata
_^][YY
X[_^]Y
5VVVh
D$$tN3
PVVVVVV
t5Vj h
uRFGHt
"WWSh,
HHtpHHtl
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
t.;t$$t(
VC20XC00U
QSUVW3
>:uNFV
>:u#FV
VWuBh|
+ttHHtd
t/WWUPj
QQSVW3
`h````
ppxxxx
(null)
GAIsProcessorFeaturePresent
KERNEL32
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
1#QNAN
1#SNAN
WS2_32.dll
CreateFileA
GetModuleFileNameA
ReadFile
SetFilePointer
GetFileSize
LocalFree
CloseHandle
WriteFile
LocalAlloc
GetWindowsDirectoryA
GetTempFileNameA
Process32Next
TerminateProcess
OpenProcess
Process32First
CreateToolhelp32Snapshot
GetCurrentProcess
GetVersionExA
DeleteFileA
WinExec
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
LockResource
SizeofResource
LoadResource
FindResourceA
FreeLibrary
EnumResourceNamesA
FlushViewOfFile
LoadLibraryExA
SetFileTime
CopyFileA
GetFileTime
SetFileAttributesA
GetFileAttributesA
GetComputerNameA
CreateThread
TerminateThread
GetProcAddress
LoadLibraryA
FindClose
FindNextFileA
FindFirstFileA
WaitForSingleObject
CreateProcessA
GetModuleHandleA
GetCurrentProcessId
SetErrorMode
HeapAlloc
GetTimeZoneInformation
GetSystemTime
GetLocalTime
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
HeapFree
WideCharToMultiByte
MultiByteToWideChar
LCMapStringA
LCMapStringW
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
RtlUnwind
GetLastError
GetCPInfo
GetACP
GetOEMCP
SetStdHandle
GetStringTypeA
GetStringTypeW
FlushFileBuffers
CompareStringA
CompareStringW
SetEnvironmentVariableA
KERNEL32.dll
ExitWindowsEx
GetDesktopWindow
GetWindow
SendMessageA
GetWindowTextA
GetWindowThreadProcessId
IsWindow
USER32.dll
RegCloseKey
RegSetValueExA
RegCreateKeyA
RegOpenKeyA
AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
ADVAPI32.dll
VerQueryValueA
GetFileVersionInfoA
GetFileVersionInfoSizeA
VERSION.dll
Software\Microsoft\Windows\CurrentVersion\RunServices
MSWDM.EXE
Software\Microsoft\Windows\CurrentVersion\Run
\mswdm.exe
device
SeShutdownPrivilege
notepad
255.0.0.0
255.255.0.0
255.255.255.0
\system\kernel32.exe
IEXPLORE.EXE
NETEYES.EXE
MSDEV.EXE
EXPLORER.EXE
XXXXXXXXXXXXXXXXXXXXXXXX.EXE
IPARMOR
TROJAN
255.255.255.255
NORTON
FIREWALL
\welcome.exe
MICROSOFT
\StringFileInfo\%04x%04x\CompanyName
\VarFileInfo\Translation
GetModuleFileNameExA
EnumProcessModules
psapi.dll
c:\mswdm.pro
sys.try
\*.exe
NtQuerySystemInformation
RegisterServiceProcess
KERNEL32.DLL
VirtualAlloc
VirtualFree
kernel32.dll
ExitProcess
user32.dll
MessageBoxA
wsprintfA
LOADER ERROR
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
(08@P`p
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
ws2_32.dll
user32.dll
advapi32.dll
version.dll
ExitWindowsEx
OpenProcessToken
GetFileVersionInfoSizeA
P@@@9y
ffFedK
FLn~f~VddfH
lvVGK{
@tf~nwflfFGc
sFn~gn
FFFvvn
f_````d
ddddd``_f
ffd``d
"JF$""#Fe
}YHHHHHHHHHHHHHH
!This program cannot be run in DOS mode.
`.data

 !!!!""""####$$$$%%%%&&&&''''(((())))****++++,,,,----....////0000111122223333444455556666777788889999::::;;;;<<<=
 !!!!""""####$$$$%%%%&&&&''''(((())))****++++,,,,----....////0000111122223333444455556666777788889999::::;;;;<<<<==>>???
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !!!!""""####$$$$%%%%&&&&''''(((())))*****++++,,,,----....////0000111122223333444455556666777788889999::::;;;;<<<<====>>>>?
!)1:BJRZcks{
!%)-16:>BFJNRVZ^cgkosw{
0d1112131415161718191:1;1<1=1>1?1@1A1B1C1D1E1F1G1H1I1J1K1L1M1N1
O1P1Q1R1S1T1
U1V1W1X1Y1Z1
[1\1]1^1_1`1
a1b1c1
UUUUUUU
TUUUUU+
)1$N*)Q&`[U
eEf=ghfijklimnf=o
f=pqrst
KLMNOP
UVWXYZ[
"#$%&'(
)*+,-.
012345678
CCDCEF
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
H SVWH
L$ SUVWH
x UAVAWH
L!|$HH
D$@D9|$@t
x UAVAWH
fB9<Bu
@SVWATAUAVAWH
\$@!\$HH
`A_A^A]A\_^[
\$ UVWATAUAVAWH
L$8HcY
A_A^A]A\_^]
D$@f90t
H!\$hD
H!D$`D
D$pt1H
H!\$0H!\$(
H!\$@H!\$8
!\$(H!\$
L$PH;L$Xs&H
UWATAVAWH
L$PH;L$Xs"H
D$@H9|$XH
D$@H9|$XL
A_A^A\_]
UATAUAVAWH
fD9<Au
A_A^A]A\]
` UAVAWH
fD94Au
H;D$pr9H
6L)|$hH
t:L97t
t]L97t
t:L97t
UWATAVAWH
fD9<Au
fD9<Yu
t<L9?t
A_A^A\_]
x UAVAWH
fA9<Fu
@SUVWAVH
L90u"H
0A^_^][
t$ WAVAWH
A_A^_
@SUVWAVH
A^_^][
|$ UATAUAVAWH
A_A^A]A\]
tbL9Chu
t$ UWAVH
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
fD9<Zu
0A_A^_^]
l$ VWAVH
\$ UVWATAUAVAWH
0A_A^A]A\_^]
WAVAWH
A_A^_
UVWAVAWH
A_A^_^]
\$ UVWH
t$ WAVAWH
0A_A^_
H;A r5H
\$ UVWAVAWH
0A_A^_^]
<[tJ<{t/H
\$ UVWATAUAVAWH
PA_A^A]A\_^]
UATAUAVAWH
u*<5w&I
u*<5w&I
A_A^A]A\]
H;\$ u
|$RBt)
|$RBt)
UATAUAVAWH
A_A^A]A\]
|$0!|$<!|$8!|$ D
@SVWATAUAVAWH
fF9,Au
pA_A^A]A\_^[
f9t$0t{3
u=9t$,v7L
x UATAUAVAWH
A_A^A]A\]
@SUVWAUAVAWH
PA_A^A]_^][
l$ VWAVH
UVWAVAWH
pA_A^_^]
l$ VWAVH
UVWAVAWH
`A_A^_^]
l$ VWAVH
;^Xu&H
SVWAVH
8A^_^[
WAVAWH
u/HcH<H
bad allocation
Unknown exception
bad array new length
string too long
bad cast
ChromeReprompt.txt
QueryFullProcessImageNameW
bookmark_bar
children
Adobe Acrobat
https://acrobat.adobe.com/?x_api_client_id=bookmark&x_api_client_location=Reader
https://acrobat.adobe.com/?x_api_client_id=bookmark&x_api_client_location=Acrobat
13346689990798272
date_added
date_last_used
d4d3e7d2-cdf9-4163-bb68-73a465fc09dc
profile
last_used
extensions
settings
efaidnbmnnnibpcajpcglclefindmkaj
invalid string position
Text only contains white space(s)
Expect either an object or array at root
Nothing should follow the root object or array.
Name of an object member must be a string
There must be a colon after the name of object member
Must be a comma or '}' after an object member
Must be a comma or ']' after an array element.
Missing the second \u in surrogate pair
The second \u in surrogate pair is invalid
Unknown escape character
lacks ending quotation before the end of string
Incorrect unescaped character in string
Incorrect hex digit after \u escape
Invalid value
Expect a value here.
Number too big to store in double
At least one digit in fraction part
At least one digit in exponent
uuuuuuuubtnufruuuuuuuuuuuuuuuuuu
0123456789ABCDEF
^'e&G0
:-6aU,$
6aKSO1
9Y>)F$
s\ax}?
tC7Ddx
%k0V(
xg^Jp5|
{zel#|67
invalid stoi argument
stoi argument out of range
cextwrite
C:\Git\servicesupdater\x64\Release\ChromeReprompt.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
.rsrc$01
.rsrc$02
URLDownloadToFileW
urlmon.dll
WTSEnumerateSessionsW
WTSFreeMemory
WTSAPI32.dll
msi.dll
SizeofResource
HeapFree
GetFullPathNameW
GetCurrentProcess
GetTempPathW
InitializeCriticalSectionEx
CreateFileW
GetFileAttributesW
K32GetProcessImageFileNameW
OpenProcess
HeapSize
CreateToolhelp32Snapshot
MultiByteToWideChar
ProcessIdToSessionId
GetTempPathA
GetLastError
Process32NextW
K32GetModuleBaseNameW
LockResource
Process32FirstW
HeapReAlloc
CloseHandle
FindResourceExW
LoadResource
FindResourceW
HeapAlloc
K32EnumProcesses
HeapDestroy
GetWindowsDirectoryW
GetProcAddress
LocalFree
DeleteCriticalSection
GetCurrentProcessId
GetProcessHeap
GetModuleHandleW
CopyFileW
lstrcpyW
K32EnumProcessModules
lstrlenW
GetModuleFileNameW
lstrcmpW
KERNEL32.dll
GetTokenInformation
LookupAccountSidW
DuplicateTokenEx
ConvertSidToStringSidW
CreateProcessAsUserW
RegOpenKeyExW
OpenProcessToken
RegSetValueExW
CreateProcessWithTokenW
RegCreateKeyExW
AllocateAndInitializeSid
EqualSid
RegCloseKey
RegQueryValueExW
RegDeleteValueW
RegCreateKeyW
ADVAPI32.dll
SHGetKnownFolderPath
SHGetSpecialFolderPathW
SHELL32.dll
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?_Xout_of_range@std@@YAXPEBD@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
??Bid@locale@std@@QEAA_KXZ
?_Xinvalid_argument@std@@YAXPEBD@Z
MSVCP140.dll
__CxxFrameHandler4
__C_specific_handler
__std_exception_destroy
longjmp
__std_exception_copy
wcsstr
wcschr
memmove
memset
__current_exception
__current_exception_context
_CxxThrowException
VCRUNTIME140_1.dll
VCRUNTIME140.dll
wmemcpy_s
calloc
_recalloc
_wcsicmp
fflush
_wfopen_s
fclose
realloc
__stdio_common_vfwprintf
_itow_s
wcscpy_s
wcscat_s
__stdio_common_vsprintf_s
_invalid_parameter_noinfo
_unlock_file
_lock_file
fwrite
_errno
fopen_s
fgetpos
setvbuf
_wcslwr_s
_time64
ungetc
strcat_s
fsetpos
_fseeki64
_invalid_parameter_noinfo_noreturn
_get_stream_buffer_pointers
malloc
wcstol
_stricmp
wcstok
_callnewh
terminate
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
__setusermatherr
_get_initial_narrow_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-filesystem-l1-1-0.dll
api-ms-win-crt-time-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
IsDebuggerPresent
OutputDebugStringW
EnterCriticalSection
LeaveCriticalSection
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
memcmp
memcpy
__intrinsic_setjmp
wcscmp
.?AVbad_alloc@std@@
.?AVCAtlException@ATL@@
.?AVbad_cast@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AUIAtlStringMgr@ATL@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AVCAtlStringMgr@ATL@@
.?AVCWin32Heap@ATL@@
.?AUIAtlMemMgr@ATL@@
.?AVRegUtil@@
installVersion
"24.2.1.0"
installType
"install"
offlineSupportDisable
trueu}
ANALYTICS_OPT_IN_ADMIN
"true"
isSharepointFeatureEnabled
false-
installSource
"sideload"
"[[\"clientId\",\"dc-prod-chrome-viewer\"],[\"floodgateUri\",\"https://p13n.adobe.io/fg/api\"],[\"env\",\"prod\"],[\"accessToken\",null],[\"useAnonymousUUID\",true],[\"anonUserUUID\",null],[\"featureGroups\",null],[\"featuresMeta\",{}],[\"lastCallTime\",0],[\"callInProgress\",false],[\"callPromise\",null],[\"ttl\",1800000],[\"ffResponse\",null]]"
_t"[[\"tabs\",{}],[\"version\",1],[\"NMHConnStatus\",true],[\"activeTab\",null],[\"isAllowedLocalFileAccess\",false]]"
"[[\"$GET_headers\",{\"Accept\":\"application/vnd.adobe.dex+json;version=1\",\"Authorization\":null,\"x-api-client-id\":\"api_browser_ext\"}],[\"$POST_headers\",{\"Accept\":\"application/vnd.adobe.dex+json;version=1\",\"Content-Type\":\"application/vnd.adobe.dex+json;version=1;charset=utf-8\",\"Authorization\":null,\"x-api-client-id\":\"api_browser_ext\"}],[\"settings\",{\"cpdf_api\":null,\"files_host\":null,\"files_api\":null,\"files_upload\":null,\"files_root\":null,\"fillsign_api\":null,\"auth_token\":null,\"ims_host\":null,\"cloud_host\":\"https://cloud.acrobat.com/\",\"redirect_uri\":\"https://createpdf.acrobat.com/static/js/aicuc/cpdf-template/sign_in_complete.html\",\"cpdf_host\":\"https://createpdf.acrobat.com/\",\"frictionless_uri\":\"https://acrobat.adobe.com/proxy/hosted-extension/iframe-index.html\",\"env\":\"prod\",\"viewer_ims_client_id\":\"dc-prod-chrome-viewer\",\"acrobat_viewer_uri\":\"https://acrobat.adobe.com/proxy/chrome-viewer/index.html\",\"imsURL\":\"https://ims-na1.adobelogin.com\",\"f
viewer-enabled-source
"ownership-install"
pdfViewer
"true"
"false"
persist-menu-closed
sessionId&"11d997c1-2629-459e-bac3-715ed39ec0c1"
sessionStarted
locale
"en-US"e
cdnUrl:"https://acrobat.adobe.com/proxy/chrome-viewer/index.html"
isDeskTop
"prod"
viewerImsClientId
"dc-prod-chrome-viewer"b[
imsContextId,"v:2,s,9122f250-90cf-11ed-9fe5-b3719c660a78"
viewerImsClientIdSocial
"dc-prod-chrome-viewer-social"
imsURL "https://ims-na1.adobelogin.com"_
imsLibUrl6"https://auth.services.adobe.com/imslib/imslib.min.js"E
dcApiUri
"https://dc-api.adobe.io"%
isAcrobat
"auto"l
anonUserUUIDA"prod_dc-prod-chrome-viewer_8af73d51-6aea-4f85-8d8b-7165569d9979")
extUserState
"ru"n{
filesData
{"filePath":"[[\"https://acrobat.adobe.com/dc-chrome-extension/mv/en_US/Acrobat-for-Chrome.pdf\",{\"filename\":\"Acrobat-for-Chrome.pdf\",\"lastVisited\":1710384413847}]]","isSyncedWithHistory":true}s;yf
loadedTabsInfo
{"tabsInfo":[{"active":true,"audible":false,"autoDiscardable":true,"discarded":false,"favIconUrl":"","groupId":-1,"height":816,"highlighted":true,"id":84895990,"incognito":false,"index":2,"lastAccessed":1.710384413564742e+12,"mutedInfo":{"muted":false},"pinned":false,"selected":true,"status":"loading","title":"Acrobat-for-Chrome.pdf","url":"chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://acrobat.adobe.com/dc-chrome-extension/mv/en_US/Acrobat-for-Chrome.pdf","width":1038,"windowId":84895987}]}]
netAccAdT
1.710384713915e+12
netAcc
true6k
adobeInternal
"true"h
isReadAloudEnable
isSaveLocationPrefEnabled
splunkLoggingEnable
enableNewExtensionMenu
trueza
enableExtMenuDarkMode
false?
enableCDNVersioning
falseB
falsev;
enableCSRF
falseX
offlineSupportDisable
false`
saveLocation
"ask"'
?"[[\"clientId\",\"dc-prod-chrome-viewer\"],[\"floodgateUri\",\"https://p13n.adobe.io/fg/api\"],[\"env\",\"prod\"],[\"accessToken\",null],[\"useAnonymousUUID\",true],[\"anonUserUUID\",\"prod_dc-prod-chrome-viewer_8af73d51-6aea-4f85-8d8b-7165569d9979\"],[\"featureGroups\",{\"dc-cv-sign-in-experiments\":[],\"dc-cv-fte-experiments\":[\"dc-cv-fte-helpx-staticpdf\"],\"dc-cv-adobe-internal\":[\"dc-cv-read-aloud-internal\",\"dc-cv-inline-edit-internal\",\"dc-cv-upsell-discover-panel-internal\",\"dc-cv-edge-upsell-internal\",\"dc-cv-adobe-yolo-internal\",\"dc-cv-enable-embed-viewer-internal\",\"dc-cv-show-digital-signature-internal\",\"dc-cv-document-properties-internal\",\"dc-cv-image-print-internal\"],\"dc-cv-anon-upsell-experiments\":[\"dc-cv-upsell-anon\"],\"||features||\":[\"fs2-choose-color\",\"dc-cv-uninstall-feedback-internal\",\"fs2-acroform-sign\",\"fs2-high-contrast\",\"dc-cv-show-get-desktop\",\"fs2-rotate-dialog\",\"dc-cv-inline-fill-sign-internal\",\"dc-cv-upsell-discover-panel\",\"dc-cv-enable-edit-con
"[[\"tabs\",{\"84895990\":{\"tabId\":84895990,\"loaded\":true,\"iconPromises\":[],\"iconSetInProgress\":false}}],[\"version\",1],[\"NMHConnStatus\",true],[\"activeTab\",84895990],[\"isAllowedLocalFileAccess\",false]]"`j.
adobeYoloEnable
sessionStarted
viewerStorage
{"theme":"light"}r
viewerStorageAsync
viewerStorage
{"theme":"light","usage":"1"}
filesData
{"filePath":"[[\"https://acrobat.adobe.com/dc-chrome-extension/mv/en_US/Acrobat-for-Chrome.pdf\",{\"filename\":\"Acrobat-for-Chrome.pdf\",\"lastVisited\":1710384413847,\"x\":0,\"y\":0,\"rotationAngle\":0,\"pageNumber\":1,\"zoomLevel\":54.678398058252434}]]","isSyncedWithHistory":true}
viewerStorage0{"dmCmShown":"true","theme":"light","usage":"1"}
viewerStoragev{"dmCmShown":"true","renderPrompt":"{\"value\":\"guided-tour\",\"expiry\":1710470820295}","theme":"light","usage":"1"}
viewerStorage
{"dmCmShown":"true","editGuidedTourShown":"true","renderPrompt":"{\"value\":\"guided-tour\",\"expiry\":1710470820295}","theme":"light","usage":"1"}
viewerStorage
{"dmCmShown":"true","fillSignTourShown":"true","renderPrompt":"{\"value\":\"guided-tour\",\"expiry\":1710470820295}","theme":"light","usage":"1"}
viewerStorage
{"dmCmShown":"true","fillSignTourShown":"true","guidedTourShown":"true","renderPrompt":"{\"value\":\"guided-tour\",\"expiry\":1710470820295}","theme":"light","usage":"1"}7
loadedTabsInfo
appLocale
"en-US"
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
231103000000Z
251104235959Z0
Delaware1
Private Organization1
27481291
San Jose1
Adobe Inc.1
Acrobat DC1
Adobe Inc.0
http://www.digicert.com/CPS0
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
+j'W)P
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
20250310121929Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
240926000000Z
351125235959Z0B1
DigiCert1 0
DigiCert Timestamp 20240
ymIXa+
z9XxGT
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
MzE @t
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
250310121929Z0+
/1(0&0$0"
(null)
((((( H
%s : fatal error -:
tinycrt
exceeded maximum command-line args %d
COPYMAR
@CBitmapSurface::EnableDefaultMappings
%1 is an unimplemented method
CBitmapSurface::SetMapping
@imageinfo.xml
imageinfo.mii
@donotdither
measure
numimages
imagelist
accessimage
bottom
ValidateMarchiveChecksums
ForceReadOnlyMarchive
@MSN Archive Stability
MSN Archive: Checksum Mismatch in file %s: %s
@CMarsProtStreamWrapper::SetSize
CMarsProtStreamWrapper::Commit
CMarsProtStreamWrapper::Revert
CMarsProtStreamWrapper::CopyTo
CMarsProtStreamWrapper::LockRegion
CMarsProtStreamWrapper::UnlockRegion
CMarsProtStreamWrapper::Clone
System\CurrentControlSet\Control\FontAssoc\Associated Charset
ANSI(00)
High Contrast
Control Panel\Appearance
Current
UseSysColors
{E8055863-4956-4cbf-9CA5-46FF053A904C}
TSAppCompat
System\CurrentControlSet\Control\Terminal Server
MSN6.INI
gopher
mailto
telnet
javascript
vbscript
image/x-png
image/png
image/gif
image/pjpeg
image/jpeg
pressed
ERROR : Unable to initialize critical section in CAtlBaseModule
HKEY_CURRENT_USER
%s -- %s
Kernel32.dll
\explorer.exe
HKEY_USERS\
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Local AppData
explorer.exe
GetUserLocalAppDataFolder : : folderpath via registry :
UserLocalAppDataFolder : : folderpath new2 :
GetUserLocalAppDataFolder : : folderpath old :
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
GetShellProcName:: Failed to copy shell full path to return var
GetShellProcName:: Failed to concat Windows Dir to shell name :
C:\Windows\explorer.exe
GetShellProcName:: Failed to copy hard coded shell value :
http://acroipm2.adobe.com/assets/CEXTW_R/
http://acroipm2.adobe.com/assets/CEXTW/
http://acroipm2.adobe.com/assets/CEXTRP_R/
http://acroipm2.adobe.com/assets/CEXTRP/
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
\Google\Chrome Beta\User Data\
\Google\Chrome\User Data\
Pinging URL
Entering EnableChromeExtension
EnableChromeExtension:: FAILED to get local appdata folder path
Stage1
\Preferences
\Secure Preferences
Stage21
Stage20
Stage31
Stage30
Stage40
Stage41
Stage42
Stage4X
Stage50
Stage51
Stage52
Stage531
Stage530
Stage551
Stage550
Stage561
Stage560
Stage6
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj
https://clients2.google.com/service/update2/crx
update_url
Stage7
\Software\Adobe\Acrobat Reader\DC\AVGeneral
\Software\Adobe\Adobe Acrobat\DC\AVGeneral
bChromeExtnRepromptDone
Step1.txt
AddEntryToChromeBookmark:: FAILED to get local appdata folder path
Step2.txt
\Bookmarks
Step3.txt
Step5.txt
Step2Exit.txt
S1.txt
http://acroipm2.adobe.com/assets/AWBM_R/
http://acroipm2.adobe.com/assets/AWBM/
S2.txt
temp_awbm_copy.txt
S7.txt
S6.txt
S5.txt
S4.txt
S3.txt
Default
GetChromeLastUsedProfilePath:: FAILED to get local appdata folder path
Local State
GetChromeLastUsedProfilePath:: Found last Used Profile =
GetChromeLastUsedProfilePath:: Couldn't find [last_used] in Chrome Prefs
GetChromeLastUsedProfilePath:: Either Doc has parse error or couldn't find [profile] in Chrome Prefs
GetChromeLastUsedProfilePath:: Failed to open file=
GetExtensionStateFromFile:: Using Chrome Pref file:
GetExtensionStateFromFile:: FAILED to find file =
GetExtensionStateFromFile:: Couldn't find [state] in Chrome Prefs
GetExtensionStateFromFile:: Couldn't find [efaidnbmnnnibpcajpcglclefindmkaj] in Chrome Prefs
GetExtensionStateFromFile:: Couldn't find [settings] in Chrome Prefs
GetExtensionStateFromFile:: Doc has parse error or couldn't find [extensions] in Chrome Prefs
\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj
FindAndSetChromeExtensionStatus:: FAILED to get local appdata folder path
FindAndSetChromeExtensionStatus:: Plugin state =
<unknown>
Found Match :
Checking :
HKEY_LOCAL_MACHINE\Software\Adobe\
Acrobat Reader\
Adobe Acrobat\
\WebResource\Experiments
SvcUpdAwBM
SvcCExtWr
SvcCExtRt
\SOFTWARE\Adobe\Adobe ARM\1.0\ARM
\WebResource
irandom
HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown
\SOFTWARE\Adobe\Adobe Acrobat\DC\Workflows\cServices\cServiceConfiguration
bIsEnterpriseUser
HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cServices
bUpdater
bAcroSuppressUpsell
bProtectedMode
\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged
\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
bEnableAV2
bIsAcrobatProUser
bIsAcrobatStdUser
uAdobeSubscriptionStatus
PowerPoint
PDFMaker.OfficeAddin
\SOFTWARE\Microsoft\Office\
\Addins\
LoadBehavior
\Software\Adobe\Adobe Acrobat\DC\PDFMakerExpRdr
bIsSubscribedOrPDFPackUser
{AC76BA86-0000-0000-7760-7E8A45000000}
sInstalledProdCode
-1033-0000-
-1033-FFFF-
iChromeExtnRepromptCount2
iChromeExtnRepromptCount
bChromeExtnRepromptDone2
bChromeExtnRepromptPending2
bChromeExtnRepromptPending
Already tried re-creating the registry for re prompt.
CustomActionInfo: ERROR: [DeleteChromeExtRegForReprompt] : :
pluginstatus is not 0, not continuing
CustomActionInfo: INFO: [DeleteChromeExtRegForReprompt] : :
Step3Exit.txt
chrome.exe
Step4.txt
Step6Exit.txt
Failed to delete chrome ext reg from 32bit HKLM
Found and deleted chrome extension reg in HKLM
Step6.txt
uChromeExtnRepromptTime
Step5U.txt
Step6UExit.txt
Failed to delete chrome ext reg from HKCU
Found and deleted chrome extension reg in HKCU
Step6U.txt
Step4Exit.txt
chrome is not running, not continuing
Step9Exit.txt
chrome is not running, retries exceeded.
chrome is not running, retries exceeded, setting ChromeExtnRepromptPending
CustomActionInfo: ERROR: [CreateChromeExtRegForReprompt] : : CHROMEEXT_REG_STATUS :
Failed to re create chrome ext reg in 32bit HKLM
CustomActionInfo: ERROR: [CreateChromeExtRegForReprompt] : :
Successfully re-created chrome ext reg in HKLM
CustomActionInfo: INFO: [CreateChromeExtRegForReprompt] : :
Failed to re create chrome ext reg in 32bit HKCU
Successfully re-created chrome ext reg in HKCU
CHROMEEXT_REG_STATUS neither 1 nor 2, skipping
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe ARM\Products\{291AA914-A987-4CE9-BD63-AC0A92D435E5}
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe ARM\Products\{291AA914-A987-4CE9-BD63-0C0A92D435E5}
24.005.20399.1
ProductVersion
Version updated
CustomActionInfo: INFO: [UpdateServiceUpdaterVersion] : :
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\WebResource
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\WebResource
iUpdateId
UpdateId updated
CustomActionInfo: INFO: [UpdateUpdateId] : :
iIntervalProcessMAU
bPDFMakerExpRdr
bIsCPDFMakerExpEnabled
VersionString
Launching process in user mode ->
HKEY_CLASSES_ROOT
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
SETTINGS
0Acrobat Update Installe
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
ClamAV Win.Trojan.Iparm-1
CMC Clean
CAT-QuickHeal Trojan.Mauvaise.SL1
ALYac Trojan.GenericKD.66110182
Cylance Unsafe
Zillya Virus.Ipamor.Win32.5
Sangfor Suspicious.Win32.Save.ins
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Clean
K7GW Virus ( 0040f5921 )
K7AntiVirus Virus ( 0040f5921 )
huorong Virus/Ipamor
Baidu Win32.Virus.Ipamor.b
VirIT Win32.Ipamor.F
Paloalto Clean
Symantec W32.HLLP.Ipamor
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Ipamor.G
APEX Malicious
Avast Win32:Ipamor
Cynet Malicious (score: 100)
Kaspersky Trojan-Banker.Win32.Banbra.vwsb
BitDefender Trojan.GenericKD.66110182
NANO-Antivirus Virus.Win32.Ipamor.cxoj
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.66110182
Sophos W32/Ipamor-B
F-Secure Trojan.TR/Agent.arue
DrWeb Trojan.MulDrop26.36640
VIPRE Trojan.GenericKD.66110182
TrendMicro Clean
McAfeeD Real Protect-LS!B12EC2F34F25
Trapmine malicious.high.ml.score
CTX exe.trojan.generic
Emsisoft Trojan.GenericKD.66110182 (B)
Ikarus Virus.Win32.Ipamor
GData Win32.Virus.Ipamor-Main.A
Jiangmin Trojan.Generic.ghobc
Webroot W32.Trojan.Ipamor
Varist W32/Trojan.IYAH-9049
Avira TR/Agent.arue
Antiy-AVL Virus/Win32.Ipamor.g
Kingsoft Clean
Gridinsoft Trojan.Win32.Agent.vb!s1
Xcitium Virus.Win32.Ipamor.G@8j5juk
Arcabit Trojan.Generic.D3F0C2E6
SUPERAntiSpyware Clean
ZoneAlarm W32/Ipamor-B
Microsoft Virus:Win32/Ipamor.A
Google Detected
AhnLab-V3 Win32/Ipamor.D.X1356
Acronis suspicious
VBA32 Virus.Facepalm.231207
TACHYON Worm/W32.Ipamor.Zen.D
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Virus.Win32.Viking.aak
Yandex Trojan.GenAsa!qp+sKG55Fu8
SentinelOne Static AI - Malicious PE
MaxSecure Banker.Banbra.vwsb
Fortinet W32/Ipamor.D
AVG Win32:Ipamor
DeepInstinct MALICIOUS
alibabacloud RiskWare:Win/ASPacked.be49d40e
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Ipamor
C4S ClamAV (Linux) Win.Trojan.Iparm-1
Trellix (Linux) W32/Ipamor
Sophos Anti-Virus (Linux) W32/Ipamor-B
Bitdefender Antivirus (Linux) Trojan.GenericKD.66110182
G Data Antivirus (Windows) Virus: Trojan.GenericKD.66110182 (Engine A), Win32.Virus.Ipamor-Main.A (Engine B)
WithSecure (Linux) Trojan.TR/Agent.arue
ESET Security (Windows) a variant of Win32/Ipamor.G virus
DrWeb Antivirus (Linux) Trojan.MulDrop26.36640
ClamAV (Linux) Win.Trojan.Iparm-1
eScan Antivirus (Linux) Trojan.GenericKD.66110182(DB)
Kaspersky Standard (Windows) Trojan-Banker.Win32.Banbra.vwsb
Emsisoft Commandline Scanner (Windows) Trojan.GenericKD.66110182 (B)
Cuckoo

We're processing your submission... This could take a few seconds.