Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Wellcome. Using Winappdbg version Version 1.5 (beta 4)
- Adobe Reader X 11.0.0
- AcroRd32 Main module found at 009f0000
- Setting breakpoint at 00a10370
- Rule: 0, 16, *.exe
- Rule: 0, 16, *.bat
- Rule: 0, 16, *.cmd
- Rule: 0, 16, *.com
- Rule: 0, 16, *.dll
- Rule: 0, 16, *.cpl
- Rule: 0, 16, *.ocx
- Rule: 0, 16, *.pif
- Rule: 0, 16, *.scr
- Rule: 0, 16, *.scf
- Rule: 0, 1, C:\Program Files\*
- Rule: 0, 1, C:\Program Files
- Rule: 0, 1, C:\Windows\*
- Rule: 0, 1, C:\Windows
- Rule: 0, 1, C:\Program Files\Adobe\Reader 11.0\*
- Rule: 0, 1, C:\Program Files\Adobe\Reader 11.0\
- Rule: 0, 1, C:\Program Files\Adobe\Reader 11.0\Reader\*
- Rule: 0, 1, C:\Program Files\Adobe\Reader 11.0\Reader
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\Privileged\11.0\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\Privileged\11.0
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Microsoft\Crypto\RSA\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Microsoft\Crypto\RSA
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Arcot\Ids\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Arcot\Ids
- Rule: 0, 1, C:\Users\w7\AppData\Local\Microsoft\Outlook\*
- Rule: 0, 1, C:\Users\w7\AppData\Local\Microsoft\Outlook
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Microsoft\Outlook\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Microsoft\Outlook
- Rule: 0, 1, *.dll
- Rule: 0, 1, *.p12
- Rule: 0, 1, *.pfx
- Rule: 0, 1, C:\Users\w7\AppData\Local\Microsoft\Windows\Temporary Internet Files\*
- Rule: 0, 1, C:\Users\w7\AppData\Local\Microsoft\Windows\Temporary Internet Files
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\8.0\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\8.0
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\9.0\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\9.0
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\10.0\*
- Rule: 0, 1, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\10.0
- Rule: 0, 0, C:\Users\w7\AppData\Local\Temp\acrord32_sbx\*
- Rule: 0, 15, *
- Rule: 0, 2, *
- Rule: 0, 0, C:\Users\w7\AppData\LocalLow\Adobe\Acrobat\11.0\*
- Rule: 0, 0, C:\Users\w7\AppData\LocalLow\Adobe\Linguistics\*
- Rule: 0, 0, C:\Users\w7\AppData\LocalLow\Microsoft\IMJP*\*
- Rule: 0, 0, C:\Users\w7\AppData\LocalLow\Microsoft\IME*\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\11.0\*
- Rule: 0, 0, C:\Users\w7\AppData\Local\Adobe\Acrobat\11.0\*
- Rule: 0, 0, C:\Users\w7\AppData\Local\Adobe\Color\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Adobe\Linguistics\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Microsoft\Speech\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Adobe\LogTransport2\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Adobe\Headlights\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Adobe\Flash Player\AssetCache\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Microsoft\IME*\*
- Rule: 0, 0, C:\Users\w7\AppData\Local\Microsoft\IME*\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Microsoft\IMJP*\*
- Rule: 0, 0, C:\Users\w7\AppData\Local\Microsoft\IMJP*\*
- Rule: 0, 0, C:\Users\w7\Documents\ArcotIDs\*
- Rule: 0, 0, C:\Users\w7\AppData\Roaming\Adobe\Acrobat\FeatOut\*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\Privileged*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\11.0\Privileged*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\TrustManager\
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\TrustManager\cTrustedFolders*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\TrustManager\cTrustedSites*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\11.0\TrustManager\
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\11.0\TrustManager\cTrustedFolders*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\11.0\TrustManager\cTrustedSites*
- Rule: 3, 12, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\AVGeneral\cRecentFiles*
- Rule: 3, 12, HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\LangBarAddin*
- Rule: 3, 11, HKEY_CLASSES_ROOT*
- Rule: 3, 11, HKEY_CURRENT_USER*
- Rule: 3, 11, HKEY_LOCAL_MACHINE*
- Rule: 3, 11, HKEY_USERS*
- Rule: 3, 11, HKEY_CURRENT_CONFIG*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\11.0
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\11.0\*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\11.0
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\11.0\*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Adobe ARM\1.0\ARM
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Adobe ARM\1.0\ARM\*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\CommonFiles\Usage\Reader 11
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\CommonFiles\Usage\Reader 11\*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech*
- Rule: 3, 17, HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Adobe\CommonFiles*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Microsoft\IMEJP*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Adobe\Acrobat Distiller*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache*
- Rule: 3, 12, HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes\Installer*
- Rule: 3, 17, HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes*
- Rule: 3, 17, HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\TrustManager\cDefaultLaunchURLPerms*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*IMSC*_S-1-5-21-3838672843-4002566486-4181322922-1001*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Imejp.ConfigrationIO_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\FileView__Satori_PropMgrGlobal_IMJP_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\FileView__Satori_PropMgrGlobal_IME*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\SatoriKnlDict_MemoryDictionary_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\_IME_*_CodeDictionarySharedMemory_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\FileView___IMJP*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\UD_FileMapping_{*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*_IMJP_??_UD_FileMapping_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*_IMJP_?_UD_FileMapping_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*_IMJP_??_UD_ManagementBlock_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*_IMJP_?_UD_ManagementBlock_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*microsoft_imjp*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\?ihs*_S-1-5-21-3838672843-4002566486-4181322922-1001*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\AtlDebugAllocator_FileMappingNameStatic3_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Global\windows_shell_global_counters
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\windows_ie_global_counters
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\MSCTF.Shared.*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Local\UrlZonesSM_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Local\!PrivacIE!SharedMem!Counter
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\MSCTF.MarshalInterface.FileMap.*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\CTF.AsmListCache.FMPDefault*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\C43FCC54-5B86-4525-B9C3-5C382D06C790*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\ASMWIN*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Local\EWH*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\A3D_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Imejp.PredictionPropertyCache_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*microsoft_ime12_imejp_dicts_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*microsoft_imjp12_imjp12*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\*microsoft_imjp12_dicts_imjp*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Global\AcroSharedMemory_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\SandboxProtectedViewSharedSection_*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\Global\FntCache-*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\dllmemfilemap*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\JsMmfAtok*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\_IMJP_*_CodeDictionarySharedMemory*
- Rule: 6, 14, \Sessions\1\BaseNamedObjects\PGPhk*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\UD_Mutex_{*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\_IMJP*Mutex_*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\PredictionPropertyMutex_*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\MSCTF.Shared.MUTEX.*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\_IME_*_MutexObject_*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\_IME_*_IME*_KnlDict_DicWriteMutex_*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\ZonesCounterMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\!IETld!Mutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\ZoneAttributeCacheCounterMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\ZonesCacheCounterMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\ZonesLockedCacheCounterMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\!PrivacIE!SharedMemory!Mutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\DDrawWindowListMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\DDrawDriverObjectListMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\__DDrawExclMode__
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\__DDrawCheckExclMode__
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\_!SHMSFTHISTORY!_
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\MidiMapper_modLongMessage_RefCnt
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\MAPI-HP*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\DDrawWindowListMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\DDrawDriverObjectListMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\QuickTimeBroadcastMsgMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\QuickTimeProcessInfoMutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\AcrobatDesignerSplash
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\AcrobatViewerIsRunning
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\AcroSrchMutexProtectThread
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\AcroCatalogMutexProtectThread
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\SWSPROF Mutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\Acrobat Instance Mutex
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\EDC_*_MUTEX
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Speech*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Local\HKEY_CURRENT_USER_SOFTWARE_Microsoft_Speech*
- Rule: 5, 13, \Sessions\1\BaseNamedObjects\Global\GoogleJapaneseInput.mutex.*
- Rule: 4, 9, CTF.ThreadMIConnectionEvent.*
- Rule: 4, 9, CTF.ThreadMarshalInterfaceEvent.*
- Rule: 4, 9, MSCTF.SendReceiveConection.Event.*
- Rule: 4, 9, MSCTF.SendReceive.Event.*
- Rule: 4, 9, MSCTF.CheckThreadInptIdle.Event.*
- Rule: 4, 9, AtlTraceModuleManager_ProcessAddedStatic*
- Rule: 4, 9, MSFT.VSA.COM.DISABLE
- Rule: 4, 9, Global\TabletHardwarePresent
- Rule: 4, 9, C63E89DC-9712-40e4-9CDB-B3BE855B6C79*
- Rule: 4, 9, C7764963-1E50-4f24-91A4-A1BC5EBA2747*
- Rule: 4, 9, Preferences_Dialog
- Rule: 4, 9, __Acroform::WorkflowInfoMutext__
- Rule: 4, 9, PPKLite:CPasswordLockbox
- Rule: 4, 9, CDataSync_DigSigCPrefsCab
- Rule: 4, 9, CDataSync_APIconFile
- Rule: 4, 9, CDataSync_FEATDataSync
- Rule: 4, 9, CDataSync_AddressBook
- Rule: 4, 9, Local\HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Speech*
- Rule: 4, 9, Local\HKEY_CURRENT_USER_SOFTWARE_Microsoft_Speech*
- Rule: 4, 9, Global\Microsoft Smart Card Resource Manager*
- Rule: 4, 9, Global\GoogleJapaneseInput.event.*
- Rule: 4, 9, JsMmfAtok*
- Rule: 4, 9, Serotek*
- Rule: 0, 0, \??\pipe\C:\Users\w7\AppData\LocalLow\Adobe\Acrobat\11.0\Synchronizer\*
- Rule: 0, 0, \??\pipe\C:\Users\w7\AppData\Roaming\Adobe\Acrobat\11.0\Synchronizer\*
- Rule: 0, 0, \??\pipe\AIPC_SRV\pdfshell_*
- Rule: 0, 0, \??\pipe\Microsoft Smart Card Resource*
- Rule: 0, 0, \??\pipe\googlejapaneseinput*
- Rule: 0, 0, \??\pipe\32B6B37A-4A7D-4e00-95F2-6F0BF3DE3E00*
- Rule: 0, 0, \??\pipe\Serotek*
Advertisement
RAW Paste Data
Copied
Advertisement