File details
File name: avastsvc.exe
Name: avast! Antivirus
Description: avast! Service
Version: 8.0.1497.376
Size: 45.71 KB
Original file name: AvastSvc.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 1/31/2014
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0081850237%
Privileged CPU:
0.0036741543%

User CPU:
0.00451086937962%

Privileged CPU time: 122028340.35 ms
Privileged CPU time /min: 97 ms
CPU cycle count:
129,450,274
CPU cycle count /min: 914,284,130
Context switches /sec:
87
 | Memory utilization averages |
Committed memory:
390.92 MB
Peak committed memory: 539.76 MB
Paged memory:
49.2 MB
Peak paged memory: 121.11 MB
Paged system memory:
428.3 KB
Non-paged system memory: 625.91 KB
Working set memory:
12.76 MB
Peak working set memory: 98.38 MB
Min working set memory: 791.81 KB
Private memory:
49.2 MB
Page faults:
14,114,987
Page faults /min: 10,149
 | Process I/O averages |
Total read operations:
286,241
Read operations /min: 252
Read transfer /min: 6.58 MB
Total write operations:
70,956
Write operations /min: 105
Total write transfer: 467.11 MB
Write transfer /min: 616.97 KB
Total other operations:
2,295,234
Other operations /min: 1,837
Total other transfer: 199.16 MB
Other Transfer /min: 1.88 MB
 | GUI Object Averages |
GDI objects:
11
USER objects:
12
Resources
Handle count average: 1,731
Thread count average: 74
Thread resource averages
Total CPU: 0.163110392084%
Privileged CPU: 0.066769079930%
User CPU: 0.096341312154%
Context switches /sec: 2
Module memory size: 9.32 MB
msvcr90.dll

Total CPU: 0.145709183346%
Privileged CPU: 0.058741653060%
User CPU: 0.086967530286%
CPU Cycle count /sec: 3,445,425
Context switches /sec: 5
Module memory size: 652 KB
Total CPU: 0.049682556485%
Privileged CPU: 0.007309808268%
User CPU: 0.042372748217%
CPU Cycle count /sec: 897,988
Context switches /sec: 1
Module memory size: 900 KB
Total CPU: 0.030803869739%
Privileged CPU: 0.017543187387%
User CPU: 0.013260682352%
CPU Cycle count /sec: 825,507
Context switches /sec: 2
Module memory size: 52 KB
advapi32.dll

Total CPU: 0.027149025248%
Privileged CPU: 0.001682211547%
User CPU: 0.025466813701%
Module memory size: 688 KB
Total CPU: 0.022752199006%
Privileged CPU: 0.011989939576%
User CPU: 0.010762259430%
CPU Cycle count /sec: 555,490
Module memory size: 72 KB
msvcr90.dll

Total CPU: 0.022544742927%
Privileged CPU: 0.011472396103%
User CPU: 0.011072346824%
CPU Cycle count /sec: 383,628
Context switches /sec: 1
Module memory size: 652 KB
sechost.dll

Total CPU: 0.022492498971%
Privileged CPU: 0.014297197993%
User CPU: 0.008195300978%
CPU Cycle count /sec: 541,612
Context switches /sec: 1
Module memory size: 100 KB
ntdll.dll

Total CPU: 0.019268599447%
Privileged CPU: 0.019201663199%
User CPU: 0.000066936247%
CPU Cycle count /sec: 60,537
Module memory size: 1.66 MB
Total CPU: 0.012620542201%
Privileged CPU: 0.004236377972%
User CPU: 0.008384164229%
Context switches /sec: 1
Module memory size: 652 KB
wow64.dll

Total CPU: 0.011767090521%
Privileged CPU: 0.009448734954%
User CPU: 0.002318355567%
CPU Cycle count /sec: 279,802
Module memory size: 252 KB
Total CPU: 0.008447182087%
Privileged CPU: 0.000674344471%
User CPU: 0.007772837616%
CPU Cycle count /sec: 303,865
Module memory size: 420 KB
Total CPU: 0.007278028016%
Privileged CPU: 0.006426896914%
User CPU: 0.000851131102%
CPU Cycle count /sec: 159,930
Module memory size: 68 KB
wow64.dll

Total CPU: 0.007253812819%
Privileged CPU: 0.000259064744%
User CPU: 0.006994748075%
CPU Cycle count /sec: 226,375
Module memory size: 252 KB
ntdll.dll

Total CPU: 0.005959159196%
Privileged CPU: 0.002803068235%
User CPU: 0.003156090961%
CPU Cycle count /sec: 125,921
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.005401311793%
Privileged CPU: 0.005401311793%
User CPU: 0.000000000000%
CPU Cycle count /sec: 103,831
Module memory size: 1.23 MB
advapi32.dll

Total CPU: 0.003512996379%
Privileged CPU: 0.001059955804%
User CPU: 0.002453040575%
CPU Cycle count /sec: 82,483
Module memory size: 792 KB
Total CPU: 0.002885110183%
Privileged CPU: 0.002337792407%
User CPU: 0.000547317776%
CPU Cycle count /sec: 47,681
Module memory size: 284 KB
wow64.dll

Total CPU: 0.002571728004%
Privileged CPU: 0.000660603562%
User CPU: 0.001911124441%
CPU Cycle count /sec: 66,095
Module memory size: 252 KB
Total CPU: 0.002121891120%
Privileged CPU: 0.000318203769%
User CPU: 0.001803687350%
Module memory size: 620 KB
Process details
Runs as (owner): User
Integrety level: System
Windows platform: 32-bit
Runs as a service: Yes
Parent Processes
Child Process
Process Commands
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
Service details
Name: avast! Antivirus
Service type:
Win32ShareProcess
Description: “Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.”
Network connectivity
TCP: r2.ycpi.vip.dee.yahoo.net on port 1976
TCP: r-063-040-234-077.ff.avast.com on port 56653
TCP: r-056-043-234-077.ff.avast.com on port 50792
TCP: r-055-044-234-077.ff.avast.com on port 1033
TCP: r-055-043-234-077.ff.avast.com on port 3474
TCP: r-055-041-234-077.ff.avast.com on port 2155
TCP: r-054-041-234-077.ff.avast.com on port 49962
TCP: r-053-044-234-077.ff.avast.com on port 59170
TCP: r-053-041-234-077.ff.avast.com on port 49165
TCP: r-052-042-234-077.ff.avast.com on port 17116
TCP: r-051-042-234-077.ff.avast.com on port 55249
TCP: r-051-042-234-077.ff.avast.com on port 2588
Image hashes
MD5: 9330941c8f6df417f6dbbe998db6687e
SHA-1: 9074e684163c7962035410a6f2ef10b88beb48b6
SHA-256: 28bc051d7c74721baf85be2aab97eae44152779106c5bda1fda07b9c049e2fdc
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegDeleteKeyA
RegEnumValueA
RegQueryInfoKeyA
RegEnumKeyExA
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
RegCreateKeyExA
RegSetValueExA
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegSetValueExW
ashbase.dll

aswcmnbs.dll

svcServiceStart
aswcmnbsDllMain
secPreventHookDllInjection
cmnbFree
cmnbInit
fsGetAvastProgramPath
kernel32.dll

GetFileAttributesW
IsBadCodePtr
GetProcAddress
GetModuleHandleA
IsBadReadPtr
GetCurrentProcess
GetModuleFileNameW
LoadLibraryA
GetVersionExW
GetPrivateProfileStringW
WideCharToMultiByte
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
InterlockedCompareExchange
GetStartupInfoW
VirtualProtect
TerminateProcess
Sleep
InterlockedExchange
CreateProcessW
CloseHandle
msvcp90.dll
msvcr90.dll
shlwapi.dll

PathAppendW
PathRemoveFileSpecW