File details
File name: avastui.exe
Name: avast! Antivirus
Description: avast! Antivirus
Version: 8.0.1497.376
Size: 4.63 MB
Original file name: AvastUi.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 1/31/2014
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0191168200%
Privileged CPU:
0.0098759301%

User CPU:
0.00924088993400%

Privileged CPU time: 134006.39 ms
Privileged CPU time /min: 4 ms
CPU cycle count:
310,002,780
CPU cycle count /min: 73,446,255
Context switches /sec:
22
 | Memory utilization averages |
Committed memory:
143.61 MB
Peak committed memory: 162.3 MB
Paged memory:
16.11 MB
Peak paged memory: 21.6 MB
Paged system memory:
201.46 KB
Non-paged system memory: 27.62 KB
Working set memory:
10.9 MB
Peak working set memory: 22.67 MB
Min working set memory: 4.93 MB
Private memory:
16.11 MB
Page faults:
182,419
Page faults /min: 90
 | Process I/O averages |
Total read operations:
16,828
Read operations /min: 7
Total read transfer: 20.98 MB
Read transfer /min: 8.67 KB
Total write operations:
57
Write operations /min: 1
Total write transfer: 11.52 KB
Write transfer /min: 3 Bytes
Total other operations:
251,284
Other operations /min: 113
Total other transfer: 4.56 MB
Other Transfer /min: 2.3 KB
 | GUI Object Averages |
GDI objects:
196
Peak GDI objects: 246
USER objects:
46
Peak USER objects: 52
Resources
Handle count average: 416
Thread count average: 22
Thread resource averages
ntdll.dll

Total CPU: 0.009168594702%
Privileged CPU: 0.006454170563%
User CPU: 0.002714424139%
CPU Cycle count /sec: 199,736
Module memory size: 1.23 MB
Total CPU: 0.008119634360%
Privileged CPU: 0.004366870452%
User CPU: 0.003752763907%
CPU Cycle count /sec: 233,836
Context switches /sec: 3
Module memory size: 4.63 MB
msvcr90.dll

Total CPU: 0.002152564535%
Privileged CPU: 0.001076270681%
User CPU: 0.001076293854%
CPU Cycle count /sec: 33,597
Module memory size: 652 KB
ntdll.dll

Total CPU: 0.001424624338%
Privileged CPU: 0.001401660755%
User CPU: 0.000022963583%
CPU Cycle count /sec: 73,814
Module memory size: 1.66 MB
Total CPU: 0.000473420256%
Privileged CPU: 0.000357134599%
User CPU: 0.000116285657%
CPU Cycle count /sec: 36,261
Context switches /sec: 1
Module memory size: 900 KB
winmm.dll

Total CPU: 0.000313826990%
Privileged CPU: 0.000049551630%
User CPU: 0.000264275360%
CPU Cycle count /sec: 5,243
Module memory size: 200 KB
winmm.dll

Total CPU: 0.000228044437%
Privileged CPU: 0.000000000000%
User CPU: 0.000228044437%
CPU Cycle count /sec: 6,182
Module memory size: 200 KB
winmm.dll

Total CPU: 0.000145049672%
Privileged CPU: 0.000000000000%
User CPU: 0.000145049672%
Module memory size: 184 KB
winmm.dll

Total CPU: 0.000108943621%
Privileged CPU: 0.000041512125%
User CPU: 0.000067431496%
Module memory size: 180 KB
winmm.dll

Total CPU: 0.000065371832%
Privileged CPU: 0.000018677666%
User CPU: 0.000046694165%
CPU Cycle count /sec: 1,570
Module memory size: 200 KB
winmm.dll

Total CPU: 0.000058722481%
Privileged CPU: 0.000019574160%
User CPU: 0.000039148320%
Module memory size: 180 KB
Total CPU: 0.000052828017%
Privileged CPU: 0.000039622270%
User CPU: 0.000013205748%
Module memory size: 264 KB
msvcr90.dll

Total CPU: 0.000048572449%
Privileged CPU: 0.000021357291%
User CPU: 0.000027215158%
CPU Cycle count /sec: 2,050
Module memory size: 652 KB
Total CPU: 0.000037903026%
Privileged CPU: 0.000022741815%
User CPU: 0.000015161210%
Module memory size: 652 KB
ntdll.dll

Total CPU: 0.000030405873%
Privileged CPU: 0.000030405873%
User CPU: 0.000000000000%
CPU Cycle count /sec: 739
Module memory size: 1.16 MB
ntdll.dll

Total CPU: 0.000016046319%
Privileged CPU: 0.000016046319%
User CPU: 0.000000000000%
CPU Cycle count /sec: 20,051
Module memory size: 1.23 MB
wdmaud.drv

Total CPU: 0.000015202985%
Privileged CPU: 0.000015202985%
User CPU: 0.000000000000%
CPU Cycle count /sec: 440
Module memory size: 188 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
System Tray: Yes
Parent Processes
Process Commands
"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
Startup files (all users) run details
Name: avast5
Command: C:\Program Files1\ALWILS~1\Avast5\avastUI.exe /nogui
Scheduled task details
Name: \{BE644B67-0FC9-4E09-8921-3C92C4187F59}
Network connectivity
TCP: maa03s04-in-f5.1e100.net on port 63815
TCP: lax17s02-in-f7.1e100.net on port 59161
TCP: hg-in-f102.1e100.net on port 49725
TCP: a23-72-62-13.deploy.static.akamaitechnologies.com on port 51790
TCP: a23-66-190-13.deploy.static.akamaitechnologies.com on port 2872
TCP: a23-37-14-13.deploy.static.akamaitechnologies.com on port 2903
TCP: a184-86-142-13.deploy.static.akamaitechnologies.com on port 4865
TCP: 178-102-241.dynamic.cyta.gr on port 54911
Windows Firewall allowed program: Yes
Image hashes
MD5: cbc7d8e5416ad30cf16dc2fd4a6aa399
SHA-1: 3f604b5bb0601534852e3017d69e8161e02fc8d8
SHA-256: 8158d11583c09ddff0f39ceaca489accd546082d0f77e4bd2a5831cb17de4a17
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
aavmrpch.dll

AavmRpcRunSystemComponent
AavmRpcCreateBinding
AavmRpcDestroyBinding
AavmRpcRunComponent
advapi32.dll

CloseServiceHandle
RegQueryValueExA
IsTextUnicode
AllocateAndInitializeSid
AddAccessAllowedAce
InitializeAcl
GetLengthSid
OpenThreadToken
EqualSid
GetTokenInformation
OpenProcessToken
RegEnumKeyExW
RegOpenKeyW
RegEnumValueW
OpenServiceW
OpenSCManagerW
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
FreeSid
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
SetEntriesInAclW
RegOpenKeyExA
RegSetValueExW
RegDeleteValueW
ashbase.dll

ashtask.dll

aswcmnbs.dll

fsGetAvastDataPath
fsGetAvastLogPath
fsGetAvastSumpPath
secPreventHookDllInjection
secCreateSharedEvent
secOpenSharedEvent
iniGetPrivateProfileString
fsGetAvastProgramPath
secCreateSharedMutex
fsGetAvastTempFileName
iniGetPrivateProfileInt
iniWritePrivateProfileInt
iniWritePrivateProfileString
cmnbFree
cmnbInit
aswcmnis.dll

cyphSimpleCode
inflateInit_
inflate
inflateEnd
deflateEnd
deflate
inflateReset
deflateReset
deflateInit2_
crcGenerate32c
mdaGenerate
aswcmnos.dll

dep_osIsWow64
dep_fsGetFileSizeHandle
dep_fsReadFile
dep_fsCloseFile
dep_osIsWinVistaOrBetter
dep_osIsWinXPOrBetter
dep_osIsWin64
dep_secGetPublicSecurity
dep_fsEnableWow64FsRedirection
dep_fsWriteFile
dep_fsExistFile
dep_fsRemoveFolderRecursive
dep_fsDeleteFileX
dep_fsOpenFileX
dep_osIsWin8OrBetter
dep_fsCopyFile
dep_procGetFileName
aswlog.dll

aswproperty.dll

aswGetPropertyInt
aswGetProperty
aswPropertyFreeLibrary
aswGetAvastPropertyInt
aswPropertyInitLibrary
aswGetIntFromCache
aswGetStrFromCache
aswSetAvastProperty
aswGetAvastProperty
aswSetPropertyInt
aswSetProperty
comctl32.dll

_TrackMouseEvent
ImageList_Draw
ImageList_GetImageInfo
ImageList_DrawEx
ImageList_GetIconSize
comdlg32.dll

crypt32.dll

CertCreateCertificateContext
CertFreeCertificateContext
cryptui.dll

CryptUIDlgViewCertificateW
dnsapi.dll

DnsRecordListFree
DnsQuery_W
DnsQuery_A
gdi32.dll

SetWindowOrgEx
SetLayout
BitBlt
SetViewportOrgEx
GetTextMetricsA
SetWindowExtEx
GetWindowExtEx
SetTextColor
DeleteDC
SetBkColor
GetObjectW
LPtoDP
ExcludeClipRect
CreateCompatibleDC
CreateRectRgnIndirect
DPtoLP
CombineRgn
SetMapMode
CreateCompatibleBitmap
GetMapMode
SaveDC
GetClipBox
SetViewportExtEx
GetViewportExtEx
GetObjectA
GetStockObject
RestoreDC
CreateSolidBrush
DeleteObject
CreateRoundRectRgn
SelectObject
GetDeviceCaps
SetTextAlign
GetTextAlign
GetTextExtentPointW
TextOutA
TextOutW
GetPixel
IntersectClipRect
RectVisible
CreatePen
CreatePatternBrush
GetTextExtentExPointW
Rectangle
SetBkMode
CreateBitmap
SetPixel
Polygon
GetCurrentPositionEx
ExtCreatePen
Polyline
PtVisible
ExtTextOutW
Escape
CreateFontIndirectW
GetCurrentObject
SetBrushOrgEx
CreateDIBPatternBrushPt
CreateDIBSection
StretchBlt
GetDIBits
StretchDIBits
SetStretchBltMode
CreateFontA
EnumFontFamiliesExA
AddFontMemResourceEx
EnumFontFamiliesExW
GetWindowOrgEx
CreateHatchBrush
GetTextExtentPoint32A
GetTextExtentPoint32W
PatBlt
GetDeviceGammaRamp
SetDeviceGammaRamp
GetKerningPairsA
GetGlyphOutlineW
AddFontResourceExW
kernel32.dll

GetLocaleInfoA
TlsGetValue
GetCurrentProcess
QueryPerformanceCounter
QueryPerformanceFrequency
InterlockedIncrement
DeleteCriticalSection
FreeLibrary
GetProcAddress
LoadLibraryA
GetSystemDirectoryA
GetLocaleInfoW
IsBadReadPtr
MulDiv
FlushFileBuffers
SetEvent
GetProcessHeap
TlsSetValue
GetExitCodeProcess
CallNamedPipeW
CreateProcessW
HeapFree
WriteFile
ReadFile
ConnectNamedPipe
TerminateThread
WaitForSingleObject
ExitThread
GetPrivateProfileStringW
GetSystemTime
LocalFree
CreateDirectoryW
LocalAlloc
GetUserDefaultLCID
VirtualFree
ExpandEnvironmentStringsA
Process32NextW
Process32FirstW
LCMapStringW
FindResourceExW
LocalUnlock
CreateFileMappingA
FlushViewOfFile
SetEndOfFile
UnmapViewOfFile
MapViewOfFile
GetThreadLocale
GetVersionExA
GlobalAlloc
SetThreadLocale
GetCPInfo
GetCurrencyFormatW
DeleteFileA
MoveFileA
SetLastError
GetShortPathNameA
CreateEventA
VirtualAlloc
GetVersionExW
DeviceIoControl
CreateFileW
GetDiskFreeSpaceExW
GetVolumeInformationW
GetDriveTypeW
GetLogicalDrives
Sleep
GetLastError
FileTimeToLocalFileTime
FileTimeToSystemTime
GetTimeFormatW
GetDateFormatW
CreateThread
CloseHandle
InitializeCriticalSection
GetACP
EnterCriticalSection
LeaveCriticalSection
WideCharToMultiByte
MultiByteToWideChar
GetTickCount
DeleteFileW
GetTempFileNameW
GetTempPathW
HeapAlloc
WaitForMultipleObjects
InterlockedExchange
InitializeCriticalSectionAndSpinCount
LoadLibraryW
OpenEventW
TerminateProcess
ExitProcess
GetPrivateProfileIntW
GetModuleFileNameW
ExpandEnvironmentStringsW
GetCurrentThreadId
GetCommandLineW
GetCurrentProcessId
CopyFileW
GlobalLock
GlobalUnlock
SetThreadPriority
GetSystemInfo
WaitNamedPipeW
LoadLibraryExW
GetShortPathNameW
FindFirstFileW
FindNextFileW
FindClose
GetSystemDirectoryW
GetWindowsDirectoryW
CreateEventW
GetNumberFormatW
GetFileAttributesW
GetLocalTime
SetFilePointer
GetFileSize
SystemTimeToFileTime
GetSystemTimeAsFileTime
InterlockedDecrement
DisconnectNamedPipe
GetUserDefaultLangID
CreateIoCompletionPort
CreateNamedPipeW
GetQueuedCompletionStatus
GetTempFileNameA
TlsAlloc
GetTempPathA
FindResourceA
FindResourceW
LoadResource
SizeofResource
LockResource
GetModuleHandleW
GetStringTypeA
GetStringTypeW
ReleaseMutex
lstrcmpiW
lstrcmpW
GetExitCodeThread
CreateToolhelp32Snapshot
OutputDebugStringW
OpenProcess
GetCurrentThread
RaiseException
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
SetProcessWorkingSetSize
DllMain
GetVersion
CreateMutexW
MoveFileExW
ResumeThread
WritePrivateProfileStringW
mfc90u.dll
msimg32.dll

msvcp90.dll
msvcr90.dll
ole32.dll

CoCreateGuid
CoTaskMemFree
StringFromCLSID
CoInitialize
CoCreateInstance
CoUninitialize
StringFromGUID2
CoInitializeEx
CLSIDFromString
oleacc.dll

CreateStdAccessibleObject
AccessibleObjectFromWindow
LresultFromObject
psapi.dll

GetModuleFileNameExW
EnumProcessModules
EnumProcesses
rpcrt4.dll

RpcBindingFromStringBindingW
RpcStringFreeW
RpcBindingFree
RpcStringBindingComposeW
UuidCreate
NdrConformantArrayMarshall
RpcRaiseException
NdrClientInitializeNew
NdrConformantArrayBufferSize
NdrFreeBuffer
NdrGetBuffer
NdrConformantStringBufferSize
NdrConformantArrayUnmarshall
NdrSendReceive
NdrConvert
NdrConformantStringMarshall
RpcBindingServerFromClient
RpcBindingToStringBindingW
RpcStringBindingParseW
I_RpcGetBuffer
NdrAllocate
NdrServerInitializeNew
NdrConformantStringUnmarshall
NdrPointerFree
RpcAsyncInitializeHandle
RpcBindingSetAuthInfoExA
RpcAsyncCancelCall
RpcBindingFromStringBindingA
RpcStringBindingComposeA
RpcAsyncCompleteCall
NdrAsyncClientCall
NdrClientCall2
RpcStringFreeA
shell32.dll

SHGetPathFromIDListW
SHGetFileInfoW
SHChangeNotify
SHGetDesktopFolder
SHGetMalloc
SHGetSpecialFolderLocation
Shell_NotifyIconW
SHBrowseForFolderW
ShellExecuteW
ShellExecuteExW
SHGetFolderPathW
SHGetSpecialFolderPathW
shlwapi.dll

PathFileExistsW
PathCompactPathW
ColorHLSToRGB
ColorRGBToHLS
PathIsDirectoryW
UrlCombineA
urlmon.dll

user32.dll
version.dll

VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
winhttp.dll

WinHttpSetOption
WinHttpSendRequest
WinHttpConnect
WinHttpCloseHandle
WinHttpSetTimeouts
WinHttpOpen
WinHttpOpenRequest
WinHttpReadData
WinHttpReceiveResponse
WinHttpQueryOption
WinHttpQueryHeaders
wininet.dll

InternetReadFile
InternetCombineUrlA
HttpOpenRequestA
InternetGetLastResponseInfoA
InternetOpenA
InternetCloseHandle
InternetQueryOptionA
InternetConnectA
HttpQueryInfoA
HttpSendRequestA
InternetCrackUrlW
InternetSetOptionA
InternetCanonicalizeUrlW
InternetSetOptionW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
InternetOpenW
winmm.dll

timeSetEvent
timeKillEvent
timeGetTime
timeGetDevCaps
PlaySoundA