File details
File name: avastsvc.exe
Name: avast! Antivirus
Description: avast! Service
Version: 8.0.1489.300
Size: 45.71 KB
Original file name: AvastSvc.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 1/31/2014
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0061909091%
Privileged CPU:
0.0042723935%

User CPU:
0.00191851562501%

Privileged CPU time: 266710084.45 ms
Privileged CPU time /min: 7,915 ms
CPU cycle count:
71,830,242
CPU cycle count /min: 544,240,387
Context switches /sec:
76
 | Memory utilization averages |
Committed memory:
371.13 MB
Peak committed memory: 538.25 MB
Paged memory:
48.96 MB
Peak paged memory: 148.93 MB
Paged system memory:
458.06 KB
Non-paged system memory: 690.37 KB
Working set memory:
13.41 MB
Peak working set memory: 123.45 MB
Min working set memory: 1.88 MB
Private memory:
48.96 MB
Page faults:
32,750,517
Page faults /min: 17,307
 | Process I/O averages |
Total read operations:
1,009,271
Read operations /min: 542
Total read transfer: 246.54 MB
Read transfer /min: 65.55 MB
Total write operations:
276,033
Write operations /min: 120
Total write transfer: 263.82 MB
Write transfer /min: 648.74 KB
Total other operations:
3,278,746
Other operations /min: 1,356
Total other transfer: 241.55 MB
Other Transfer /min: 1.64 MB
 | GUI Object Averages |
GDI objects:
11
USER objects:
8
Resources
Handle count average: 1,756
Thread count average: 74
Thread resource averages
msvcr90.dll

Total CPU: 0.082633543330%
Privileged CPU: 0.027957536008%
User CPU: 0.054676007322%
CPU Cycle count /sec: 1,336,961
Context switches /sec: 1
Module memory size: 652 KB
Total CPU: 0.037068818005%
Privileged CPU: 0.007977318752%
User CPU: 0.029091499253%
Module memory size: 620 KB
Total CPU: 0.036387434652%
Privileged CPU: 0.008706829271%
User CPU: 0.027680605381%
CPU Cycle count /sec: 711,908
Module memory size: 9.32 MB
Total CPU: 0.036241975718%
Privileged CPU: 0.007250077862%
User CPU: 0.028991897856%
CPU Cycle count /sec: 687,218
Context switches /sec: 1
Module memory size: 900 KB
sechost.dll

Total CPU: 0.035448530818%
Privileged CPU: 0.014268183044%
User CPU: 0.021180347773%
CPU Cycle count /sec: 1,032,881
Context switches /sec: 1
Module memory size: 100 KB
msvcr90.dll

Total CPU: 0.034933075001%
Privileged CPU: 0.011874239323%
User CPU: 0.023058835678%
CPU Cycle count /sec: 1,050,179
Context switches /sec: 1
Module memory size: 652 KB
Total CPU: 0.032735274107%
Privileged CPU: 0.011855258149%
User CPU: 0.020880015958%
CPU Cycle count /sec: 837,992
Context switches /sec: 1
Module memory size: 52 KB
advapi32.dll

Total CPU: 0.020971781375%
Privileged CPU: 0.009786831308%
User CPU: 0.011184950067%
CPU Cycle count /sec: 340,040
Module memory size: 792 KB
Total CPU: 0.014859880528%
Privileged CPU: 0.007193377270%
User CPU: 0.007666503259%
CPU Cycle count /sec: 239,401
Module memory size: 284 KB
Total CPU: 0.012992235946%
Privileged CPU: 0.005394536123%
User CPU: 0.007597699824%
CPU Cycle count /sec: 315,661
Module memory size: 72 KB
Total CPU: 0.011780128114%
Privileged CPU: 0.007674329914%
User CPU: 0.004105798200%
CPU Cycle count /sec: 247,793
Module memory size: 68 KB
msvcr90.dll

Total CPU: 0.011253635625%
Privileged CPU: 0.006671092351%
User CPU: 0.004582543274%
CPU Cycle count /sec: 320,707
Context switches /sec: 2
Module memory size: 652 KB
advapi32.dll

Total CPU: 0.010076584993%
Privileged CPU: 0.004820056531%
User CPU: 0.005256528462%
CPU Cycle count /sec: 160,992
Module memory size: 792 KB
ntdll.dll

Total CPU: 0.005054201606%
Privileged CPU: 0.003992335544%
User CPU: 0.001061866062%
CPU Cycle count /sec: 91,535
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.005004785176%
Privileged CPU: 0.004705690414%
User CPU: 0.000299094763%
CPU Cycle count /sec: 116,995
Module memory size: 1.66 MB
msvcr90.dll

Total CPU: 0.004871931095%
Privileged CPU: 0.001452647374%
User CPU: 0.003419283722%
CPU Cycle count /sec: 153,053
Module memory size: 652 KB
Total CPU: 0.004575421563%
Privileged CPU: 0.001565376538%
User CPU: 0.003010045025%
CPU Cycle count /sec: 135,789
Context switches /sec: 11
Module memory size: 52 KB
wow64.dll

Total CPU: 0.004507484293%
Privileged CPU: 0.002959913934%
User CPU: 0.001547570360%
CPU Cycle count /sec: 134,937
Module memory size: 252 KB
rpcrt4.dll

Total CPU: 0.003256103516%
Privileged CPU: 0.001324261123%
User CPU: 0.001931842393%
CPU Cycle count /sec: 109,857
Context switches /sec: 1
Module memory size: 780 KB
ntdll.dll

Total CPU: 0.002974260662%
Privileged CPU: 0.002917690445%
User CPU: 0.000056570217%
CPU Cycle count /sec: 106,579
Module memory size: 1.23 MB
Process details
Runs as (owner): System
Integrety level: System
Windows platform: 64-bit
Runs as a service: Yes
Parent Processes
Child Processes
Process Commands
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Programmer\Alwil Software\Avast5\AvastSvc.exe"
Service details
Name: avast! Antivirus
Service type:
Win32ShareProcess
Description: “Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.”
Network connectivity
TCP: wikimedia-lb.eqiad.wikimedia.org on port 1266
TCP: web02.imediacom.fr on port 49512
TCP: r-056-044-234-077.ff.avast.com on port 58870
TCP: r-056-043-234-077.ff.avast.com on port 52540
TCP: r-056-041-234-077.ff.avast.com on port 64935
TCP: r-055-043-234-077.ff.avast.com on port 53377
TCP: r-054-044-234-077.ff.avast.com on port 49182
TCP: r-054-042-234-077.ff.avast.com on port 49157
TCP: r-053-044-234-077.ff.avast.com on port 1042
TCP: r-053-042-234-077.ff.avast.com on port 49209
TCP: r-053-042-234-077.ff.avast.com on port 49525
TCP: r-052-044-234-077.ff.avast.com on port 4756
Image hashes
MD5: 28d6701c710ad7ba3cb95e75f8f1a9aa
SHA-1: a2870dd55e905fa47f8b178eacf59837f35533d1
SHA-256: 66ee8bc56e5043b5a84e1ba37d591ead132bd949f03ca8092fdcc3e196ab39d0
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
advapi32.dll

RegDeleteKeyA
RegEnumValueA
RegQueryInfoKeyA
RegEnumKeyExA
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
RegCreateKeyExA
RegSetValueExA
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegSetValueExW
ashbase.dll

aswcmnbs.dll

svcServiceStart
aswcmnbsDllMain
secPreventHookDllInjection
cmnbFree
cmnbInit
fsGetAvastProgramPath
kernel32.dll

GetFileAttributesW
IsBadCodePtr
GetProcAddress
GetModuleHandleA
IsBadReadPtr
GetCurrentProcess
GetModuleFileNameW
LoadLibraryA
GetVersionExW
GetPrivateProfileStringW
WideCharToMultiByte
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
InterlockedCompareExchange
GetStartupInfoW
VirtualProtect
TerminateProcess
Sleep
InterlockedExchange
CreateProcessW
CloseHandle
msvcp90.dll
msvcr90.dll
shlwapi.dll

PathAppendW
PathRemoveFileSpecW