File details
File name: avastui.exe
Name: avast! Antivirus
Description: avast! Antivirus
Version: 8.0.1489.300
Size: 4.63 MB
Original file name: AvastUi.exe
Digital certificate
Certificate authority:
VeriSign
Expiration date: 1/31/2014
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0102684322%
Privileged CPU:
0.0047952257%

User CPU:
0.00547320653554%

Privileged CPU time: 32210267.74 ms
Privileged CPU time /min: 27 ms
CPU cycle count:
291,828,985
CPU cycle count /min: 146,813,043
Context switches /sec:
23
 | Memory utilization averages |
Committed memory:
151.34 MB
Peak committed memory: 170.29 MB
Paged memory:
14.55 MB
Peak paged memory: 19.79 MB
Paged system memory:
226.36 KB
Non-paged system memory: 28.72 KB
Working set memory:
10.93 MB
Peak working set memory: 21.5 MB
Min working set memory: 5.4 MB
Private memory:
14.55 MB
Page faults:
160,917
Page faults /min: 278
 | Process I/O averages |
Total read operations:
9,776
Read operations /min: 10
Total read transfer: 16.02 MB
Read transfer /min: 21.08 KB
Total write operations:
81
Write operations /min: 1
Total write transfer: 60.67 KB
Write transfer /min: 39 Bytes
Total other operations:
316,166
Other operations /min: 525
Total other transfer: 3.89 MB
Other Transfer /min: 7.02 KB
 | GUI Object Averages |
GDI objects:
186
Peak GDI objects: 270
USER objects:
44
Peak USER objects: 54
Resources
Handle count average: 406
Thread count average: 22
Thread resource averages
ntdll.dll

Total CPU: 0.020445166264%
Privileged CPU: 0.019127291957%
User CPU: 0.001317874307%
CPU Cycle count /sec: 980,949
Context switches /sec: 1
Module memory size: 1.23 MB
Total CPU: 0.008305023014%
Privileged CPU: 0.004130640114%
User CPU: 0.004174382900%
CPU Cycle count /sec: 604,479
Context switches /sec: 3
Module memory size: 4.63 MB
ntdll.dll

Total CPU: 0.007748794493%
Privileged CPU: 0.002453309853%
User CPU: 0.005295484641%
CPU Cycle count /sec: 223,631
Context switches /sec: 1
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.005211867880%
Privileged CPU: 0.003724382762%
User CPU: 0.001487485118%
CPU Cycle count /sec: 85,681
Module memory size: 1.23 MB
Total CPU: 0.003112228856%
Privileged CPU: 0.002378145219%
User CPU: 0.000734083637%
CPU Cycle count /sec: 138,926
Context switches /sec: 1
Module memory size: 900 KB
winmm.dll

Total CPU: 0.001937945668%
Privileged CPU: 0.000227993608%
User CPU: 0.001709952060%
CPU Cycle count /sec: 47,720
Module memory size: 132 KB
winmm.dll

Total CPU: 0.001758521470%
Privileged CPU: 0.000957622407%
User CPU: 0.000800899064%
CPU Cycle count /sec: 58,164
Module memory size: 200 KB
rpcrt4.dll

Total CPU: 0.001061144886%
Privileged CPU: 0.001061144886%
User CPU: 0.000000000000%
CPU Cycle count /sec: 11,512
Module memory size: 776 KB
ntdll.dll

Total CPU: 0.000849866484%
Privileged CPU: 0.000412966165%
User CPU: 0.000436900319%
CPU Cycle count /sec: 43,556
Module memory size: 1.66 MB
winmm.dll

Total CPU: 0.000823285817%
Privileged CPU: 0.000000000000%
User CPU: 0.000823285817%
Module memory size: 184 KB
winmm.dll

Total CPU: 0.000777930245%
Privileged CPU: 0.000207592858%
User CPU: 0.000570337387%
CPU Cycle count /sec: 12,333
Module memory size: 200 KB
ntdll.dll

Total CPU: 0.000605131346%
Privileged CPU: 0.000121026269%
User CPU: 0.000484105076%
CPU Cycle count /sec: 16,093
Module memory size: 1.41 MB
msvcr90.dll

Total CPU: 0.000588986560%
Privileged CPU: 0.000576038767%
User CPU: 0.000012947793%
CPU Cycle count /sec: 19,383
Module memory size: 652 KB
msvcr90.dll

Total CPU: 0.000438314465%
Privileged CPU: 0.000170916947%
User CPU: 0.000267397519%
CPU Cycle count /sec: 9,563
Module memory size: 652 KB
ntdll.dll

Total CPU: 0.000398593954%
Privileged CPU: 0.000380324500%
User CPU: 0.000018269454%
CPU Cycle count /sec: 12,651
Module memory size: 1.23 MB
ntdll.dll

Total CPU: 0.000235477880%
Privileged CPU: 0.000156281749%
User CPU: 0.000079196131%
CPU Cycle count /sec: 19,424
Module memory size: 1.23 MB
wow64cpu.dll

Total CPU: 0.000162143014%
Privileged CPU: 0.000044857536%
User CPU: 0.000117285477%
CPU Cycle count /sec: 13,404
Module memory size: 32 KB
winmm.dll

Total CPU: 0.000159645969%
Privileged CPU: 0.000000000000%
User CPU: 0.000159645969%
Module memory size: 180 KB
ntdll.dll

Total CPU: 0.000147040790%
Privileged CPU: 0.000098018054%
User CPU: 0.000049022736%
CPU Cycle count /sec: 21,126
Module memory size: 1.67 MB
winmm.dll

Total CPU: 0.000141498640%
Privileged CPU: 0.000035477743%
User CPU: 0.000106020897%
CPU Cycle count /sec: 2,824
Module memory size: 200 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 64-bit
System Tray: Yes
Parent Processes
Child Process
Process Commands
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
"C:\Program Files\AVAST Software\Avast\AvastUI.exe"
Startup files (all users) run details
Name: avast5
Command: C:\Program Files1\ALWILS~1\Avast5\avastUI.exe /nogui
Scheduled task details
Name: \{BE644B67-0FC9-4E09-8921-3C92C4187F59}
Network connectivity
TCP: yh-in-f139.1e100.net on port 61848
TCP: yh-in-f113.1e100.net on port 61395
TCP: ye-in-f139.1e100.net on port 2516
TCP: ye-in-f139.1e100.net on port 62294
TCP: sin04s02-in-f3.1e100.net on port 49238
TCP: sin04s01-in-f9.1e100.net on port 49601
TCP: par03s03-in-f0.1e100.net on port 49742
TCP: par03s02-in-f7.1e100.net on port 49297
TCP: ord08s08-in-f9.1e100.net on port 49173
TCP: nuq04s19-in-f2.1e100.net on port 53603
TCP: ni-in-f138.1e100.net on port 49444
TCP: lhr08s01-in-f9.1e100.net on port 49207
Windows Firewall allowed program: Yes
Image hashes
MD5: 3f11b20d12d89365d7721bdc860ce5f0
SHA-1: ee9833d15410cad2146f6e831f591942aa9b5e2f
SHA-256: 9f6f8c0f1d39eebb23e0d6e062f3b57fbc703330300b5edb64ab1c51b859e56b
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++ 9.0
File packed: No
Import Table
aavmrpch.dll

AavmRpcRunSystemComponent
AavmRpcCreateBinding
AavmRpcDestroyBinding
AavmRpcRunComponent
advapi32.dll

CloseServiceHandle
RegQueryValueExA
IsTextUnicode
AllocateAndInitializeSid
AddAccessAllowedAce
InitializeAcl
GetLengthSid
OpenThreadToken
EqualSid
GetTokenInformation
OpenProcessToken
RegEnumKeyExW
RegOpenKeyW
RegEnumValueW
OpenServiceW
OpenSCManagerW
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
FreeSid
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
SetEntriesInAclW
RegOpenKeyExA
RegSetValueExW
RegDeleteValueW
ashbase.dll

ashtask.dll

aswcmnbs.dll

fsGetAvastDataPath
fsGetAvastLogPath
fsGetAvastSumpPath
secPreventHookDllInjection
secCreateSharedEvent
secOpenSharedEvent
iniGetPrivateProfileString
fsGetAvastProgramPath
secCreateSharedMutex
fsGetAvastTempFileName
iniGetPrivateProfileInt
iniWritePrivateProfileInt
iniWritePrivateProfileString
cmnbFree
cmnbInit
aswcmnis.dll

cyphSimpleCode
inflateInit_
inflate
inflateEnd
deflateEnd
deflate
inflateReset
deflateReset
deflateInit2_
crcGenerate32c
mdaGenerate
aswcmnos.dll

dep_osIsWow64
dep_fsGetFileSizeHandle
dep_fsReadFile
dep_fsCloseFile
dep_osIsWinVistaOrBetter
dep_osIsWinXPOrBetter
dep_osIsWin64
dep_secGetPublicSecurity
dep_fsEnableWow64FsRedirection
dep_fsWriteFile
dep_fsExistFile
dep_fsRemoveFolderRecursive
dep_fsDeleteFileX
dep_fsOpenFileX
dep_osIsWin8OrBetter
dep_fsCopyFile
dep_procGetFileName
aswlog.dll

aswproperty.dll

aswGetPropertyInt
aswGetProperty
aswPropertyFreeLibrary
aswGetAvastPropertyInt
aswPropertyInitLibrary
aswGetIntFromCache
aswGetStrFromCache
aswSetAvastProperty
aswGetAvastProperty
aswSetPropertyInt
aswSetProperty
comctl32.dll

_TrackMouseEvent
ImageList_Draw
ImageList_GetImageInfo
ImageList_DrawEx
ImageList_GetIconSize
comdlg32.dll

crypt32.dll

CertCreateCertificateContext
CertFreeCertificateContext
cryptui.dll

CryptUIDlgViewCertificateW
dnsapi.dll

DnsRecordListFree
DnsQuery_W
DnsQuery_A
gdi32.dll

SetWindowOrgEx
SetLayout
BitBlt
SetViewportOrgEx
GetTextMetricsA
SetWindowExtEx
GetWindowExtEx
SetTextColor
DeleteDC
SetBkColor
GetObjectW
LPtoDP
ExcludeClipRect
CreateCompatibleDC
CreateRectRgnIndirect
DPtoLP
CombineRgn
SetMapMode
CreateCompatibleBitmap
GetMapMode
SaveDC
GetClipBox
SetViewportExtEx
GetViewportExtEx
GetObjectA
GetStockObject
RestoreDC
CreateSolidBrush
DeleteObject
CreateRoundRectRgn
SelectObject
GetDeviceCaps
SetTextAlign
GetTextAlign
GetTextExtentPointW
TextOutA
TextOutW
GetPixel
IntersectClipRect
RectVisible
CreatePen
CreatePatternBrush
GetTextExtentExPointW
Rectangle
SetBkMode
CreateBitmap
SetPixel
Polygon
GetCurrentPositionEx
ExtCreatePen
Polyline
PtVisible
ExtTextOutW
Escape
CreateFontIndirectW
GetCurrentObject
SetBrushOrgEx
CreateDIBPatternBrushPt
CreateDIBSection
StretchBlt
GetDIBits
StretchDIBits
SetStretchBltMode
CreateFontA
EnumFontFamiliesExA
AddFontMemResourceEx
EnumFontFamiliesExW
GetWindowOrgEx
CreateHatchBrush
GetTextExtentPoint32A
GetTextExtentPoint32W
PatBlt
GetDeviceGammaRamp
SetDeviceGammaRamp
GetKerningPairsA
GetGlyphOutlineW
AddFontResourceExW
kernel32.dll

GetLocaleInfoA
TlsGetValue
GetCurrentProcess
QueryPerformanceCounter
QueryPerformanceFrequency
InterlockedIncrement
DeleteCriticalSection
FreeLibrary
GetProcAddress
LoadLibraryA
GetSystemDirectoryA
GetLocaleInfoW
IsBadReadPtr
MulDiv
FlushFileBuffers
SetEvent
GetProcessHeap
TlsSetValue
GetExitCodeProcess
CallNamedPipeW
CreateProcessW
HeapFree
WriteFile
ReadFile
ConnectNamedPipe
TerminateThread
WaitForSingleObject
ExitThread
GetPrivateProfileStringW
GetSystemTime
LocalFree
CreateDirectoryW
LocalAlloc
GetUserDefaultLCID
VirtualFree
ExpandEnvironmentStringsA
Process32NextW
Process32FirstW
LCMapStringW
FindResourceExW
LocalUnlock
CreateFileMappingA
FlushViewOfFile
SetEndOfFile
UnmapViewOfFile
MapViewOfFile
GetThreadLocale
GetVersionExA
GlobalAlloc
SetThreadLocale
GetCPInfo
GetCurrencyFormatW
DeleteFileA
MoveFileA
SetLastError
GetShortPathNameA
CreateEventA
VirtualAlloc
GetVersionExW
DeviceIoControl
CreateFileW
GetDiskFreeSpaceExW
GetVolumeInformationW
GetDriveTypeW
GetLogicalDrives
Sleep
GetLastError
FileTimeToLocalFileTime
FileTimeToSystemTime
GetTimeFormatW
GetDateFormatW
CreateThread
CloseHandle
InitializeCriticalSection
GetACP
EnterCriticalSection
LeaveCriticalSection
WideCharToMultiByte
MultiByteToWideChar
GetTickCount
DeleteFileW
GetTempFileNameW
GetTempPathW
HeapAlloc
WaitForMultipleObjects
InterlockedExchange
InitializeCriticalSectionAndSpinCount
LoadLibraryW
OpenEventW
TerminateProcess
ExitProcess
GetPrivateProfileIntW
GetModuleFileNameW
ExpandEnvironmentStringsW
GetCurrentThreadId
GetCommandLineW
GetCurrentProcessId
CopyFileW
GlobalLock
GlobalUnlock
SetThreadPriority
GetSystemInfo
WaitNamedPipeW
LoadLibraryExW
GetShortPathNameW
FindFirstFileW
FindNextFileW
FindClose
GetSystemDirectoryW
GetWindowsDirectoryW
CreateEventW
GetNumberFormatW
GetFileAttributesW
GetLocalTime
SetFilePointer
GetFileSize
SystemTimeToFileTime
GetSystemTimeAsFileTime
InterlockedDecrement
DisconnectNamedPipe
GetUserDefaultLangID
CreateIoCompletionPort
CreateNamedPipeW
GetQueuedCompletionStatus
GetTempFileNameA
TlsAlloc
GetTempPathA
FindResourceA
FindResourceW
LoadResource
SizeofResource
LockResource
GetModuleHandleW
GetStringTypeA
GetStringTypeW
ReleaseMutex
lstrcmpiW
lstrcmpW
GetExitCodeThread
CreateToolhelp32Snapshot
OutputDebugStringW
OpenProcess
GetCurrentThread
RaiseException
InterlockedCompareExchange
GetStartupInfoW
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
SetProcessWorkingSetSize
DllMain
GetVersion
CreateMutexW
MoveFileExW
ResumeThread
WritePrivateProfileStringW
mfc90u.dll
msimg32.dll

msvcp90.dll
msvcr90.dll
ole32.dll

CoCreateGuid
CoTaskMemFree
StringFromCLSID
CoInitialize
CoCreateInstance
CoUninitialize
StringFromGUID2
CoInitializeEx
CLSIDFromString
oleacc.dll

CreateStdAccessibleObject
AccessibleObjectFromWindow
LresultFromObject
psapi.dll

GetModuleFileNameExW
EnumProcessModules
EnumProcesses
rpcrt4.dll

RpcBindingFromStringBindingW
RpcStringFreeW
RpcBindingFree
RpcStringBindingComposeW
UuidCreate
NdrConformantArrayMarshall
RpcRaiseException
NdrClientInitializeNew
NdrConformantArrayBufferSize
NdrFreeBuffer
NdrGetBuffer
NdrConformantStringBufferSize
NdrConformantArrayUnmarshall
NdrSendReceive
NdrConvert
NdrConformantStringMarshall
RpcBindingServerFromClient
RpcBindingToStringBindingW
RpcStringBindingParseW
I_RpcGetBuffer
NdrAllocate
NdrServerInitializeNew
NdrConformantStringUnmarshall
NdrPointerFree
RpcAsyncInitializeHandle
RpcBindingSetAuthInfoExA
RpcAsyncCancelCall
RpcBindingFromStringBindingA
RpcStringBindingComposeA
RpcAsyncCompleteCall
NdrAsyncClientCall
NdrClientCall2
RpcStringFreeA
shell32.dll

SHGetPathFromIDListW
SHGetFileInfoW
SHChangeNotify
SHGetDesktopFolder
SHGetMalloc
SHGetSpecialFolderLocation
Shell_NotifyIconW
SHBrowseForFolderW
ShellExecuteW
ShellExecuteExW
SHGetFolderPathW
SHGetSpecialFolderPathW
shlwapi.dll

PathFileExistsW
PathCompactPathW
ColorHLSToRGB
ColorRGBToHLS
PathIsDirectoryW
UrlCombineA
urlmon.dll

user32.dll
version.dll

VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
winhttp.dll

WinHttpSetOption
WinHttpSendRequest
WinHttpConnect
WinHttpCloseHandle
WinHttpSetTimeouts
WinHttpOpen
WinHttpOpenRequest
WinHttpReadData
WinHttpReceiveResponse
WinHttpQueryOption
WinHttpQueryHeaders
wininet.dll

InternetReadFile
InternetCombineUrlA
HttpOpenRequestA
InternetGetLastResponseInfoA
InternetOpenA
InternetCloseHandle
InternetQueryOptionA
InternetConnectA
HttpQueryInfoA
HttpSendRequestA
InternetCrackUrlW
InternetSetOptionA
InternetCanonicalizeUrlW
InternetSetOptionW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
InternetOpenW
winmm.dll

timeSetEvent
timeKillEvent
timeGetTime
timeGetDevCaps
PlaySoundA