Author Topic: Avast scan says AvastSvc.exe is PUP ?!?  (Read 2908 times)

0 Members and 1 Guest are viewing this topic.

PortalGuy

  • Guest
Avast scan says AvastSvc.exe is PUP ?!?
« on: February 07, 2013, 01:12:04 PM »
So is this the 'real' avastsvc.exe, or a fake?

The scan reports that that its PID is 1636, and if I do a netstat I see that PID 1636 is talking to Alexa on several high ports.  Good thing I have Alexa and other corporate spyware sites pointing to 127.0.0.1 in my hosts file.

Looked up the equivalent of kill -9 in Windows Vista, it is KILLTASK.  Trying to kill 1636 gives me an 'access denied' even in an elevated session.  Thanks Microsoft: you corporations always seem to stick together.

Please advise.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #1 on: February 07, 2013, 01:27:43 PM »
PUP is not a virus, but Possible Unwanted Program

but yes strange it would say that about its own file....
Test suspicious files at virustotal.com

PortalGuy

  • Guest
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #2 on: February 07, 2013, 07:48:10 PM »
Thanks Pondus, I searched my hard disc for any instance of AvastSvc.exe, no such file. 

Is this an Avast asset, or just some 3rd party product that communicates with Alexa, and named to look like a trusted program?

Cheers,
Robert

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #3 on: February 07, 2013, 07:52:24 PM »
PID is 1636  you have set Avast to scan memory.. If you do that expect the unexpected

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89334
  • No support PMs thanks
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #4 on: February 07, 2013, 07:56:00 PM »
What is strange is that avast doesn't scan for PUPs by default (mainly because of the confusion that it causes I believe), so you appear to have changed your shield/scan settings or as essexboy mentions elected to have avast scan memory in a custom scan.

The avastSvc.exe is the main avast process, controlling the shields, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

PortalGuy

  • Guest
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #5 on: February 07, 2013, 08:21:27 PM »
So, assuming this instance of AvastSvc.exe is the legitimate one... here's the questions:

Avast sends data to Alexa? 

What data?   (E.g. url prefetch & scanning, site ratings)

Did you know that this allows Alexa to do data mining on my visited web sites and sent data?

Why take over so many high ports?

How can I turn this off?

Please advise.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #6 on: February 07, 2013, 08:32:49 PM »
Avast is not sending data to alexa.  Avast service controls all out going data through a proxy  to scan for any malicious activity hence if IE was doing that it would appear to be coming through Avast as as it is scanning it.  So you need to look at the other net fronting programmes to determine what is doing it.

The only data sent to avast by the programme is details of suspicious files/websites but, only if you opted in to community IQ 

There is a good explanation of that if I can relocate the link

PortalGuy

  • Guest
Re: Avast scan says AvastSvc.exe is PUP ?!?
« Reply #7 on: February 07, 2013, 10:21:03 PM »
Thank you kindly, Essexboy; I'm here to learn and learning a lot.

Will check on those items, and update the thread with what I find....

Avast is not sending data to alexa.  Avast service controls all out going data through a proxy  to scan for any malicious activity hence if IE was doing that it would appear to be coming through Avast as as it is scanning it.  So you need to look at the other net fronting programmes to determine what is doing it.

The only data sent to avast by the programme is details of suspicious files/websites but, only if you opted in to community IQ 

There is a good explanation of that if I can relocate the link