Author Topic: AvastSvc.exe connecting to odd sites  (Read 4937 times)

0 Members and 1 Guest are viewing this topic.

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
AvastSvc.exe connecting to odd sites
« on: July 27, 2018, 01:07:23 AM »
Hi guys,

while using Windows' Resource Monitor I noticed today (for the first time) that AvastSvc.exe connected to a site called "ntp.candystore.at", I've never seen it do that before. Also a couple of weeks ago I've seen it connect to another site called "manage.mediainvent.at", on at least 2 different days.

Since I live in Austria and .at is the top level domain of Austrian sites, I'm assuming it's some sort of regional (possibly advertising related?) thing, but I wanted to make sure so I'll ask you guys. Especially the new one, candystore.at, sounds kinda weird to me and I couldn't find any info on that site. Is Avast supposed to connect to those sites or is something funny going on?

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
Re: AvastSvc.exe connecting to odd sites
« Reply #1 on: August 01, 2018, 07:34:38 PM »
Can nobody tell me what that is all about? oO
It made a very weird impression on me, and not getting any answers is not exactly reassuring.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48524
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: AvastSvc.exe connecting to odd sites
« Reply #2 on: August 01, 2018, 10:38:52 PM »
Reported to Avast. Hope that helps.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: AvastSvc.exe connecting to odd sites
« Reply #3 on: August 03, 2018, 08:20:11 AM »
Hi, Avast acts as a local proxy, so all traffic runs trough avastsvc.exe, that's normal.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
Re: AvastSvc.exe connecting to odd sites
« Reply #4 on: August 06, 2018, 10:46:27 PM »
@bob3160
So when will they be able to tell me what exactly that is? Or is Asyn's post the official answer already?

@Asyn
That may be, however those connections happened when I wasn't even using any browser or other internet-related program. Actually it looks like all 3 connections happened right after pc startup, without me even touching any program aside from Task Manager & Resource Monitor. Also when I connect to websites normally, it never says AvastSvc.exe in Resource Monitor, it always shows the name of the program I'm using, e.g. Chrome, Firefox, Steam or whatever, so that explanation doesn't make sense.
« Last Edit: August 06, 2018, 10:51:01 PM by Weiku »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48524
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: AvastSvc.exe connecting to odd sites
« Reply #5 on: August 07, 2018, 02:09:06 AM »
@bob3160
So when will they be able to tell me what exactly that is? Or is Asyn's post the official answer already?

@Asyn
That may be, however those connections happened when I wasn't even using any browser or other internet-related program. Actually it looks like all 3 connections happened right after pc startup, without me even touching any program aside from Task Manager & Resource Monitor. Also when I connect to websites normally, it never says AvastSvc.exe in Resource Monitor, it always shows the name of the program I'm using, e.g. Chrome, Firefox, Steam or whatever, so that explanation doesn't make sense.
I don't know about official since Asyn like the rest of us are Avast users just like you. It is factual.
You seem to forget about the numerous updates that occur throughout the day. There are many of them.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
Re: AvastSvc.exe connecting to odd sites
« Reply #6 on: August 07, 2018, 09:53:16 PM »
Of course there are updates all the time, but sites like manage.mediainvent.at and especially candystore.at don't sound like sites that deliver updates at all. Those usually come either from the developer's own site, or from some well known cdn, like those from Microsoft, Amazon, Cloudflare etc.

I couldn't find anything about those weird sites, so I'd really want to know why Avast has connected to them. It's especially weird that both of them end in my country's top level domain.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: AvastSvc.exe connecting to odd sites
« Reply #7 on: August 10, 2018, 09:39:55 AM »
I couldn't find anything about those weird sites, so I'd really want to know why Avast has connected to them. It's especially weird that both of them end in my country's top level domain.
Hi again, same country and I've never ever seen such connections here.
Sounds like something on your system is phoning home (program, ads, etc.).
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
Re: AvastSvc.exe connecting to odd sites
« Reply #8 on: August 10, 2018, 07:13:31 PM »
@Asyn
So far I've only seen those connections on 3 occasions over the course of a few months, and always shortly after PC startup if I remember correctly. If it was a program phoning home, why would it say AvastSvc.exe? Because as I already mentioned, whatever program connects to the internet, Resource Monitor always shows its real name, be it a Browser, Steam or a game. Why would it say AvastSvc.exe in this particular case if it wasn't actually Avast? It just doesn't make sense.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: AvastSvc.exe connecting to odd sites
« Reply #9 on: August 10, 2018, 07:40:51 PM »
Again, that's the local proxy (web/network shield), it doesn't connect anywhere on its own.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
Re: AvastSvc.exe connecting to odd sites
« Reply #10 on: August 21, 2018, 08:46:38 PM »
But you're not answering the actual question here. When I connect to an address using Firefox, it says firefox.exe, using Chrome it says chrome.exe, using Steam it says steam.exe, why would some random other program say AvastSvc.exe? If ALL my internet traffic runs through some Avast proxy as you said, everything should be saying AvastSvc.exe, including my browsers, Steam and instant messaging programs, but that is not the case as I said.

Offline Weiku

  • Jr. Member
  • **
  • Posts: 45
Re: AvastSvc.exe connecting to odd sites
« Reply #11 on: November 08, 2018, 08:37:14 PM »
I just figured out that those connections aren't just happening sometimes, they happen after every single PC boot. I didn't realize that at first because you have to open Resource Monitor immediately after booting to be able to see it, if you're even a second too slow, it doesn't show up on the list.

It has been connecting to a bunch of other sites too, always just sending a small amount of Bytes/s, never saw it receiving anything, and then disappears pretty fast. I'll list some of the sites below.

This is the only instance of AvastSvc.exe that connects to weird sites that make no sense to me, all other connections of any programs that I use always use the name of the program itself to connect to servers, never AvastSvc, so I don't understand the "proxy" explanation at all.

Is there a way to find out what exactly is starting this process at every PC startup?



Here are some of the sites it has been connecting to, aside from the ones I already mentioned:
ntp.vives.be
time2.mediainvent.at
fetchmail.mediainvent.at
ts1.aco.net
time.conova.com
ntp.kennisdelen.net
service01.vie.xpirio.net
ntp.cnh.at
extern4.nemox.net
server.samoylyk.net
kashra.auction
mail.somenet.org
tgr1.komitex.net
orfeo.duckcorp.org
78.41.116.113
185.9.19.142



Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48524
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: AvastSvc.exe connecting to odd sites
« Reply #12 on: November 09, 2018, 12:54:35 AM »
Reported to Avast.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet