Author Topic: AvastSvc.exe 8min after Boot  (Read 5751 times)

0 Members and 1 Guest are viewing this topic.

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
AvastSvc.exe 8min after Boot
« on: March 09, 2021, 09:36:08 PM »
Does anybody know what process or service is running in the file around 8 minutes after boot?  Started having an issue 3 weeks ago with this.  Went away for about for a week or two but came back today.  Re-installation had no effect.  About 8 minutes after booting this file will start to use a huge amount of CPU resources constantly: AvastSvc.exe /runassvc

I tried disabling everything one by one and finally ran Avast in passive mode and after 8 minutes there still was a little CPU usage from this file but it shut down after a few seconds.  Why would there by activity from anything in passive mode?  Turned everything back on, now no problems.  Any clues??

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48564
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: AvastSvc.exe 8min after Boot
« Reply #1 on: March 09, 2021, 09:50:22 PM »
Does anybody know what process or service is running in the file around 8 minutes after boot?  Started having an issue 3 weeks ago with this.  Went away for about for a week or two but came back today.  Re-installation had no effect.  About 8 minutes after booting this file will start to use a huge amount of CPU resources constantly: AvastSvc.exe /runassvc

I tried disabling everything one by one and finally ran Avast in passive mode and after 8 minutes there still was a little CPU usage from this file but it shut down after a few seconds.  Why would there by activity from anything in passive mode?  Turned everything back on, now no problems.  Any clues??
I think it's a rootkit scan that's done 8 min after bootup.




Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #2 on: March 09, 2021, 09:57:31 PM »
I think it's a rootkit scan that's done 8 min after bootup.
I see that this can be disabled in the core shield settings but I already tried disabling each shield individually and then all the shields together and it had no effect.  If it starts doing it again I'll try disabling just the rook kit and see what happens.  Thanks for you help!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: AvastSvc.exe 8min after Boot
« Reply #3 on: March 10, 2021, 12:00:46 AM »
The anti-rootkit scan shouldn't have a great impact on the system, certainly not on mine (as and when I do a system restart). 

Although the time frame 8 minutes after boot falls in line with when the anti-rootkit scan I'm not sure about the AvastSvc.exe /runassvc is directly related to the anti-rootkit scan but simply the path and command to run the service immediately on boot.

"C:\Program Files\AVAST Software\Avast\AvastSvc.exe" /runassvc see attached image, I assume this is where you got this from.

If this is the anti-rootkit scan check these files using notepad (see attached image) I believe these are related to the anti-rootkit scan and see what stats are there, runtime number of files scanned, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #4 on: March 10, 2021, 08:05:34 PM »
The anti-rootkit scan shouldn't have a great impact on the system
Definitely not, something is wrong.  Feels like it's completely loading one of my i7 cores and debilitating the system.  Happened again this morning when I booted up.  Tried disabling the Anti-Rookit scan, restarted and same problem.  So did what I did yesterday and activated passive mode, restarted then no problems.  Re-enabled all protection, restarted and now it's fine.

LOG FILE CONTENT

arpot.log (these are today's entries only)
2021-03-10 11:44:42 AVAVER: 21.1.2449 AR2: 210304 defs: 21030800
2021-03-10 11:44:57 AVAVER: 21.1.2449 AR2: 210309 defs: 21031004
2021-03-10 11:44:58 AVAVER: 21.1.2449 AR2: 210309 defs: 21031004
2021-03-10 12:04:21 AVAVER: 21.1.2449 AR2: 210309 defs: 21031004
2021-03-10 12:25:04 AVAVER: 21.1.2449 AR2: 210309 defs: 21031004
2021-03-10 12:34:52 AR2CFG: 210309
2021-03-10 12:34:52 AR2DEV: Start 1 Driver: 210129

aswAr.log
Avast Antirootkit, version 21.1.2449
Scan started: Wednesday, March 10, 2021 1:07:54 PM
<maybe a few hundred processes and services scanned here>
Scan finished: Wednesday, March 10, 2021 1:07:58 PM
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0

aswAr1.log (this appears to be a record from a scan I did last night)
Avast Antirootkit, version 21.1.2449
[Full] Scan started: Tuesday, March 09, 2021 5:11:36 PM
<Few thousand files scanned here>
Scan finished: Tuesday, March 09, 2021 5:13:24 PM
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0
« Last Edit: March 10, 2021, 08:33:11 PM by jmichaelm »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: AvastSvc.exe 8min after Boot
« Reply #5 on: March 10, 2021, 09:27:48 PM »
Well I was somewhat sceptical that it would be the anti-rootkit scan

I think the contents of the arpot.log reflect the Virus definitions updates as they may or may not include data for the anti-rootkit scanner/service.

The other logs basically only record the last scan or they could get very large.
The aswAr1.log does show a scan of just under two minutes and the aswAr.log only 4 seconds, and I really don't know the difference (in scan/recording) between the two.

Fingers crossed, now that it is more what I would consider normal, no real impact on normal system operations.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #6 on: March 10, 2021, 09:51:57 PM »
Ok when it happens again I'll try to pull the aswAr.log contents right away to see if there is anything more telling.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: AvastSvc.exe 8min after Boot
« Reply #7 on: March 10, 2021, 10:34:03 PM »
Ok when it happens again I'll try to pull the aswAr.log contents right away to see if there is anything more telling.

OK, but I think the log would be the same, if there wasn't a detection, in which case I would have expected Avast to have alerted.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #8 on: March 10, 2021, 11:02:30 PM »
I just want to see if the scan takes longer when the CPU is being taxed constantly because that only shows the last scan which was done after I got it fixed today.
« Last Edit: March 10, 2021, 11:08:36 PM by jmichaelm »

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #9 on: March 11, 2021, 05:05:39 PM »
Yep the issue occurred again this morning and it does appear to be related to the Anti-rookit scan.  Here are the entire contents of my aswAr.log file, the scan starts right at the time the CPU load goes through the roof and even after 4 minutes or more there is no scan completion note in the log:

Avast Antirootkit, version 21.1.2449
Scan started: Thursday, March 11, 2021 9:51:06 AM

Process  [4]
Process C:\Windows\System32\smss.exe [392]
Process C:\Windows\System32\csrss.exe [564]
Process C:\Windows\System32\wininit.exe [624]
Process C:\Windows\System32\csrss.exe [656]
Process C:\Windows\System32\services.exe [680]
Process C:\Windows\System32\lsass.exe [724]
Process C:\Windows\System32\winlogon.exe [732]
Process C:\Windows\System32\lsm.exe [740]
Process C:\Windows\System32\svchost.exe [864]
Process C:\Windows\System32\svchost.exe [940]
Process C:\Windows\System32\svchost.exe [184]
Process C:\Windows\System32\svchost.exe [476]
Process C:\Windows\System32\svchost.exe [820]
Process C:\Windows\System32\svchost.exe [484]
Process C:\Windows\System32\igfxCUIService.exe [1188]
Process C:\Windows\System32\svchost.exe [1240]
Process C:\Program Files\Avast Software\Avast\AvastSvc.exe [1308]
Process C:\Windows\System32\spoolsv.exe [1800]
Process C:\Windows\System32\svchost.exe [1840]
Process C:\Program Files\Avast Software\Avast\aswEngSrv.exe [1072]
Process C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [632]
Process C:\Windows\System32\svchost.exe [2616]
Process C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe [3108]
Process C:\Program Files\Avast Software\Avast\aswidsagent.exe [3148]
Process C:\Windows\System32\WUDFHost.exe [3416]
Process C:\Windows\System32\wbem\unsecapp.exe [3596]
Process C:\Windows\System32\SearchIndexer.exe [3948]
Process C:\Windows\System32\svchost.exe [2704]
Process C:\Windows\System32\svchost.exe [3408]
Process C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [5852]
Process C:\Windows\System32\taskeng.exe [3996]
Process C:\Windows\System32\SearchProtocolHost.exe [4272]
Process C:\Windows\System32\SearchFilterHost.exe [4364]
Process C:\Windows\System32\LogonUI.exe [5112]
Process C:\Windows\System32\LogonUI.exe [6008]

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #10 on: March 11, 2021, 05:14:26 PM »
Rebooted into passive mode, and the scan appears to complete in 4 seconds... and yes the scan is STILL being done despite Avast allegedly being passive mode!

Avast Antirootkit, version 21.1.2449
Scan started: Thursday, March 11, 2021 10:05:07 AM

Service .NET CLR Data [???]
Service .NET CLR Networking [???]
Service .NET CLR Networking 4.0.0.0 [???]
Service .NET Data Provider for Oracle [???]
Service .NET Data Provider for SqlServer [???]
Service .NET Memory Cache 4.0 [???]
Service .NETFramework [???]
Service 1394ohci [C:\Windows\system32\drivers\1394ohci.sys]
Service ACPI [C:\Windows\system32\drivers\ACPI.sys]
Service AcpiPmi [C:\Windows\system32\drivers\acpipmi.sys]
Service Adobe LM Service [C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe]
Service adp94xx [C:\Windows\system32\DRIVERS\adp94xx.sys]
Service adpahci [C:\Windows\system32\DRIVERS\adpahci.sys]
Service adpu320 [C:\Windows\system32\DRIVERS\adpu320.sys]
Service adsi [???]
Service AeLookupSvc [C:\Windows\System32\aelupsvc.dll]
Service AFD [C:\Windows\system32\drivers\afd.sys]
Service agp440 [C:\Windows\system32\drivers\agp440.sys]
Service ALG [C:\Windows\System32\alg.exe]
Service aliide [C:\Windows\system32\drivers\aliide.sys]
Service amdide [C:\Windows\system32\drivers\amdide.sys]
Service AmdK8 [C:\Windows\system32\drivers\amdk8.sys]
Service AmdPPM [C:\Windows\system32\drivers\amdppm.sys]
Service amdsata [C:\Windows\system32\drivers\amdsata.sys]
Service amdsbs [C:\Windows\system32\DRIVERS\amdsbs.sys]
Service amdxata [C:\Windows\system32\drivers\amdxata.sys]
Service AppID [C:\Windows\system32\drivers\appid.sys]
Service AppIDSvc [C:\Windows\System32\appidsvc.dll]
Service Appinfo [C:\Windows\System32\appinfo.dll]
Service AppMgmt [C:\Windows\System32\appmgmts.dll]
Service arc [C:\Windows\system32\DRIVERS\arc.sys]
Service arcsas [C:\Windows\system32\DRIVERS\arcsas.sys]
Service asComSvc [C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe]
Service AsIO [C:\Windows\SysWow64\drivers\AsIO.sys]
Service ASP.NET [???]
Service ASP.NET_4.0.30319 [???]
Service aspnet_state [C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe]
Service aswArDisk [C:\Windows\system32\drivers\aswArDisk.sys]
Service aswArPot [C:\Windows\system32\drivers\aswArPot.sys]
Service aswbdisk [???]
<ect... ect>
Scan finished: Thursday, March 11, 2021 10:05:11 AM
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0

What I think is interesting is now there are 3 questions marks in the [] instead of numbers (which this forum changes to smiley faces lol...) should be time in milliseconds right??
« Last Edit: March 11, 2021, 05:16:07 PM by jmichaelm »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: AvastSvc.exe 8min after Boot
« Reply #11 on: March 11, 2021, 05:25:57 PM »
Well I would say that the anti-rootkit scan like other on-demand scans wouldn't be prevented from running whilst in passive mode.
In roughly the same way as when you installed Avast, then MS Defender is disabled/passive (by default), but it can still run periodic scans.

In passive mode (not that I ever use it) I guess that you still have the avast tray icon displayed ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #12 on: March 11, 2021, 07:14:52 PM »
In passive mode (not that I ever use it) I guess that you still have the avast tray icon displayed ?
Yes that's correct.  As I understand it passive mode is supposed to shut off all real time features and enable Avast to be used solely for manual scans... and if disabling rook kit detection from the core shield won't disable it, where does this leave me?  At this point not really sure what to do other than uninstall it.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48564
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: AvastSvc.exe 8min after Boot
« Reply #13 on: March 11, 2021, 07:33:39 PM »
In passive mode (not that I ever use it) I guess that you still have the avast tray icon displayed ?
Yes that's correct.  As I understand it passive mode is supposed to shut off all real time features and enable Avast to be used solely for manual scans... and if disabling rook kit detection from the core shield won't disable it, where does this leave me?  At this point not really sure what to do other than uninstall it.
Reported to Avast. Let's see if that helps to get an answer.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline jmichaelm

  • Newbie
  • *
  • Posts: 15
Re: AvastSvc.exe 8min after Boot
« Reply #14 on: March 11, 2021, 07:41:13 PM »
Reported to Avast. Let's see if that helps to get an answer.
Thank You!