Author Topic: Why Is AvastUI.exe Dialing Out To India?  (Read 10425 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67195
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #16 on: September 19, 2011, 02:41:45 AM »
The best things in life are free.

Offline MartinZ

  • Advanced Poster
  • **
  • Posts: 1057
  • Product Manager
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #17 on: September 19, 2011, 10:12:18 AM »
Registration, expiration warnings...

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #18 on: September 19, 2011, 10:18:23 AM »
Registration, expiration warnings...

Thanks Martin..!
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

DonZ63

  • Guest
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #19 on: September 19, 2011, 12:56:59 PM »
The only baseline software reason I can determine avastui.exe is used for is the WebRep feature. I don't use that feature.

I personally detest "cloud" concepts and processing. To me it equates to giving vendors a built-in spyware backdoor; something by the way that MS has built into their OSes since day one. The risks of clould compting far outweight its benefits.

As far as my situation goes, I could live with the Avast advertising but not when DNS resolution is to questionable sources.

Also closely look at the WhoIs data from my original screen shot. You will notice that the Indian city mentioned is Bombay. Has that city not been named Mumbai for sometime?   

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #20 on: September 19, 2011, 01:16:23 PM »
The only baseline software reason I can determine avastui.exe is used for is the WebRep feature.

WebRep doesn't need avastui, afaik.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #21 on: September 19, 2011, 02:50:39 PM »
The only baseline software reason I can determine avastui.exe is used for is the WebRep feature. I don't use that feature.

The avastUI.exe is the graphical interface and is used by many shields, I believe that the alert windows are also handled by the avastUI so if that isn't running, I guess you wouldn't see the alert window. You could test that by downloading the eicar test file whilst you don't have the avastUI running.

I don't believe it is required by the WebRep to display the WebRep information, as I believe that would be done by the browser as essentially it is a pop-up displaying the data when you click on the webrep icon, etc.

I personally detest "cloud" concepts and processing. To me it equates to giving vendors a built-in spyware backdoor; something by the way that MS has built into their OSes since day one. The risks of clould compting far outweight its benefits.

I guess you are going to have a hard time with that one, as it seems that this is the way most AVs are going. I'm no cloud fan as when your internet is down so to is that element, but it rather depends on how heavily the AV is dependant on cloud processing.

As far as my situation goes, I could live with the Avast advertising but not when DNS resolution is to questionable sources.

Also closely look at the WhoIs data from my original screen shot. You will notice that the Indian city mentioned is Bombay. Has that city not been named Mumbai for sometime?   

The resolution of the IP address isn't something in the control of avast, that is down to whatever application (TCPView) resolves it and the DNS server it used to resolve the IP address.

Get the IP resolution wrong and the whois details taken from the domain name (resolved IP address) will also be wrong. As Vlk said "Reverse DNS lookup is often bogus." perhaps, bogus should be replaced by wrong.

As you found doing a whois on the wrong domain name returns a different IP address, so the problem is one of incorrect resolution of the IP address...
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #22 on: September 19, 2011, 02:55:22 PM »
...I believe that the alert windows are also handled by the avastUI so if that isn't running, I guess you wouldn't see the alert window.

You're wrong about this Dave.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #23 on: September 19, 2011, 02:59:19 PM »
I would add: "That, however, may change at any time, even via a virus definition update".

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #24 on: September 19, 2011, 03:02:33 PM »
I would add: "That, however, may change at any time, even via a virus definition update".

Hope you tell us before. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

DonZ63

  • Guest
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #25 on: September 21, 2011, 12:36:41 AM »
I unblocked avastui.exe and checked to see what it connected to. IP is 75.125.212.75 with no DNS resolution for two connections. This is an iPlanet IP so I assume it's OK. The other two connections are to avast.com, IP 207.218.232.82.

Still would like to know what avastui.exe does. It just stays in a perpetual wait state for port 443.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #26 on: September 21, 2011, 12:44:19 AM »
Yes, avast has a number of hosted servers at planet internet.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

cavehomme

  • Guest
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #27 on: September 21, 2011, 05:37:25 PM »
Why is is that software today always seems to like connecting to the internet for no apparent reason, I must say, on top of all the scareware, logic bombs and shovelware this does seem suspicious.

How do you think that some free products cover their costs? They need advertising, and may be also sell "aggregate" data?!  As for Indian IP addresses, that is one of the "benefits" of the "wonderful" cloud that every one is so hot about these days.

I wish Avast were a bit more upfront on this. I was thinking of buying a few professional licenses for our small office but this now worries me a bit. I will wait for an answer befroe I decide next week.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: Why Is AvastUI.exe Dialing Out To India?
« Reply #28 on: September 21, 2011, 05:48:49 PM »
Please read the thread again... there is no Indian IP - it's just a problem with the reverse lookup on the original poster's machine.