Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4, 8, 1367, 0 33.33%
4, 8, 1351, 0 66.67%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
aavm4h.dll
AavmCreateDispBinding, AavmGetInteractiveSessionId, MyAavmGuiProviderChange, AavmSetShutdownState, AavmIsFileSignedByTrustedPublisherW, AavmWhsInitLib, AavmCreateDefTasksAndRunDefault, AavmStop, DeinitAavmGui, AavmSetDataRefreshRate, InitAavmGui, AavmWhsCreateNotification, AavmDestroyDispBinding, AavmRunConsentApp, AavmPwdCheck, AavmGetVpsInfo, AavmInfoMessageCreate, AavmRegisterIniChangeNotification, AavmUpdateWscStatus, AavmStart, AavmWhsFreeLib
advapi32.dll
OpenEventLogA, RegQueryValueExA, CloseEventLog, ReadEventLogA, GetOldestEventLogRecord, RegSetValueExA, RegCloseKey, RegOpenKeyExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegCreateKeyExA
ashbase.dll
_basScheduleBts@4, _basGetProfileInt@12, _basPlaySound@4, _basLoadLanguage@4, _basGetProfileStringA@20, _basLogEvent@24, _basInitScheduler@0, _notInit@0, _notAddEvent@12, _basLoadStorage@0, _basAddSchedulerEvent@24, _basGetErrorType@4, _notRemEvent@4, _notFree@0, _basFreeStorage@4, _basFreeScheduler@0, _basStopThread@4, _basRemSchedulerEvent@4, _strDecode@12, _basResPwdCheck@4, _basValidatePath@8, _basFreeLibrary@0, _basGetLanguagePath@0, _basU2A@12, _basGetLanguage@0, _basIsCurrCodePageRTL@0, _basCreatePath@16, _basInitThreadLocale@0, _notEvent@4, _basGetErrorString@12, _basGetDWORDValue@12, _basInitLibrary@4, _basWriteProfileStringA@12, _basMigrateStorage@0, _basEmptyAvastTempFolder@8, _basGetNetUser@0, _basA2U@12, _basEncodeFileToSubmit@28, _basProductInfo@0, _basExecuteAndWait@8, _basProductInfoFilesOnly@0, _basVPS2Label@24, _licValidateKey@12, _basGetProcAddress@8
ashtask.dll
_tskLaunchSyncer@16, _tskCheckVPSTime@4, _FreeARList@4, _ARConstructStringFromList@4, _tskFreeResultFileName@12, _tskARDeleteFile@8, _tskUpdateStatistics@4, _tskDoAntiRootkitScan@16, _tskFreeAntirootkit@4, _tskGetResultFileName@16, _ARConstructListFromString@8
aswcmnb.dll
fsGetAvastProgramPath, fsGetAvastIntegrityPath, cmnbFree, fsGetAvastSumpPath, fsGetAvastDataPath
aswcmnos.dll
dep_fsEnableWow64FsRedirection, dep_fsWriteFile, fsGetRootNameS, dep_fsReadFile, dep_fsOpenFileX, dep_fsDeleteFile, dep_fsExistFile, dep_memCreateSharedMemory, dep_osGetID, dep_memCloseSharedMemory, dep_osIsWow64, dep_fsCloseFile, dep_secSetPrivilege
aswcmns.dll
svcServiceStart, cyphSimpleCode, DSA_FileVerify, mdaGenerate
aswengin.dll
avscanGetVpsInformation, avfilesProcessCleaningLog, RevertNoGuiBoot, avworkInitialize, avscanGetVirusDetails, avworkClose, avfilesScanReal
aswidle.dll
IdleUIInit, IdleUIGetLastInputTime
aswinteg.dll
aswintegGetRecordTimes, aswintegAddRecord, aswintegCompareRecord, aswintegRemove, aswintegFlush, aswintegClose, aswintegInitialize
kernel32.dll
GetStartupInfoA, ExitProcess, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, LocalFree, LocalAlloc, GetModuleFileNameA, GetSystemInfo, GetSystemDirectoryA, CopyFileA, GetFileSize, WriteFile, ReadFile, SetFilePointer, FileTimeToLocalFileTime, FileTimeToSystemTime, lstrlenA, WideCharToMultiByte, MultiByteToWideChar, GetVolumeInformationA, GetDiskFreeSpaceA, OpenProcess, GetProcessHeap, HeapAlloc, HeapFree, ReadProcessMemory, GetExitCodeProcess, SetPriorityClass, GetLogicalDriveStringsA, GetDriveTypeA, RaiseException, InterlockedExchange, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, InterlockedDecrement, DeleteCriticalSection, WaitForMultipleObjects, ResetEvent, ReleaseMutex, CreateMutexA, ResumeThread, InterlockedIncrement, GetVersionExA, LoadLibraryA, SetLastError, CreateEventA, GetCurrentThread, SetThreadPriority, GetFileAttributesA, CreateThread, GetProcAddress, GetPrivateProfileStringW, GetFileAttributesW, DeleteFileW, SetEvent, GetModuleHandleA, DisableThreadLibraryCalls, TerminateThread, FindFirstFileA, DeleteFileA, FindClose, OpenEventA, LoadLibraryExA, FreeLibrary, GetLastError, GetCurrentThreadId, GetTickCount, GetPrivateProfileIntA, GetPrivateProfileStringA, GetCurrentProcess, SetProcessWorkingSetSize, CreateFileA, DeviceIoControl, CloseHandle, WaitForSingleObject, Sleep, FindNextFileA
msvcp71.dll
DllMain
msvcr71.dll
DllMain
rpcrt4.dll
RpcServerUnregisterIf, RpcBindingVectorFree, RpcEpUnregister, RpcEpRegisterA, RpcServerInqBindings, RpcServerRegisterIf, RpcServerUseProtseqA, RpcServerUseProtseqEpA, I_RpcGetBuffer, NdrAllocate, NdrServerInitializeNew, NdrPointerFree, NdrConformantStringUnmarshall, RpcBindingFree, RpcStringFreeA, RpcStringBindingParseA, RpcBindingToStringBindingA, RpcBindingServerFromClient, RpcMgmtStopServerListening, NdrConformantArrayBufferSize, NdrConformantArrayMarshall, NdrConformantArrayUnmarshall, NdrConformantStringBufferSize, NdrConformantStringMarshall, RpcRaiseException, NdrClientInitializeNew, NdrGetBuffer, NdrSendReceive, NdrConvert, NdrFreeBuffer
user32.dll
MessageBoxA, PostMessageA, LoadStringW, GetKeyState, CheckMenuRadioItem, CheckMenuItem, GetMessageA, TranslateMessage, KillTimer, DestroyWindow, RegisterClassA, CreateWindowExA, RegisterWindowMessageA, DestroyIcon, LoadIconA, DefWindowProcA, GetSubMenu, RemoveMenu, GetMenuStringA, SetMenuItemInfoA, GetCursorPos, SetForegroundWindow, TrackPopupMenu, DestroyMenu, LoadStringA, SystemParametersInfoA, OpenDesktopA, CloseDesktop, SetTimer, ExitWindowsEx, wsprintfA, PeekMessageA, DispatchMessageA, MsgWaitForMultipleObjects, LoadMenuA
Export table
_iwdGetStatus@4
_iwdStart@4
_iwdStop@0
_S_AVAST4_MEMORY_ID

ashserv.exe

avast! Antivirus by ALWIL Software (Signed)

Remove ashserv.exe
Version:   4, 8, 1367, 0
MD5:   0aaf6b848185899cf76ae04e62eab3d2
SHA1:   38efc4e5adbb8d36bc51466f58e2c31650bf5d7f
SHA256:   7349517c319d26be8f9382e3995d4130dc8f6c28499b4ae25ba05af13c4de638

What is ashserv.exe?

avast! antivirus service is part of Avast Antivirus, a kernel based certified antivirus engine with protection against well-known network worms and real-time protection against viruses and other malware threats. Scans files as they run on your computer to keep viruses from being able to execute. Avast includes streaming updates from the cloud in addition to daily virus database updates. Throughout the day, AVAST streams updates to users, giving them faster warnings about new malware.

About ashserv.exe (from ALWIL Software)

Avast Antivirus is for individuals or companies that want customizable computer security that will integrate easily with an existing firewall. It has all the features of Avast Free Antivirus, plus a c

DetailsDetails

File name:ashserv.exe
Publisher:ALWIL Software
Product name:avast! Antivirus
Description:avast! antivirus service
Typical file path:C:\Program Files\alwil software\avast4\ashserv.exe
Original name:aswServ.exe
File version:4, 8, 1367, 0
Product version:4, 8, 0, 0
Size:135.43 KB (138,680 bytes)
Certificate
Issued to:ALWIL Software
Authority (CA):VeriSign
Effective date:Saturday, December 6, 2008
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 7.1
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
AVAST Software
7% remove
Avast! Antivirus is a full-featured antivirus and anti-spyware scanning and removal product that offers a web-reputation browser extension as well as virtualization technology. Accurate threat updates via Avast updates are delivered automatically using PUSH update technology.

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'avast! Antivirus'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00169382%
0.028634%
Kernel CPU:0.00103965%
0.013761%
User CPU:0.00065416%
0.014873%
Kernel CPU time:3,713 ms/min
100,923,805ms/min
Context switches:3/sec
284/sec
Memory
Private memory:85.81 MB
21.59 MB
Private (maximum):41.25 MB
Private (minimum):2.21 MB
Non-paged memory:85.81 MB
21.59 MB
Virtual memory:303.76 MB
140.96 MB
Virtual memory (peak):413.64 MB
169.69 MB
Working set:3.73 MB
18.61 MB
Working set (peak):321.89 MB
37.95 MB
Resource allocations
Threads:33
12
Handles:363
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\alwil software\avast4\ashserv.exe"
Owner:SYSTEM
Windows Service
Service name:avast! Antivirus
Description:“Gère et implémente les services de l'antivirus avast! pour cet ordinateur. Ceci inclut la protection résidente, la zone de quarantaine et le planificateur.”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
sechost.dll
Total CPU:0.02072095%
0.272967%
Kernel CPU:0.00109297%
0.107585%
User CPU:0.01962798%
0.165382%
CPU cycles:512,883/sec
5,741,424/sec
Memory:100 KB
1.16 MB
msvcr71.dll (Microsoft Visual Studio .NET by Microsoft)
Total CPU:0.01029218%
Kernel CPU:0.00063758%
User CPU:0.00965460%
CPU cycles:262,846/sec
Memory:344 KB
aavm4h.dll (avast! Antivirus by ALWIL Software)
Total CPU:0.00502587%
Kernel CPU:0.00083511%
User CPU:0.00419076%
CPU cycles:127,237/sec
Memory:224 KB
ashServ.exe (main module)
Total CPU:0.00063772%
Kernel CPU:0.00028849%
User CPU:0.00034923%
CPU cycles:23,857/sec
Memory:136 KB
ntdll.dll
Total CPU:0.00033763%
Kernel CPU:0.00033763%
User CPU:0.00000000%
CPU cycles:1,647/sec
Memory:1.23 MB
asw6ldr.dll (avast! antivirus by ALWIL Software)
Total CPU:0.00013864%
Kernel CPU:0.00000000%
User CPU:0.00013864%
CPU cycles:3,302/sec
Memory:36 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 33.33%
Windows 7 Ultimate 33.33%
Windows 7 Professional 33.33%

Distribution by countryDistribution by country

MA installs about 33.33% of avast! Antivirus .

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE