The aswRdr Service.

I’ve been using avast! 4.6 Home Edition on a Win. XP Pro SP2 system for about 2 months and earlier today after starting the computer noticed an Event Viewer entry:

Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 21/02/2006
Time: 3:54:06 PM
User: NT AUTHORITY\SYSTEM
Computer: WDGCR
Description:
The aswRdr service was successfully sent a start control.

As this is the first time I’ve seen such an entry, I’m curious as to why, and for what reason, the aswRdr service was sent a start control.

I assume the service wasn’t actually started as there wasn’t a subsequent Event Viewer entry “the aswRdr service entered the running state”, nor any sign of it in Task Manager. What is the purpose of the aswRdr service?

From a forum search for aswRdr it would appear that it is a device driver for avast not a service as such.

http://forum.avast.com/index.php?topic=18336.msg157472#msg157472

Looking more closely at my system I find 4 references to “aswRdr”, and as you said, it is an avast! driver. “Service” would appear to be an Event Viewer misnomer.

C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
C:\Program Files\Alwil Software\Avast4\Setup\INF\AswRdr.sys
C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswRdr.sys
C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswRdr.sys

Each of these instances has this information at Context Menu → Properties:

File version: 4.6.763.0
Description: avast! TDI RDR Driver
Copyright: Copyright (c) 1996-2006 ALWIL Software

It certainly looks that way, I’m sure that here are other (programs) device drivers that are loaded and reported in the same ‘service’ Information Event Viewer entry. The ‘Service Control Manager’ on my system (also XP Pro SP2) also uses the 7035 Event Id and that isn’t a service despite its name.

Welcome to the forums.