Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4,4,3,64051 6.25%
4,0,3,57478 6.25%
3,6,2,47687 6.25%
3,6,2,44641 6.25%
3,4,2,41470 6.25%
3,3,1,33119 6.25%
3,1,1,30291 31.25%
3,1,1,29578 18.75%
3,1,1,28642 6.25%
3,1,1,21903 6.25%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RevertToSelf, RegOpenCurrentUser, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyExW, OpenProcessToken, EqualSid, GetTokenInformation, QueryServiceStatus, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, SetSecurityInfo, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, CreateServiceW, RegEnumValueW, RegDeleteKeyW, RegQueryInfoKeyW, RegSetValueExW, ConvertSidToStringSidW, OpenThreadToken, ImpersonateLoggedOnUser, CreateProcessAsUserW, SetTokenInformation, AdjustTokenPrivileges, FreeSid, SetEntriesInAclW, AllocateAndInitializeSid, RegDeleteValueW, GetNamedSecurityInfoW, LookupPrivilegeValueW, SetNamedSecurityInfoW, LookupAccountNameW, RegCreateKeyExW, GetUserNameW, RegisterServiceCtrlHandlerW, SetServiceStatus, StartServiceCtrlDispatcherW, ImpersonateNamedPipeClient, DuplicateTokenEx, GetSidSubAuthorityCount, GetSidSubAuthority, RegOpenKeyW, RegSetValueW, RegCreateKeyW, GetSidIdentifierAuthority
crypt32.dll
CertFindCertificateInStore, CertFreeCertificateContext, CertGetNameStringW, CryptQueryObject, CertCloseStore, CryptMsgGetParam, CryptMsgClose
gdi32.dll
GetStockObject
imm32.dll
ImmDisableIME
iphlpapi.dll
GetAdaptersAddresses
kernel32.dll
DllMain
log.dll
CloseLog, CreateLog, WriteLog
ole32.dll
CoInitializeSecurity, CoInitialize, CoUninitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CoSetProxyBlanket, CoInitializeEx
pdh.dll
PdhOpenQueryW, PdhAddCounterW, PdhCloseQuery, PdhCollectQueryData, PdhGetFormattedCounterValue
psapi.dll
GetModuleFileNameExW, EnumProcessModules, GetProcessImageFileNameW
rpcrt4.dll
UuidCreate, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiGetDeviceRegistryPropertyW, SetupDiGetDeviceInterfaceDetailW, CM_Get_DevNode_Registry_PropertyW, SetupDiEnumDeviceInterfaces, SetupDiSetClassInstallParamsW, CM_Get_Device_IDW, CM_Enumerate_Classes, SetupDiCallClassInstaller, CM_Get_DevNode_Status, CM_Request_Device_EjectW, SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW, CM_Get_Parent, CM_Get_Child
shell32.dll
SHGetFolderPathW, ShellExecuteExW, SHGetDesktopFolder, ShellExecuteW, SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathIsDirectoryW, PathAddBackslashW, PathFindFileNameW, PathFileExistsW, PathRenameExtensionW, PathRemoveFileSpecW, PathIsFileSpecW, StrRChrW, PathAddExtensionW, StrStrIW, StrRetToStrW, SHDeleteKeyW
user32.dll
KillTimer, GetSystemMetrics, wsprintfW, FindWindowExW, GetWindowThreadProcessId, IsWindow, GetWindowLongW, SendMessageTimeoutW, SendMessageW, PostQuitMessage, DefWindowProcW, PostMessageW, GetClassInfoW, CreateWindowExW, SetWindowLongW, MsgWaitForMultipleObjectsEx, PeekMessageW, TranslateMessage, DispatchMessageW, GetMessageW, RegisterClassW, SetTimer, DestroyWindow, CloseDesktop, OpenDesktopW, UnregisterDeviceNotification, PostThreadMessageW, RegisterDeviceNotificationW, LoadIconW, LoadCursorW, UnregisterClassW
userenv.dll
ExpandEnvironmentStringsForUserW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
winhttp.dll
WinHttpOpenRequest, WinHttpCrackUrl, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpCloseHandle, WinHttpConnect, WinHttpOpen, WinHttpQueryHeaders
ws2_32.dll
WSCEnumProtocols, WSCDeinstallProvider, WSCGetProviderPath
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSFreeMemory

bavsvc.exe

Baidu Antivirus by Baidu Online Network Technology (Beijing)Co. (Signed)

Remove bavsvc.exe
Version:   3,1,1,21903
MD5:   68857319e81a8c279e5cfc5dde9398fe
SHA1:   b977159ff613c46f47559049cd42e90ea86e20df
SHA256:   110adaa1c00b915b5ea427c4da262439c12eafdf7305dc0b279a29f3a18ea5f7

Overview

bavsvc.exe runs as a service under the name BAVSvc (BAVSvc) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Baidu Online Network Technology (Beijing)Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:bavsvc.exe
Publisher:Baidu, Inc.
Product name:Baidu Antivirus
Description:Baidu Antivirus Service
Typical file path:C:\Program Files\baidu security\cloud security\bavsvc.exe
File version:3,1,1,21903
Size:1.53 MB (1,599,104 bytes)
Certificate
Issued to:Baidu Online Network Technology (Beijing)Co.
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • BAVSvc
  • 'BAVSvc' (Baidu Antivirus Service)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00006522%
0.028634%
Kernel CPU:0.00003919%
0.013761%
User CPU:0.00002603%
0.014873%
Kernel CPU time:140 ms/min
100,923,805ms/min
Context switches:32/sec
284/sec
Memory
Private memory:8.38 MB
21.59 MB
Private (maximum):11.2 MB
Private (minimum):652 KB
Non-paged memory:8.38 MB
21.59 MB
Virtual memory:122.33 MB
140.96 MB
Virtual memory (peak):129.54 MB
169.69 MB
Working set:5.55 MB
18.61 MB
Working set (peak):11.21 MB
37.95 MB
Resource allocations
Threads:26
12
Handles:408
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\baidu security\cloud security\bavsvc.exe"
Owner:SYSTEM
Windows Service
Service name:BAVSvc
Display name:BAVSvc
Description:“Baidu Antivirus Service”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.00013961%
0.272967%
Kernel CPU:0.00010471%
0.107585%
User CPU:0.00003490%
0.165382%
CPU cycles:3,729/sec
5,741,424/sec
Memory:1.67 MB
1.16 MB
BAVSvc.exe (main module)
Total CPU:0.00005584%
Kernel CPU:0.00003490%
User CPU:0.00002094%
CPU cycles:39,720/sec
Context switches:4/sec
Memory:1.54 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 31.25%
Windows 7 Professional 25.00%
Windows 7 Ultimate 25.00%
Windows 8.1 Pro 6.25%
Windows 8.1 6.25%
Windows 7 Home Premium 6.25%

Distribution by countryDistribution by country

Egypt installs about 25.00% of Baidu Antivirus.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 31.25%
Intel 25.00%
Hewlett-Packard 12.50%
Compaq 12.50%
American Megatrends 12.50%
GIGABYTE 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE