Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4,4,3,64051 6.25%
4,0,3,57478 6.25%
3,6,2,47687 6.25%
3,6,2,44641 6.25%
3,4,2,41470 6.25%
3,3,1,33119 6.25%
3,1,1,30291 31.25%
3,1,1,29578 18.75%
3,1,1,28642 6.25%
3,1,1,21903 6.25%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RevertToSelf, RegOpenCurrentUser, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyExW, OpenProcessToken, EqualSid, GetTokenInformation, QueryServiceStatus, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, SetSecurityInfo, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, CreateServiceW, RegEnumValueW, RegDeleteKeyW, RegQueryInfoKeyW, RegSetValueExW, ConvertSidToStringSidW, OpenThreadToken, ImpersonateLoggedOnUser, CreateProcessAsUserW, SetTokenInformation, AdjustTokenPrivileges, FreeSid, SetEntriesInAclW, AllocateAndInitializeSid, RegDeleteValueW, GetNamedSecurityInfoW, LookupPrivilegeValueW, SetNamedSecurityInfoW, LookupAccountNameW, RegCreateKeyExW, GetUserNameW, RegisterServiceCtrlHandlerW, SetServiceStatus, StartServiceCtrlDispatcherW, ImpersonateNamedPipeClient, DuplicateTokenEx, GetSidSubAuthorityCount, GetSidSubAuthority, RegOpenKeyW, RegSetValueW, RegCreateKeyW, GetSidIdentifierAuthority
crypt32.dll
CertFindCertificateInStore, CertFreeCertificateContext, CertGetNameStringW, CryptQueryObject, CertCloseStore, CryptMsgGetParam, CryptMsgClose
gdi32.dll
GetStockObject
imm32.dll
ImmDisableIME
iphlpapi.dll
GetAdaptersAddresses
kernel32.dll
DllMain
log.dll
CloseLog, CreateLog, WriteLog
ole32.dll
CoInitializeSecurity, CoInitialize, CoUninitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CoSetProxyBlanket, CoInitializeEx
pdh.dll
PdhOpenQueryW, PdhAddCounterW, PdhCloseQuery, PdhCollectQueryData, PdhGetFormattedCounterValue
psapi.dll
GetModuleFileNameExW, EnumProcessModules, GetProcessImageFileNameW
rpcrt4.dll
UuidCreate, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiGetDeviceRegistryPropertyW, SetupDiGetDeviceInterfaceDetailW, CM_Get_DevNode_Registry_PropertyW, SetupDiEnumDeviceInterfaces, SetupDiSetClassInstallParamsW, CM_Get_Device_IDW, CM_Enumerate_Classes, SetupDiCallClassInstaller, CM_Get_DevNode_Status, CM_Request_Device_EjectW, SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW, CM_Get_Parent, CM_Get_Child
shell32.dll
SHGetFolderPathW, ShellExecuteExW, SHGetDesktopFolder, ShellExecuteW, SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathIsDirectoryW, PathAddBackslashW, PathFindFileNameW, PathFileExistsW, PathRenameExtensionW, PathRemoveFileSpecW, PathIsFileSpecW, StrRChrW, PathAddExtensionW, StrStrIW, StrRetToStrW, SHDeleteKeyW
user32.dll
KillTimer, GetSystemMetrics, wsprintfW, FindWindowExW, GetWindowThreadProcessId, IsWindow, GetWindowLongW, SendMessageTimeoutW, SendMessageW, PostQuitMessage, DefWindowProcW, PostMessageW, GetClassInfoW, CreateWindowExW, SetWindowLongW, MsgWaitForMultipleObjectsEx, PeekMessageW, TranslateMessage, DispatchMessageW, GetMessageW, RegisterClassW, SetTimer, DestroyWindow, CloseDesktop, OpenDesktopW, UnregisterDeviceNotification, PostThreadMessageW, RegisterDeviceNotificationW, LoadIconW, LoadCursorW, UnregisterClassW
userenv.dll
ExpandEnvironmentStringsForUserW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
winhttp.dll
WinHttpOpenRequest, WinHttpCrackUrl, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpCloseHandle, WinHttpConnect, WinHttpOpen, WinHttpQueryHeaders
ws2_32.dll
WSCEnumProtocols, WSCDeinstallProvider, WSCGetProviderPath
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSFreeMemory

bavsvc.exe

Baidu Antivirus by Baidu Online Network Technology (Beijing)Co. (Signed)

Remove bavsvc.exe
Version:   3,1,1,29578
MD5:   94208fcc8a3e18f7bc2b01ffb5c20fba
SHA1:   0ee2a7367bd196f0565d2d7a4271815de24895a9
SHA256:   767c107cd14b2b6d9d31d48f7c947ad960c2681438a77a290113d842c3d57b34

Overview

bavsvc.exe runs as a service under the name BAVSvc (BAVSvc) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Baidu Online Network Technology (Beijing)Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:bavsvc.exe
Publisher:Baidu, Inc.
Product name:Baidu Antivirus
Description:Baidu Antivirus Service
Typical file path:C:\Program Files\baidu security\cloud security\bavsvc.exe
File version:3,1,1,29578
Size:1.54 MB (1,618,280 bytes)
Build date:5/15/2013 11:17 AM
Certificate
Issued to:Baidu Online Network Technology (Beijing)Co.
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • BAVSvc
  • 'BAVSvc' (Baidu Antivirus Service)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00078527%
0.028634%
Kernel CPU:0.00048754%
0.013761%
User CPU:0.00029772%
0.014873%
Kernel CPU time:1,950,098 ms/min
100,923,805ms/min
CPU cycles:3,284/sec
17,470,203/sec
Context switches:35/sec
284/sec
Memory
Private memory:8.23 MB
21.59 MB
Private (maximum):8.48 MB
Private (minimum):394 KB
Non-paged memory:8.23 MB
21.59 MB
Virtual memory:104.99 MB
140.96 MB
Virtual memory (peak):110.57 MB
169.69 MB
Working set:2.24 MB
18.61 MB
Working set (peak):9.71 MB
37.95 MB
Page faults:10,008/min
2,039/min
I/O
I/O read transfer:414 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:82 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:42 Bytes/sec
448.09 KB/min
I/O other operations:2/sec
1,671/min
Resource allocations
Threads:26
12
Handles:251
600
GUI GDI count:8
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\baidu security\cloud security\bavsvc.exe"
Owner:SYSTEM
Windows Service
Service name:BAVSvc
Display name:BAVSvc
Description:“Baidu Antivirus Service”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 31.25%
Windows 7 Professional 25.00%
Windows 7 Ultimate 25.00%
Windows 8.1 Pro 6.25%
Windows 8.1 6.25%
Windows 7 Home Premium 6.25%

Distribution by countryDistribution by country

Egypt installs about 25.00% of Baidu Antivirus.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 31.25%
Intel 25.00%
Hewlett-Packard 12.50%
Compaq 12.50%
American Megatrends 12.50%
GIGABYTE 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE