Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4,4,3,64051 6.25%
4,0,3,57478 6.25%
3,6,2,47687 6.25%
3,6,2,44641 6.25%
3,4,2,41470 6.25%
3,3,1,33119 6.25%
3,1,1,30291 31.25%
3,1,1,29578 18.75%
3,1,1,28642 6.25%
3,1,1,21903 6.25%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RevertToSelf, RegOpenCurrentUser, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyExW, OpenProcessToken, EqualSid, GetTokenInformation, QueryServiceStatus, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, SetSecurityInfo, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, CreateServiceW, RegEnumValueW, RegDeleteKeyW, RegQueryInfoKeyW, RegSetValueExW, ConvertSidToStringSidW, OpenThreadToken, ImpersonateLoggedOnUser, CreateProcessAsUserW, SetTokenInformation, AdjustTokenPrivileges, FreeSid, SetEntriesInAclW, AllocateAndInitializeSid, RegDeleteValueW, GetNamedSecurityInfoW, LookupPrivilegeValueW, SetNamedSecurityInfoW, LookupAccountNameW, RegCreateKeyExW, GetUserNameW, RegisterServiceCtrlHandlerW, SetServiceStatus, StartServiceCtrlDispatcherW, ImpersonateNamedPipeClient, DuplicateTokenEx, GetSidSubAuthorityCount, GetSidSubAuthority, RegOpenKeyW, RegSetValueW, RegCreateKeyW, GetSidIdentifierAuthority
crypt32.dll
CertFindCertificateInStore, CertFreeCertificateContext, CertGetNameStringW, CryptQueryObject, CertCloseStore, CryptMsgGetParam, CryptMsgClose
gdi32.dll
GetStockObject
imm32.dll
ImmDisableIME
iphlpapi.dll
GetAdaptersAddresses
kernel32.dll
DllMain
log.dll
CloseLog, CreateLog, WriteLog
ole32.dll
CoInitializeSecurity, CoInitialize, CoUninitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CoSetProxyBlanket, CoInitializeEx
pdh.dll
PdhOpenQueryW, PdhAddCounterW, PdhCloseQuery, PdhCollectQueryData, PdhGetFormattedCounterValue
psapi.dll
GetModuleFileNameExW, EnumProcessModules, GetProcessImageFileNameW
rpcrt4.dll
UuidCreate, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiGetDeviceRegistryPropertyW, SetupDiGetDeviceInterfaceDetailW, CM_Get_DevNode_Registry_PropertyW, SetupDiEnumDeviceInterfaces, SetupDiSetClassInstallParamsW, CM_Get_Device_IDW, CM_Enumerate_Classes, SetupDiCallClassInstaller, CM_Get_DevNode_Status, CM_Request_Device_EjectW, SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW, CM_Get_Parent, CM_Get_Child
shell32.dll
SHGetFolderPathW, ShellExecuteExW, SHGetDesktopFolder, ShellExecuteW, SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathIsDirectoryW, PathAddBackslashW, PathFindFileNameW, PathFileExistsW, PathRenameExtensionW, PathRemoveFileSpecW, PathIsFileSpecW, StrRChrW, PathAddExtensionW, StrStrIW, StrRetToStrW, SHDeleteKeyW
user32.dll
KillTimer, GetSystemMetrics, wsprintfW, FindWindowExW, GetWindowThreadProcessId, IsWindow, GetWindowLongW, SendMessageTimeoutW, SendMessageW, PostQuitMessage, DefWindowProcW, PostMessageW, GetClassInfoW, CreateWindowExW, SetWindowLongW, MsgWaitForMultipleObjectsEx, PeekMessageW, TranslateMessage, DispatchMessageW, GetMessageW, RegisterClassW, SetTimer, DestroyWindow, CloseDesktop, OpenDesktopW, UnregisterDeviceNotification, PostThreadMessageW, RegisterDeviceNotificationW, LoadIconW, LoadCursorW, UnregisterClassW
userenv.dll
ExpandEnvironmentStringsForUserW, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
winhttp.dll
WinHttpOpenRequest, WinHttpCrackUrl, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpCloseHandle, WinHttpConnect, WinHttpOpen, WinHttpQueryHeaders
ws2_32.dll
WSCEnumProtocols, WSCDeinstallProvider, WSCGetProviderPath
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSFreeMemory

bavsvc.exe

Baidu Antivirus by Baidu Online Network Technology (Beijing)Co. (Signed)

Remove bavsvc.exe
Version:   3,1,1,30291
MD5:   ad434ef3e96e6dd6f0195338de71ddf2
SHA1:   a84d58b1d49f2670535eb72fb2dbebc8981e9f82
SHA256:   be5eda441d419ba175d74e98ab2fca668b302b27fe5d954311cea4fde505114d

Overview

bavsvc.exe runs as a service under the name BAVSvc (BAVSvc) with extensive SYSTEM privileges (full administrator access). This is typically installed with the program Baidu Antivirus published by Baidu, Inc.. The file is digitally signed by Baidu Online Network Technology (Beijing)Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:bavsvc.exe
Publisher:Baidu, Inc.
Product name:Baidu Antivirus
Description:Baidu Antivirus Service
Typical file path:C:\Program Files\baidu security\cloud security\bavsvc.exe
File version:3,1,1,30291
Size:1.54 MB (1,618,280 bytes)
Build date:5/22/2013 5:48 AM
Certificate
Issued to:Baidu Online Network Technology (Beijing)Co.
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Baidu, Inc.
18% remove
Baidu Antivirus protects your computer against malware, phishing and malicious websites, worms, and trojans. Remove viruses. Free download and permanently free in future use. Baidu Antivirus consists of Antivirus, Cloud Scan, HIPS, Firewall, Anti-phishing.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • BAVSvc
  • 'BAVSvc' (Baidu Antivirus Service)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.02804720%
0.028634%
Kernel CPU:0.01994621%
0.013761%
User CPU:0.00810100%
0.014873%
Kernel CPU time:7,384,209 ms/min
100,923,805ms/min
Context switches:16/sec
284/sec
Memory
Private memory:9.48 MB
21.59 MB
Private (maximum):14.29 MB
Private (minimum):1.43 MB
Non-paged memory:9.48 MB
21.59 MB
Virtual memory:101.75 MB
140.96 MB
Virtual memory (peak):345.21 MB
169.69 MB
Working set:3.51 MB
18.61 MB
Working set (peak):23.52 MB
37.95 MB
Resource allocations
Threads:26
12
Handles:386
600
GUI GDI count:8
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\baidu security\cloud security\bavsvc.exe"
Owner:SYSTEM
Windows Service
Service name:BAVSvc
Display name:BAVSvc
Description:“Baidu Antivirus Service”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 31.25%
Windows 7 Professional 25.00%
Windows 7 Ultimate 25.00%
Windows 8.1 Pro 6.25%
Windows 8.1 6.25%
Windows 7 Home Premium 6.25%

Distribution by countryDistribution by country

Egypt installs about 25.00% of Baidu Antivirus.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 31.25%
Intel 25.00%
Hewlett-Packard 12.50%
Compaq 12.50%
American Megatrends 12.50%
GIGABYTE 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE