bavtray.exe
Baidu Antivirus by Baidu Online Network Technology (Beijing)Co. (Signed)
Overview
There are 5 versions of bavtray.exe in the wild, the latest version being 4,4,3,64051. bavtray.exe is run as a standard windows process with the logged in user's account privileges. During installation, a run registry key for all users is added that will cause the program to run each time any user logs on to Windows. The average file size is about 933.25 KB. The file is a digitally signed and issued to Baidu Online Network Technology (Beijing)Co. by VeriSign. Some variations of the file have been seen to be installed with the program Baidu Antivirus from Baidu, Inc.. During the process's lifecycle, the typical CPU resource utilization is about 0.0041% including both foreground and background operations, the average private memory consumption is about 4.4 MB with the maximum memory reaching around 8.28 MB. Addionally, typically read and write I/O disk operations is about 1.31 KB per minute for reads and 559 Bytes per minute for writes.
Details |
File name: | bavtray.exe |
Publisher: | Baidu, Inc. |
Product name: | Baidu Antivirus |
Description: | Baidu Antivirus Tray Application |
Typical file path: | C:\Program Files\baidu security\baidu antivirus\bavtray.exe |
Certificate |
Issued to: | Baidu Online Network Technology (Beijing)Co. |
Authority (CA): | VeriSign |
Programs installed in
(Note, the programs listed below are for all versions of Baidu Antivirus.)
“Baidu Antivirus protects your computer against malware, phishing and malicious websites, worms, and trojans. Remove viruses. Free download and permanently free in future use. Baidu Antivirus consists ...”
Behaviors
(Note, the behaviors below are for all versions of bavtray.exe, select a unique version for details.)
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Baidu Antivirus' → "C:\Program Files\Baidu Security\Baidu Antivirus\BavTray.exe" -auto
All file variations of bavtray.exe