Should I block it?

45%
45% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

4,0,7,71382 2.17%
4,0,1,55251 4.35%
4,0,0,48672 2.17%
3,7,1,43377 17.39%
3,7,1,42904 2.17%
3,7,1,41782 2.17%
3,7,1,39149 4.35%
3,2,0,29 13.04%
3,2,0,25 2.17%
3,0,0,4 2.17%
1,18,0,9 2.17%
1,17,0,4 10.87%
1,16,0,7 17.39%
1,16,0,6 2.17%
1,13,0,17 15.22%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetSecurityDescriptorSacl, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegEnumKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegCreateKeyW, RegOpenKeyW, RegQueryValueExW, GetUserNameW, RevertToSelf, RegOpenCurrentUser, ImpersonateLoggedOnUser, ConvertSidToStringSidW, LookupAccountNameW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, CreateProcessAsUserW, SetSecurityInfo, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, RegDeleteKeyW
comctl32.dll
InitCommonControlsEx
directui.dll
DirectUI_GetStringItem, DirectUI_Button_SetCheck, DirectUI_ShowControl, DirectUI_EnableControl, DirectUI_GetStringLength, DirectUI_SetControlPos, DirectUI_ComboBox_SetCurSel, DirectUI_ComboBox_GetCurSel, DirectUI_Button_GetCheck, DirectUI_SubclassWindow, DirectUI_SetControlText, DirectUI_ListCtrl_EnsureVisible, DirectUI_TreeCtrl_SetTooltipString, DirectUI_TreeCtrl_ShowControl, DirectUI_TreeCtrl_SetControlText, DirectUI_TreeCtrl_InsertItem, DirectUI_TreeCtrl_DeleteAllItems, DirectUI_Progress_SetRange, DirectUI_TreeCtrl_EnableAnimate, DirectUI_AutoText_SetControlText, DirectUI_SetControlTextEx, DirectUI_GetControlRect, DirectUI_Progress_SetPos, DirectUI_LoadSkinResourceFromFolder, DirectUI_TrackPopupMenu, DirectUI_UpdateSkin, DirectUI_GetControlText, DirectUI_IsControlVisible, _DirectUI_ChangeStyle@12, DirectUI_ComboBox_AddString, _DirectUI_GetControlPos@28, DirectUI_SetLanguageStyle
gdi32.dll
DeleteObject
iphlpapi.dll
GetAdaptersAddresses
kernel32.dll
GetDateFormatA, GetTimeFormatA, SetConsoleCtrlHandler, FlushFileBuffers, GetTickCount, QueryPerformanceCounter, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetConsoleMode, GetConsoleCP, SetFilePointer, GetStartupInfoA, GetFileType, SetHandleCount, IsValidCodePage, GetOEMCP, GetACP, GetTimeZoneInformation, GetModuleHandleA, GetModuleFileNameA, GetStdHandle, ExitProcess, GetCurrentThread, TlsFree, WaitForSingleObject, TlsAlloc, TlsGetValue, FatalAppExitA, HeapCreate, GetCPInfo, LCMapStringW, WideCharToMultiByte, LCMapStringA, GetStartupInfoW, CreateThread, ExitThread, GetSystemTimeAsFileTime, IsDebuggerPresent, GetUserDefaultLCID, RtlUnwind, InterlockedExchange, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, LoadLibraryA, InterlockedCompareExchange, HeapSize, HeapReAlloc, HeapDestroy, SetUnhandledExceptionFilter, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, GetStringTypeA, GetStringTypeW, InitializeCriticalSectionAndSpinCount, GetLocaleInfoW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEndOfFile, CreateFileA, CompareStringA, CompareStringW, WritePrivateProfileSectionW, WritePrivateProfileStringW, GetPrivateProfileStringW, WTSGetActiveConsoleSessionId, LocalFree, CreateFileW, WriteFile, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, LoadLibraryW, HeapAlloc, IsBadReadPtr, GetDiskFreeSpaceW, GetProcessHeap, HeapFree, GetLongPathNameW, SetLastError, GetVersionExW, lstrcmpiW, LoadLibraryExW, MultiByteToWideChar, FreeLibrary, InitializeCriticalSection, GetModuleFileNameW, lstrlenW, InterlockedDecrement, InterlockedIncrement, SetEnvironmentVariableA, OpenFileMappingW, IsBadWritePtr, VirtualQuery, TerminateProcess, CreateProcessW, GetLocalTime, VerSetConditionMask, VerifyVersionInfoW, CreateDirectoryW, ReadFile, GetFileSize, OpenProcess, Thread32Next, ResumeThread, SuspendThread, OpenThread, GetCurrentProcessId, Thread32First, UnhandledExceptionFilter, GetCurrentProcess, FlushInstructionCache, LeaveCriticalSection, EnterCriticalSection, FindResourceExW, LoadResource, LockResource, SizeofResource, FindResourceW, RaiseException, DeleteCriticalSection, GetPrivateProfileIntW, CreateFileMappingW, GetLastError, MapViewOfFile, CloseHandle, UnmapViewOfFile, Sleep, GetModuleHandleW, GetProcAddress, GetCurrentThreadId, TlsSetValue, ExpandEnvironmentStringsW, IsDBCSLeadByteEx, CreateMutexW, ReleaseMutex, GetPrivateProfileSectionW, GlobalAlloc, GlobalFree, DeviceIoControl, GetExitCodeProcess
log.dll
CreateLog, WriteLog
ole32.dll
CoCreateInstance, CoTaskMemRealloc, CoInitialize, CoTaskMemAlloc, CoTaskMemFree, CoUninitialize, CoCreateGuid
rpcrt4.dll
UuidToStringW, UuidCreate, RpcStringFreeW
shell32.dll
SHQueryRecycleBinW, SHGetSpecialFolderPathW, SHGetFolderPathW, SHAppBarMessage, ShellExecuteW, Shell_NotifyIconW, ShellExecuteExW
shlwapi.dll
PathAppendW, PathRemoveFileSpecW, PathCombineW, PathFileExistsW, StrRChrW, StrFormatByteSizeW, PathFindFileNameW, SHGetValueW, PathFindExtensionW, PathAddBackslashW
urlmon.dll
FindMimeFromData
user32.dll
MonitorFromWindow, GetMonitorInfoW, wsprintfW, ScreenToClient, MonitorFromPoint, GetMenuItemInfoW, RemoveMenu, GetMenuItemCount, TrackPopupMenuEx, InvalidateRect, PtInRect, GetClientRect, MapWindowPoints, SetWindowPos, PeekMessageW, GetMessageW, TranslateMessage, DispatchMessageW, DestroyMenu, MessageBeep, LoadStringA, PostQuitMessage, SetFocus, GetWindowLongW, GetWindowRect, GetWindow, GetParent, DefWindowProcW, SendMessageW, DestroyWindow, RegisterClassExW, LoadImageW, LoadCursorW, GetClassInfoExW, CreateWindowExW, SetWindowLongW, RegisterWindowMessageW, CharNextW, LoadIconW, DestroyIcon, SetMenuItemBitmaps, AppendMenuW, UnregisterClassA, CreatePopupMenu, TranslateAcceleratorW, LoadBitmapW, AttachThreadInput, WindowFromPoint, GetWindowThreadProcessId, ClientToScreen, SetMenuDefaultItem, GetCursorPos, RedrawWindow, SetActiveWindow, SetForegroundWindow, GetActiveWindow, IsWindowVisible, GetPropW, RegisterClassW, SetPropW, CallWindowProcW, BringWindowToTop, GetDlgItem, CreateDialogParamW, GetDesktopWindow, GetShellWindow, GetForegroundWindow, FindWindowW, GetSystemMetrics, MoveWindow, UpdateWindow, SetLayeredWindowAttributes, IsWindow, ShowWindow, EndDialog, SetWindowTextW, PostMessageW, DialogBoxParamW, KillTimer, SetTimer, LoadStringW, SetCursor
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
winhttp.dll
WinHttpReadData, WinHttpQueryHeaders, WinHttpReceiveResponse, WinHttpWriteData, WinHttpSendRequest, WinHttpSetCredentials, WinHttpOpenRequest, WinHttpConnect, WinHttpCloseHandle, WinHttpOpen, WinHttpSetOption, WinHttpCreateUrl, WinHttpAddRequestHeaders
wininet.dll
InternetCrackUrlW, InternetOpenW, InternetConnectW, HttpOpenRequestW, HttpSendRequestW, HttpQueryInfoW, InternetReadFile, InternetCloseHandle, InternetCreateUrlW
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSFreeMemory

pcfaster.exe

Baidu PC Faster by Baidu Online Network Technology (Beijing)Co. (Signed)

Remove pcfaster.exe
Version:   1,17,0,4
MD5:   9dcdf9211b7dc7a8ca262c9ce2b10abb
SHA1:   91a828f34db789528aa5c4b84874ad769eb34600
SHA256:   88ed2584873173966b6ca794b76a462ee0c03f3ee145dda8d4dcf6e1b7548721

Overview

pcfaster.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program Baidu PC Faster published by Baidu, Inc. and is most likely removed by most users once installed (65% removed). The file is digitally signed by Baidu Online Network Technology (Beijing)Co. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:pcfaster.exe
Publisher:Baidu Inc.
Product name:Baidu PC Faster
Typical file path:C:\Program Files\baidu security\pc faster\pcfaster.exe
File version:1,17,0,4
Size:1.79 MB (1,882,000 bytes)
Certificate
Issued to:Baidu Online Network Technology (Beijing)Co.
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Baidu, Inc.
  65% remove
The software is typically bundled with third party installers such as Open Candy. "Offer your users a free system maintenance and utility suite to help them get the most out of their PC’s performance."

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Baidu PC Faster 4.0.0.0' → "C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFaster.exe" -auto -start
  • 'Baidu PC Faster 3.7.0.0' → "C:\Program Files\Baidu Security\PC Faster\3.7.0.0\PCFaster.exe" -auto -start
  • 'Baidu PC Faster 3.2.0.25' → "C:\Program Files\Baidu Security\PC Faster\3.2.0.25\PCFaster.exe" -auto -start
  • 'Baidu PC Faster 3.2.0.29' → "C:\Program Files\Baidu Security\PC Faster\3.2.0.29\PCFaster.exe" -auto -start
  • 'Baidu PC Faster 3.0.0.4' → "C:\Program Files\Baidu Security\PC Faster\3.0.0.4\PCFaster.exe" -auto -start
  • 'Baidu PC Faster 1.18.0.9' → "C:\Program Files\Baidu Security\PC Faster\1.18.0.9\PCFaster.exe" -auto -start
  • 'BaiduPCFaster' → "C:\Program Files\Baidu Security\PC Faster\PCFaster.exe" -auto -start

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.01213990%
0.028634%
Kernel CPU:0.00911910%
0.013761%
User CPU:0.00302079%
0.014873%
Kernel CPU time:2,384,294 ms/min
100,923,805ms/min
CPU cycles:4,129,221/sec
17,470,203/sec
Context switches:328/sec
284/sec
Memory
Private memory:26.83 MB
21.59 MB
Private (maximum):32.55 MB
Private (minimum):14.98 MB
Non-paged memory:26.83 MB
21.59 MB
Virtual memory:116.61 MB
140.96 MB
Virtual memory (peak):118.83 MB
169.69 MB
Working set:15.76 MB
18.61 MB
Working set (peak):34.23 MB
37.95 MB
Page faults:910,950/min
2,039/min
I/O
I/O read transfer:235.83 KB/sec
1.02 MB/min
I/O read operations:62/sec
343/min
I/O write transfer:9.65 KB/sec
274.99 KB/min
I/O write operations:33/sec
227/min
I/O other transfer:850 Bytes/sec
448.09 KB/min
I/O other operations:73/sec
1,671/min
Resource allocations
Threads:13
12
Handles:400
600
GUI GDI count:189
103
GUI GDI peak:288
142
GUI USER count:63
49
GUI USER peak:107
71

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Undefined
Platform:32-bit
Command lines:
  • "C:\Program Files\baidu security\pc faster\pcfaster.exe" -auto -start
  • "C:\Program Files\baidu security\pc faster\pcfaster.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

ResourcesThreads

Averages
 
PCFaster.exe (main module)
Total CPU:5.89348310%
0.272967%
Kernel CPU:4.92500576%
0.107585%
User CPU:0.96847734%
0.165382%
CPU cycles:151,388,412/sec
5,741,424/sec
Context switches:76/sec
79/sec
Memory:1.81 MB
1.16 MB
datareport.dll
Total CPU:0.00385745%
Kernel CPU:0.00356362%
User CPU:0.00029383%
CPU cycles:92,882/sec
Memory:188 KB
baidustore.dll (Baidu PC Faster by Baidu)
Total CPU:0.00120553%
Kernel CPU:0.00047085%
User CPU:0.00073468%
CPU cycles:38,844/sec
Context switches:5/sec
Memory:1.18 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 32.61%
Windows 7 Ultimate 26.09%
Windows 7 Professional 19.57%
Windows 7 Home Premium 6.52%
Windows 8 Pro 4.35%
Windows 8 Single Language 2.17%
Windows 8.1 2.17%
Windows 8.1 Enterprise 2.17%
Windows 8.1 Pro 2.17%
Windows 7 Enterprise 2.17%

Distribution by countryDistribution by country

Thailand installs about 36.96% of Baidu PC Faster.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 26.47%
Hewlett-Packard 11.76%
GIGABYTE 11.76%
Compaq 11.76%
Intel 11.76%
Lenovo 5.88%
ASUS 5.88%
MSI 5.88%
Toshiba 5.88%
American Megatrends 2.94%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE