Baidu Bar

The BaiduBar is is an Internet Explorer Toolbar. The toolbar is in the Chinese Language. It is a generic toolbar that is a component of commercial toolbars. It monitors browsing patterns and sends URL information to a remote server. It can also hijacks the Internet Explorer search function and show advertising messages.0

General information:

Malware Name: Baidu Bar
Malware Type: Toolbar
Company Name: Baidu
Company URL:
Threat Level: High
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Browser Restart.

Company Description:

The BaiduBar is is an Internet Explorer Toolbar. The toolbar is in the Chinese Language. It is a generic toolbar that is a component of commercial toolbars. It monitors browsing patterns and sends URL information to a remote server. It can also hijacks the Internet Explorer search function and show advertising messages.

Spyware Description:

The BaiduBar is is an Internet Explorer Toolbar. The toolbar is in the Chinese Language. It is a generic toolbar that is a component of commercial toolbars. It monitors browsing patterns and sends URL information to a remote server. It can also hijacks the Internet Explorer search function and show advertising messages.0

Characteristics/Symptoms:

    -> Keeps watch on user’s browsing activity -> Changes default search settings -> Hijacks searches -> Checks for updates -> Shows popup messages0

Additional information might be found here:

google Search at Google for Baidu Bar
bing Search at Bing for Baidu Bar
yahoo Search at Yahoo for Baidu Bar

Processes Running:

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\baidu\bar\BaiduBar.dll 680027 Application Extension
C:\Program Files\baidu\bar\baidubar.dat 9383 DAT File
C:\Program Files\baidu\bar\bang.ini 3095 Configuration Settings

Folder information Created after Installation:

Folder Location

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\Baidu\BaiduBar\sys {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A}
HKEY_CURRENT_USER \Software\Baidu\BaiduBar\sys {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
HKEY_CURRENT_USER \Software\Baidu\BaiduBar\sys {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}