Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12.0.122.172 5.00%
11.0.6300.541 5.00%
11.0.6200.513 15.00%
11.0.6100.463 5.00%
11.0.6070.422 25.00%
11.0.5002.290 5.00%
11.0.4010.14 5.00%
11.0.4000.2263 5.00%
11.0.3001.2198 5.00%
11.0.777.1008 5.00%
10.2.0.276 5.00%
10.1.9.9000 5.00%
10.1.6.6000 5.00%
10.0.0.846 5.00%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RevertToSelf, ImpersonateLoggedOnUser, DuplicateTokenEx, CheckTokenMembership, SetTokenInformation, GetSecurityInfo, MapGenericMask, GetFileSecurityW, AccessCheck, RegCreateKeyW, OpenSCManagerA, QueryServiceConfigA, LsaQueryInformationPolicy, LsaNtStatusToWinError, LsaFreeMemory, LsaClose, LsaOpenPolicy, RegDeleteKeyW, SetNamedSecurityInfoA, GetNamedSecurityInfoA, SetEntriesInAclA, RegQueryValueExW, LookupAccountSidA, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerExA, GetUserNameA, SetServiceStatus, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, RegLoadKeyA, RegUnLoadKeyA, ReportEventA, GetTokenInformation, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, EqualSid, ControlService, QueryServiceStatus, ChangeServiceConfigA, StartServiceA, OpenServiceA, CloseServiceHandle, GetAce, SetFileSecurityA, ImpersonateSelf, IsValidSid, LookupAccountNameA, DeregisterEventSource, RegisterEventSourceA, CopySid, OpenProcessToken, OpenThreadToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegEnumValueA, RegEnumKeyA, RegEnumKeyExW, RegOpenKeyW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptGenRandom, CryptAcquireContextA, CryptDestroyHash, CryptReleaseContext, RegCreateKeyA, RegSetValueA, RegEnumValueW, RegOpenKeyExW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExA, GetAclInformation, DeleteAce, GetLengthSid, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, IsValidSecurityDescriptor, FreeSid, AllocateAndInitializeSid, RegNotifyChangeKeyValue, RegQueryInfoKeyA, RegSetValueExA, RegCreateKeyExA, RegDeleteValueA, RegDeleteKeyA, RegOpenKeyExA, RegEnumKeyExA, RegOpenKeyA, RegCloseKey, RegFlushKey, RegisterServiceCtrlHandlerA, CreateServiceA
crypt32.dll
CryptProtectData, CryptUnprotectData
i2ldvp3.dll
VEGetCurrentDefPath, VELoadPatternFile, VEInit, VEGetInfo, VEDeInit, VEFreePatternFiles, VEGetSignatureVirusCount, VEDecomposerInit, VEEnumSignatures, VEGetScanner
iphlpapi.dll
NotifyRouteChange, NotifyAddrChange
kernel32.dll
DllMain
mpr.dll
WNetGetUniversalNameW
msvcp71.dll
DllMain
msvcp80.dll
DllMain
msvcr71.dll
DllMain
msvcr80.dll
DllMain
navlu.dll
_DoLiveUpdate@12
netapi32.dll
NetApiBufferFree, NetMessageBufferSend, NetSessionEnum, NetWkstaGetInfo, Netbios
ole32.dll
CoInitializeEx, CoUninitialize, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoCreateGuid, OleRun, CoCreateInstance, CoDisconnectObject, CoInitialize, StringFromGUID2, CoRevokeClassObject, CoRegisterClassObject, CoSuspendClassObjects, CoResumeClassObjects, CoInitializeSecurity, CoFreeUnusedLibraries, StringFromCLSID, CreateBindCtx, CLSIDFromString, OleSaveToStream, GetHGlobalFromStream, CreateStreamOnHGlobal, OleLoadFromStream
pdh.dll
PdhCloseQuery, PdhRemoveCounter, PdhCollectQueryData, PdhAddCounterA, PdhValidatePathA, PdhOpenQueryA, PdhEnumObjectItemsA, PdhGetFormattedCounterValue
psapi.dll
EnumProcessModules, GetModuleBaseNameA, EnumProcesses, GetProcessMemoryInfo, GetModuleInformation
rpcrt4.dll
RpcStringFreeA, UuidToStringA, UuidCreate
secur32.dll
LsaFreeReturnBuffer, LsaGetLogonSessionData
shell32.dll
SHGetFolderPathA, SHGetSpecialFolderPathA, SHGetMalloc, SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHGetDesktopFolder, SHCreateDirectoryExA
shlwapi.dll
SHDeleteKeyA, PathAddBackslashA, PathRemoveBackslashA
urlmon.dll
MkParseDisplayNameEx
user32.dll
CharUpperA, CharNextA, LoadStringA, DispatchMessageA, TranslateMessage, UnregisterClassA, PeekMessageA, PostThreadMessageA, SendMessageTimeoutA, SendMessageA, CharUpperW, wsprintfA, CharNextW, MessageBoxA, GetSystemMetrics, MsgWaitForMultipleObjects, CharPrevA, FindWindowA, IsWindow, DestroyWindow, DefWindowProcA, PostQuitMessage, GetMessageA, ShowWindow, CreateWindowExA, RegisterClassA, LoadCursorA, MsgWaitForMultipleObjectsEx, IsWindowUnicode, GetMessageW, DispatchMessageW, CharToOemA, GetSystemMenu, EnableMenuItem, PostMessageA, IsCharAlphaNumericA
userenv.dll
GetProfilesDirectoryA
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW, GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationA, WTSEnumerateSessionsA, WTSSendMessageA
Export table
SymSVM_ClientDataStruct
SymSVM_ScanControlStruct
SymSVM_VMEnvironmentInfo

RTVScan.exe

Symantec AntiVirus by Symantec Corporation (Signed)

Remove RTVScan.exe
Version:   11.0.6070.422
MD5:   f3a4ead0b3946e439f0397f7a4d09952
SHA1:   a223f70549016a30327d3c09168f26fa9218f1d6
SHA256:   4c58a5bf9f4756f95357e80c20a016e6040323f7a49ac7fafc73cc783396b7fd

Overview

rtvscan.exe runs as a service under the name Symantec Endpoint Protection (Symantec AntiVirus) with extensive SYSTEM privileges (full administrator access). This is typically installed with the program Symantec Endpoint Protection published by Symantec Corporation. The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:rtvscan.exe
Publisher:Symantec Corporation
Product name:Symantec AntiVirus
Typical file path:C:\Program Files\symantec client security\symantec antivirus\rtvscan.exe
File version:11.0.6070.422
Size:1.75 MB (1,831,024 bytes)
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Tuesday, October 30, 2007
Expiration date:Wednesday, November 24, 2010
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Symantec Corporation
9% remove
Customers have embraced Symantec Endpoint Protection 12 faster than any previous release. In Symantec Endpoint Protection 12.1.2, we've worked hard to further the Unrivaled Security, Blazing Performance and support for Virtual Environments. By layering technologies like Insight and SONAR, antivirus scans are reduced and maximum performance is achieved while stopping cyber-criminals and even zero-day threats in their tracks. Endpoint pro...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Symantec AntiVirus'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00018924%
0.028634%
Kernel CPU:0.00007676%
0.013761%
User CPU:0.00011247%
0.014873%
Kernel CPU time:2,823,046 ms/min
100,923,805ms/min
CPU cycles:8,156,030/sec
17,470,203/sec
Memory
Private memory:35.96 MB
21.59 MB
Private (maximum):167.18 MB
Private (minimum):1014.67 KB
Non-paged memory:35.96 MB
21.59 MB
Virtual memory:304.67 MB
140.96 MB
Virtual memory (peak):789.73 MB
169.69 MB
Working set:10.42 MB
18.61 MB
Working set (peak):188.5 MB
37.95 MB
Page faults:147,161,596/min
2,039/min
I/O
I/O read transfer:12.25 MB/sec
1.02 MB/min
I/O read operations:7,808/sec
343/min
I/O write transfer:2.96 MB/sec
274.99 KB/min
I/O write operations:372/sec
227/min
I/O other transfer:231.55 KB/sec
448.09 KB/min
I/O other operations:23,445/sec
1,671/min
Resource allocations
Threads:27
12
Handles:818
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\symantec\symantec endpoint protection\rtvscan.exe"
Owner:SYSTEM
Windows Service
Service name:Symantec AntiVirus
Display name:Symantec Endpoint Protection
Description:“Provides real-time virus scanning, reporting, and management functionality for Symantec AntiVirus.”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
Rtvscan.exe (main module)
Total CPU:0.24472066%
0.272967%
Kernel CPU:0.09042476%
0.107585%
User CPU:0.15429590%
0.165382%
CPU cycles:4,738,364/sec
5,741,424/sec
Memory:1.81 MB
1.16 MB
ntdll.dll
Total CPU:0.04402226%
Kernel CPU:0.02192342%
User CPU:0.02209884%
CPU cycles:875,035/sec
Memory:1.66 MB
sechost.dll
Total CPU:0.00289883%
Kernel CPU:0.00085891%
User CPU:0.00203992%
CPU cycles:58,863/sec
Memory:100 KB
wow64.dll (Win32 Emulation on NT64 by Microsoft)
Total CPU:0.00053823%
Kernel CPU:0.00018863%
User CPU:0.00034960%
CPU cycles:12,571/sec
Memory:252 KB
wow64cpu.dll
Total CPU:0.00022553%
Kernel CPU:0.00007470%
User CPU:0.00015083%
CPU cycles:5,282/sec
Memory:32 KB
MSVCR80.dll
Total CPU:0.00016877%
Kernel CPU:0.00013809%
User CPU:0.00003069%
CPU cycles:37,710/sec
Memory:620 KB
ole32.dll
Total CPU:0.00003068%
Kernel CPU:0.00003068%
User CPU:0.00000000%
CPU cycles:1,170/sec
Memory:1.36 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 47.37%
Windows 7 Home Premium 26.32%
Windows 7 Enterprise 10.53%
Windows Vista Home Premium 5.26%
Windows Vista Ultimate 5.26%
Windows 7 Professional 5.26%

Distribution by countryDistribution by country

United States installs about 57.89% of Symantec AntiVirus.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 47.62%
Hewlett-Packard 23.81%
Lenovo 19.05%
Intel 9.52%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE