Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

10.2.0.276 25.00%
10.1.9.9000 25.00%
10.1.6.6000 25.00%
10.0.0.846 25.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetSidIdentifierAuthority, FreeSid, IsValidSecurityDescriptor, DeleteAce, AddAccessDeniedAce, RegEnumValueA, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegSetValueExA, CopySid, GetLengthSid, GetTokenInformation, SetSecurityDescriptorDacl, AddAccessAllowedAce, AddAce, GetAce, InitializeAcl, GetAclInformation, GetSecurityDescriptorDacl, InitializeSecurityDescriptor, CreateProcessAsUserA, QueryServiceStatus, CloseServiceHandle, OpenServiceA, OpenSCManagerA, DuplicateTokenEx, GetUserNameA, RegOpenKeyA, EqualSid, AllocateAndInitializeSid, GetSidSubAuthority, GetSidSubAuthorityCount
gdi32.dll
CreateSolidBrush, SetTextColor, SetBkColor, TextOutA, GetStockObject, DeleteObject
kernel32.dll
GetSystemDirectoryA, CreateProcessA, LocalFree, lstrcpynA, SetErrorMode, GetDriveTypeA, GetLogicalDriveStringsA, CreateDirectoryA, WriteFile, GetCommandLineA, GetExitCodeProcess, WaitForSingleObject, LeaveCriticalSection, EnterCriticalSection, lstrcmpA, GetCurrentProcessId, OpenProcess, WaitForMultipleObjects, CreateFileA, CompareFileTime, GetLocalTime, CreateThread, GetModuleHandleA, GetSystemTimeAsFileTime, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetStartupInfoA, ExitProcess, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, DeviceIoControl, FindFirstFileA, FindClose, SetEvent, CreateEventA, CreateWaitableTimerA, GetCurrentProcess, InterlockedExchange, CloseHandle, SetWaitableTimer, LoadLibraryA, lstrcpyA, FormatMessageA, LocalAlloc, InterlockedDecrement, InterlockedIncrement, GetFileAttributesA, LoadLibraryExA, FreeLibrary, GetProcAddress, lstrlenA, GetVersion, FindResourceExA, FindResourceA, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSection, GetLastError, RaiseException, WideCharToMultiByte, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, SystemTimeToFileTime, lstrcatA
msvcp71.dll
DllMain
msvcr71.dll
DllMain
ole32.dll
CoUninitialize, CoInitialize, CoTaskMemFree, CoCreateInstance, OleRun
psapi.dll
EnumProcesses, EnumProcessModules, GetModuleBaseNameA
shell32.dll
ShellExecuteExA, ShellExecuteA, Shell_NotifyIconA, SHGetSpecialFolderPathA
shlwapi.dll
PathRemoveBackslashA, PathAddBackslashA
user32.dll
BeginPaint, ShowWindow, MoveWindow, SystemParametersInfoA, SetTimer, SendMessageA, DestroyWindow, KillTimer, ModifyMenuA, GetMenuStringA, RemoveMenu, GetSubMenu, GetSystemMenu, PostMessageA, SetForegroundWindow, GetCursorPos, SetUserObjectSecurity, GetUserObjectSecurity, CloseDesktop, CloseWindowStation, GetClientRect, SetProcessWindowStation, OpenWindowStationA, GetProcessWindowStation, DefWindowProcA, CreateDialogParamA, PostQuitMessage, DestroyMenu, IsIconic, RegisterWindowMessageA, SetMenuItemInfoA, LoadMenuA, LoadImageA, DispatchMessageA, IsDialogMessageA, GetMessageA, CreateWindowExA, RegisterClassA, FindWindowA, CharNextA, PeekMessageA, SetWindowTextA, GetDlgItem, EnableMenuItem, GetMenuState, CheckMenuItem, FillRect, LoadStringA, OpenDesktopA, TrackPopupMenu, LoadIconA, DrawIcon, EndPaint, GetSystemMetrics, MessageBoxA, ExitWindowsEx, wsprintfA, UnregisterClassA, GetLastActivePopup, TranslateMessage, LoadCursorA

vptray.exe

Symantec AntiVirus by Symantec Corporation (Signed)

Remove vptray.exe
Version:   10.1.9.9000
MD5:   77a4a7be0dd881c3f286841670c6aa0e
SHA1:   a5eff37202d807c7e1b7c577d11af8ceea87d6a4
SHA256:   b315abff4ac5a931b4519e7356f7834a1daf3cbdfdb6dc8ae9bbce9cbdb91cf5

Overview

vptray.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:vptray.exe
Publisher:Symantec Corporation
Product name:Symantec AntiVirus
Typical file path:C:\Program Files\symantec client security\symantec antivirus\vptray.exe
File version:10.1.9.9000
Size:122.43 KB (125,368 bytes)
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Monday, November 8, 2004
Expiration date:Monday, November 21, 2005
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 7.1
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'vptray' → C:\Program Files1\SYMANT~1\SYMANT~2\VPTray.exe

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 75.00%
Windows Vista Home Premium 25.00%

Distribution by countryDistribution by country

Turkey installs about 25.00% of Symantec AntiVirus.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE