Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12, 0, 12, 77 20.00%
12, 0, 12, 72 20.00%
12, 0, 12, 72 60.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
StartServiceCtrlDispatcherW, GetSecurityDescriptorOwner, RegCloseKey, AllocateAndInitializeSid, OpenSCManagerW, CloseServiceHandle, StartServiceW, GetSecurityDescriptorGroup, GetSecurityDescriptorSacl, GetSecurityDescriptorControl, MakeAbsoluteSD, GetAclInformation, GetSecurityDescriptorDacl, CryptImportKey, CryptDecrypt, CryptExportKey, CryptEncrypt, CryptGetUserKey, CryptGenKey, CryptDestroyKey, CryptSetProvParam, CryptGetProvParam, CryptAcquireContextW, CryptReleaseContext, OpenServiceW, ControlService, DeleteService, CreateServiceW, RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken, DuplicateTokenEx, LogonUserW, LookupAccountSidW, EnumServicesStatusW, QueryServiceStatus, SetServiceStatus, RegisterServiceCtrlHandlerExW, UnlockServiceDatabase, ChangeServiceConfigW, QueryServiceLockStatusW, LockServiceDatabase, RegQueryValueExA, RegOpenKeyExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegOpenCurrentUser, LookupPrivilegeValueW, SetEntriesInAclW, CreateWellKnownSid, GetTokenInformation, AdjustTokenPrivileges, QueryServiceConfigW, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, CopySid, GetLengthSid, IsValidSid, SetSecurityInfo, AddAce, InitializeAcl
bdfltlib.dll
FlStartDriver, FlStartScanner2, FlQueryDriver, FlStopScanner, FlGetTraceFile, FlSetTraceFile, FlGetLogFile, FlSetLogFile, FlKillConnections, FlInvalidateCacheEntryOfFile, FlGetOpt, FlRegisterBypassPid, FlSetOpt, FlSetOptVarlen, FlGetDriverVersion, FlUnregisterBypassPid
crypt32.dll
CryptUnprotectData, CryptProtectData
iphlpapi.dll
NotifyAddrChange
kernel32.dll
InitializeCriticalSection, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, FreeLibrary, SetEvent, ResetEvent, CloseHandle, InitializeCriticalSectionAndSpinCount, ReleaseSemaphore, GetCurrentThreadId, lstrlenA, WaitForSingleObject, InterlockedExchangeAdd, MoveFileExW, GetCurrentProcessId, ReleaseMutex, GetTickCount, LocalFree, GetVersion, OpenProcess, GetCurrentProcess, SetProcessWorkingSetSize, CreateThread, GetExitCodeProcess, TerminateProcess, TryEnterCriticalSection, LocalAlloc, DeviceIoControl, ExitProcess, GetCommandLineW, WaitForMultipleObjects, FindClose, LeaveCriticalSection, GetSystemTime, FileTimeToSystemTime, GetFileTime, SetFilePointer, WriteFile, GlobalUnlock, GlobalLock, UnmapViewOfFile, TerminateThread, MapViewOfFile, GetSystemInfo, DuplicateHandle, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, InterlockedCompareExchange, PostQueuedCompletionStatus, GetQueuedCompletionStatus, CreateIoCompletionPort, ResumeThread, GetFileSize, ReadFile, LoadLibraryA, CompareStringA, GetModuleHandleA, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, EnterCriticalSection, RaiseException, GetLocalTime, InterlockedExchange, Sleep, LoadResource, LockResource, SizeofResource, GetLastError, UnhandledExceptionFilter, GetProcessHeap, HeapSize, SetLastError, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, SetThreadPriority, GetLogicalDrives
midascomm.dll
MdSetMidasDirectory, MdLoadInitAndActivateMdexSignatures, MdUninitialize, MdSetOptVarlen, MdGetOpt, MdSetOpt, MdSetTraceFile, MdSetLogFile, MdInitialize, MdLoadInitAndActivateNeurons
msvcp80.dll
DllMain
msvcr80.dll
DllMain
netapi32.dll
NetUserAdd, NetApiBufferFree, NetUserGetInfo, NetUserEnum, NetServerGetInfo, NetUserChangePassword, NetUserSetInfo, NetUserDel
ole32.dll
CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoMarshalInterface, CoGetClassObject, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, OleRun, StringFromGUID2, CoRevokeClassObject, CoRegisterClassObject, GetHGlobalFromStream, CreateStreamOnHGlobal, CoSetProxyBlanket, CoGetObject, CLSIDFromProgID, CoReleaseMarshalData
psapi.dll
EnumProcesses, GetModuleFileNameExW
rpcrt4.dll
UuidFromStringW, UuidCreateSequential, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiEnumDeviceInterfaces, SetupDiGetDeviceInterfaceDetailW, SetupDiDestroyDeviceInfoList
shell32.dll
SHGetFileInfoW, SHGetFolderPathW, SHGetSpecialFolderLocation, SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathRemoveBackslashW, PathFindExtensionW, UrlUnescapeW, PathAddBackslashW, PathFileExistsW, PathRemoveFileSpecW, PathIsRelativeW
user32.dll
GetUserObjectInformationW, GetForegroundWindow, AllowSetForegroundWindow, ShowWindow, TranslateMessage, PostQuitMessage, GetThreadDesktop, KillTimer, LoadImageW, UnregisterClassA
userenv.dll
ExpandEnvironmentStringsForUserW
wininet.dll
InternetCloseHandle, InternetOpenUrlA, InternetOpenA, InternetReadFile
wintrust.dll
WinVerifyTrust, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminReleaseContext, CryptCATAdminAcquireContext, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext
ws2_32.dll
WSARecvFrom, WSAGetOverlappedResult, WSASendTo, WSACreateEvent, WSASocketW
wslib.dll
WSLibNew, WSLibDelete

vsserv.exe

BitDefender 2009 by BITDEFENDER LLC (Signed)

Remove vsserv.exe
Version:   12, 0, 12, 77
MD5:   517aeba6196c606fa6380aee1befdfc6
SHA1:   b8114bf605dabb7fb83120afed1d088bde0e3edc

What is vsserv.exe?

BitDefender Security Service is part of Bitdefender, an antivirus software suite developed by Romania-based software company Softwin. Bitdefender is designed to protect computers from viruses and spyware. Unlike the commercial version, the free tools only offer an on-demand virus scanning and doesn't provide real time scanning.

About vsserv.exe (from BITDEFENDER LLC)

Bitdefender antivirus technology to secure online transactions, protect mobile devices from theft, automatically back up files, and Tune-Up PCs. Active Virus Control is a proactive, dynamic detection

DetailsDetails

File name:vsserv.exe
Publisher:BitDefender S. R. L.
Product name:BitDefender 2009
Description:BitDefender Security Service
Typical file path:C:\Program Files\bitdefender\bitdefender 2009\vsserv.exe
File version:12, 0, 12, 77
Product version:12, 0, 192, 0
Size:2.49 MB (2,609,632 bytes)
Certificate
Issued to:BITDEFENDER LLC
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VSSERV' (BitDefender Virus Shield)
Network connections
  • [UDP] listens on port 10000

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00057107%
    0.028634%
    Kernel CPU:0.00016385%
    0.013761%
    User CPU:0.00040723%
    0.014873%
    Kernel CPU time:372,218,386 ms/min
    100,923,805ms/min
    Memory
    Private memory:97.46 MB
    21.59 MB
    Private (maximum):31.84 MB
    Private (minimum):1.59 MB
    Non-paged memory:97.46 MB
    21.59 MB
    Virtual memory:538.22 MB
    140.96 MB
    Virtual memory (peak):545.86 MB
    169.69 MB
    Working set:12.02 MB
    18.61 MB
    Working set (peak):76.89 MB
    37.95 MB
    Resource allocations
    Threads:51
    12
    Handles:509
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command line:"C:\Program Files\bitdefender\bitdefender 2009\vsserv.exe" /service
    Owner:User
    Windows Service
    Service name:VSSERV
    Display name:BitDefender Virus Shield
    Description:“Scans media for viruses and other security threats”
    Type:Win32OwnProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 60.00%
    Windows Vista Home Premium 20.00%
    Windows 7 Ultimate 20.00%

    Distribution by countryDistribution by country

    United States installs about 40.00% of BitDefender 2009.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Acer 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE