Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

17.28.0.1186 104613 41.67%
17.22.0.975 102614 8.33%
17.21.0.908 102416 8.33%
17.20.0.873 102352 8.33%
17.18.0.799 102139 8.33%
17.13.0.537 101386 25.00%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
QueryServiceLockStatusW, RegDeleteKeyW, GetTokenInformation, IsValidSid, ConvertSidToStringSidW, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, SetTokenInformation, AdjustTokenPrivileges, CreateProcessAsUserW, AllocateAndInitializeSid, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumKeyExW, RegQueryInfoKeyW, RegEnumValueW, ImpersonateLoggedOnUser, RevertToSelf, CloseServiceHandle, EnumServicesStatusW, OpenSCManagerW, DeleteService, OpenServiceW, QueryServiceStatus, SetServiceStatus, StartServiceW, ControlService, RegisterServiceCtrlHandlerExW, UnlockServiceDatabase, ChangeServiceConfigW, LockServiceDatabase, CreateServiceW, StartServiceCtrlDispatcherW, RegQueryValueExA, RegOpenKeyExA, RegOpenKeyW, RegCreateKeyW, LookupAccountSidW, RegOpenCurrentUser, GetUserNameW, RegDeleteValueW
crypt32.dll
CryptUnprotectData
dnsapi.dll
DnsQuery_A, DnsFree
iphlpapi.dll
DeleteIpForwardEntry, GetIpForwardTable, CreateIpForwardEntry
kernel32.dll
GetDriveTypeW, GetLogicalDrives, InterlockedExchange, QueryPerformanceCounter, MoveFileExW, QueryPerformanceFrequency, FormatMessageW, GetVersionExW, LocalAlloc, GetCommandLineW, GetPrivateProfileStringW, CreateEventW, CreateThread, GetTempPathW, CreateProcessW, UnmapViewOfFile, WaitForMultipleObjects, MapViewOfFile, CreateFileMappingW, GetTickCount, SystemTimeToFileTime, GetSystemTime, GetProcessTimes, CreateFileW, GetExitCodeProcess, WritePrivateProfileStringW, GetFileSizeEx, CopyFileW, GetUserDefaultLCID, GetTimeFormatW, GetDateFormatW, GetProcessHeap, GetEnvironmentVariableW, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, GetPrivateProfileIntW, TerminateProcess, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer, HeapSize, HeapReAlloc, HeapDestroy, InitializeCriticalSectionAndSpinCount, RaiseException, LoadLibraryA, HeapAlloc, HeapFree, SetProcessWorkingSetSize, GetCurrentProcessId, LocalFree, GetModuleHandleW, LoadLibraryExW, GetCurrentProcess, GetFirmwareEnvironmentVariableW, WTSGetActiveConsoleSessionId, CreateToolhelp32Snapshot, Process32FirstW, Sleep, ProcessIdToSessionId, Process32NextW, OpenProcess, CreateDirectoryW, GetModuleFileNameW, lstrlenW, CloseHandle, SetEvent, lstrlenA, ExpandEnvironmentStringsW, MultiByteToWideChar, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, OutputDebugStringW, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, WaitForSingleObject, UnhandledExceptionFilter, CreateSemaphoreW, GetCurrentThreadId, ReleaseSemaphore, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, FindFirstFileW, DeleteFileW, FindNextFileW, FindClose, RemoveDirectoryW, GetFileAttributesW, SetFileAttributesW, GetLastError, CreateMutexW, LoadLibraryW, GetProcAddress, FreeLibrary, ReleaseMutex
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
StringFromGUID2, CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoGetObject
shell32.dll
ShellExecuteExW, ShellExecuteW, CommandLineToArgvW, SHGetFolderPathW
shlwapi.dll
PathFileExistsW, PathIsDirectoryW, PathAppendW, PathStripPathW, PathRemoveExtensionW, PathRemoveFileSpecW, PathIsRelativeW, PathAddBackslashW, PathQuoteSpacesW
userenv.dll
CreateEnvironmentBlock
winmm.dll
timeGetTime
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW
Export table
OPENSSL_Applink

vsserv.exe

Bitdefender 2014 by Bitdefender SRL (Signed)

Remove vsserv.exe
Version:   17.13.0.537 101386
MD5:   88773db4fc5f2304e5510aec166568b9
SHA1:   558e3b94481c6cf5bdd504e01088b21bd42d149e
SHA256:   7ef73f578d1e71c709523479261c8cab738d8db2d78f136b62844ab65052b88f

Overview

vsserv.exe runs as a service under the name Bitdefender Virus Shield (VSSERV) with extensive SYSTEM privileges (full administrator access). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Bitdefender SRL which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:vsserv.exe
Publisher:Bitdefender
Product name:Bitdefender 2014
Description:Bitdefender Security Service
Typical file path:C:\Program Files\bitdefender\bitdefender\vsserv.exe
File version:17.13.0.537 101386
Size:1.43 MB (1,502,080 bytes)
Build date:6/20/2013 3:15 PM
Certificate
Issued to:Bitdefender SRL
Authority (CA):VeriSign
Effective date:Saturday, May 12, 2012
Expiration date:Thursday, May 1, 2014
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VSSERV' (Bitdefender Virus Shield)
Network connections
  • [TCP] push1.amz.vdc.bitdefender.net (54.235.219.195:4002)
  • [UDP] listens on port 50578
  • [UDP] listens on port 49152

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00046496%
    0.028634%
    Kernel CPU:0.00018167%
    0.013761%
    User CPU:0.00028329%
    0.014873%
    Kernel CPU time:87,128,847 ms/min
    100,923,805ms/min
    CPU cycles:13,515,786/sec
    17,470,203/sec
    Context switches:54/sec
    284/sec
    Memory
    Private memory:213.46 MB
    21.59 MB
    Private (maximum):154.92 MB
    Private (minimum):1.6 MB
    Non-paged memory:213.46 MB
    21.59 MB
    Virtual memory:786.65 MB
    140.96 MB
    Working set:42.89 MB
    18.61 MB
    Working set (peak):175.74 MB
    37.95 MB
    Page faults:19,251,037/min
    2,039/min
    I/O
    I/O read transfer:1.05 MB/sec
    1.02 MB/min
    I/O read operations:522/sec
    343/min
    I/O write transfer:1.13 MB/sec
    274.99 KB/min
    I/O write operations:1,014/sec
    227/min
    I/O other transfer:336.32 KB/sec
    448.09 KB/min
    I/O other operations:1,504/sec
    1,671/min
    Resource allocations
    Threads:89
    12
    Handles:2000
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command line:"C:\Program Files\bitdefender\bitdefender\vsserv.exe" /service
    Owner:SYSTEM
    Windows Service
    Service name:VSSERV
    Display name:Bitdefender Virus Shield
    Type:Win32OwnProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    apprep.dll (Bitdefender Security by Bitdefender)
    Total CPU:0.03985020%
    0.272967%
    Kernel CPU:0.01086315%
    0.107585%
    User CPU:0.02898706%
    0.165382%
    CPU cycles:1,254,474/sec
    5,741,424/sec
    Context switches:1/sec
    79/sec
    Memory:304 KB
    1.16 MB
    bdpredir.dll (BitDefender Firewall by BitDefender)
    Total CPU:0.01544416%
    Kernel CPU:0.00347932%
    User CPU:0.01196483%
    CPU cycles:529,846/sec
    Context switches:1/sec
    Memory:112 KB
    gzfltum.dll (BitDefender by BitDefender)
    Total CPU:0.00953962%
    Kernel CPU:0.00098925%
    User CPU:0.00855037%
    CPU cycles:317,513/sec
    Memory:84 KB
    sechost.dll (Host for SCM/SDDL/LSA Lookup APIs by Microsoft)
    Total CPU:0.00595390%
    Kernel CPU:0.00115718%
    User CPU:0.00479671%
    CPU cycles:186,408/sec
    Memory:124 KB
    serverpush.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00589866%
    Kernel CPU:0.00412533%
    User CPU:0.00177333%
    CPU cycles:190,470/sec
    Memory:164 KB
    framework.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00502602%
    Kernel CPU:0.00188509%
    User CPU:0.00314093%
    CPU cycles:452,963/sec
    Context switches:3/sec
    Memory:196 KB
    ntdll.dll
    Total CPU:0.00322276%
    Kernel CPU:0.00009332%
    User CPU:0.00312944%
    CPU cycles:86,927/sec
    Context switches:1/sec
    Memory:1.66 MB
    npcomm.dll (BitDefender 16 by BitDefender LLC)
    Total CPU:0.00204685%
    Kernel CPU:0.00105142%
    User CPU:0.00099543%
    CPU cycles:224,287/sec
    Context switches:2/sec
    Memory:136 KB
    bdfwcore.dll (BitDefender Firewall)
    Total CPU:0.00148391%
    Kernel CPU:0.00011199%
    User CPU:0.00137192%
    CPU cycles:47,056/sec
    Memory:168 KB
    avccore.dll (BitDefender AntiVirus by BitDefender S.R.L. Bucharest, ROMANIA)
    Total CPU:0.00013532%
    Kernel CPU:0.00010966%
    User CPU:0.00002566%
    CPU cycles:4,950/sec
    Memory:364 KB
    loggeral.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00013067%
    Kernel CPU:0.00013067%
    User CPU:0.00000000%
    CPU cycles:17,974/sec
    Memory:84 KB
    msvcr100.dll (Microsoft Visual Studio 2010 by Microsoft)
    Total CPU:0.00005600%
    Kernel CPU:0.00001867%
    User CPU:0.00003733%
    CPU cycles:34,211/sec
    Memory:840 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 25.00%
    Windows 7 Ultimate 16.67%
    Windows 7 Professional 16.67%
    Windows 8.1 8.33%
    Windows 8.1 Pro with Media Center 8.33%
    Windows 8.1 Pro 8.33%
    Windows 7 Home Premium 8.33%
    Microsoft Windows XP 8.33%

    Distribution by countryDistribution by country

    United States installs about 58.33% of Bitdefender 2014.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Lenovo 30.77%
    Apple 30.77%
    Hewlett-Packard 23.08%
    Acer 7.69%
    Samsung 7.69%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE