Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12, 0, 12, 77 20.00%
12, 0, 12, 72 20.00%
12, 0, 12, 72 60.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
StartServiceCtrlDispatcherW, GetSecurityDescriptorOwner, RegCloseKey, AllocateAndInitializeSid, OpenSCManagerW, CloseServiceHandle, StartServiceW, GetSecurityDescriptorGroup, GetSecurityDescriptorSacl, GetSecurityDescriptorControl, MakeAbsoluteSD, GetAclInformation, GetSecurityDescriptorDacl, CryptImportKey, CryptDecrypt, CryptExportKey, CryptEncrypt, CryptGetUserKey, CryptGenKey, CryptDestroyKey, CryptSetProvParam, CryptGetProvParam, CryptAcquireContextW, CryptReleaseContext, OpenServiceW, ControlService, DeleteService, CreateServiceW, RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken, DuplicateTokenEx, LogonUserW, LookupAccountSidW, EnumServicesStatusW, QueryServiceStatus, SetServiceStatus, RegisterServiceCtrlHandlerExW, UnlockServiceDatabase, ChangeServiceConfigW, QueryServiceLockStatusW, LockServiceDatabase, RegQueryValueExA, RegOpenKeyExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegOpenCurrentUser, LookupPrivilegeValueW, SetEntriesInAclW, CreateWellKnownSid, GetTokenInformation, AdjustTokenPrivileges, QueryServiceConfigW, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, CopySid, GetLengthSid, IsValidSid, SetSecurityInfo, AddAce, InitializeAcl
bdfltlib.dll
FlStartDriver, FlStartScanner2, FlQueryDriver, FlStopScanner, FlGetTraceFile, FlSetTraceFile, FlGetLogFile, FlSetLogFile, FlKillConnections, FlInvalidateCacheEntryOfFile, FlGetOpt, FlRegisterBypassPid, FlSetOpt, FlSetOptVarlen, FlGetDriverVersion, FlUnregisterBypassPid
crypt32.dll
CryptUnprotectData, CryptProtectData
iphlpapi.dll
NotifyAddrChange
kernel32.dll
InitializeCriticalSection, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, FreeLibrary, SetEvent, ResetEvent, CloseHandle, InitializeCriticalSectionAndSpinCount, ReleaseSemaphore, GetCurrentThreadId, lstrlenA, WaitForSingleObject, InterlockedExchangeAdd, MoveFileExW, GetCurrentProcessId, ReleaseMutex, GetTickCount, LocalFree, GetVersion, OpenProcess, GetCurrentProcess, SetProcessWorkingSetSize, CreateThread, GetExitCodeProcess, TerminateProcess, TryEnterCriticalSection, LocalAlloc, DeviceIoControl, ExitProcess, GetCommandLineW, WaitForMultipleObjects, FindClose, LeaveCriticalSection, GetSystemTime, FileTimeToSystemTime, GetFileTime, SetFilePointer, WriteFile, GlobalUnlock, GlobalLock, UnmapViewOfFile, TerminateThread, MapViewOfFile, GetSystemInfo, DuplicateHandle, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, InterlockedCompareExchange, PostQueuedCompletionStatus, GetQueuedCompletionStatus, CreateIoCompletionPort, ResumeThread, GetFileSize, ReadFile, LoadLibraryA, CompareStringA, GetModuleHandleA, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, EnterCriticalSection, RaiseException, GetLocalTime, InterlockedExchange, Sleep, LoadResource, LockResource, SizeofResource, GetLastError, UnhandledExceptionFilter, GetProcessHeap, HeapSize, SetLastError, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, SetThreadPriority, GetLogicalDrives
midascomm.dll
MdSetMidasDirectory, MdLoadInitAndActivateMdexSignatures, MdUninitialize, MdSetOptVarlen, MdGetOpt, MdSetOpt, MdSetTraceFile, MdSetLogFile, MdInitialize, MdLoadInitAndActivateNeurons
msvcp80.dll
DllMain
msvcr80.dll
DllMain
netapi32.dll
NetUserAdd, NetApiBufferFree, NetUserGetInfo, NetUserEnum, NetServerGetInfo, NetUserChangePassword, NetUserSetInfo, NetUserDel
ole32.dll
CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoMarshalInterface, CoGetClassObject, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, OleRun, StringFromGUID2, CoRevokeClassObject, CoRegisterClassObject, GetHGlobalFromStream, CreateStreamOnHGlobal, CoSetProxyBlanket, CoGetObject, CLSIDFromProgID, CoReleaseMarshalData
psapi.dll
EnumProcesses, GetModuleFileNameExW
rpcrt4.dll
UuidFromStringW, UuidCreateSequential, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiEnumDeviceInterfaces, SetupDiGetDeviceInterfaceDetailW, SetupDiDestroyDeviceInfoList
shell32.dll
SHGetFileInfoW, SHGetFolderPathW, SHGetSpecialFolderLocation, SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathRemoveBackslashW, PathFindExtensionW, UrlUnescapeW, PathAddBackslashW, PathFileExistsW, PathRemoveFileSpecW, PathIsRelativeW
user32.dll
GetUserObjectInformationW, GetForegroundWindow, AllowSetForegroundWindow, ShowWindow, TranslateMessage, PostQuitMessage, GetThreadDesktop, KillTimer, LoadImageW, UnregisterClassA
userenv.dll
ExpandEnvironmentStringsForUserW
wininet.dll
InternetCloseHandle, InternetOpenUrlA, InternetOpenA, InternetReadFile
wintrust.dll
WinVerifyTrust, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminReleaseContext, CryptCATAdminAcquireContext, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext
ws2_32.dll
WSARecvFrom, WSAGetOverlappedResult, WSASendTo, WSACreateEvent, WSASocketW
wslib.dll
WSLibNew, WSLibDelete

vsserv.exe

BitDefender 2009 by BITDEFENDER LLC (Signed)

Remove vsserv.exe
Version:   12, 0, 12, 72
MD5:   95c72765a76e6d49fa76539f9a623fb2
SHA1:   850460d7920d72efccb474cb6f35f8a8c653f391
SHA256:   2f988e73cbf82a52ffd36fdff76c1a5d354f19bc8817ab625afbda8275b8701a

What is vsserv.exe?

BitDefender Security Service is part of Bitdefender, an antivirus software suite developed by Romania-based software company Softwin. Bitdefender is designed to protect computers from viruses and spyware. Unlike the commercial version, the free tools only offer an on-demand virus scanning and doesn't provide real time scanning.

About vsserv.exe (from BITDEFENDER LLC)

Bitdefender antivirus technology to secure online transactions, protect mobile devices from theft, automatically back up files, and Tune-Up PCs. Active Virus Control is a proactive, dynamic detection

DetailsDetails

File name:vsserv.exe
Publisher:BitDefender S. R. L.
Product name:BitDefender 2009
Description:BitDefender Security Service
Typical file path:C:\Program Files\bitdefender\bitdefender 2009\vsserv.exe
File version:12, 0, 12, 72
Product version:12, 0, 192, 0
Size:2.46 MB (2,578,944 bytes)
Certificate
Issued to:BITDEFENDER LLC
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VSSERV' (BitDefender Virus Shield)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00058010%
0.028634%
Kernel CPU:0.00026441%
0.013761%
User CPU:0.00031569%
0.014873%
Kernel CPU time:57,502 ms/min
100,923,805ms/min
CPU cycles:2,972,908/sec
17,470,203/sec
Memory
Private memory:110.68 MB
21.59 MB
Private (maximum):71.76 MB
Private (minimum):1.5 MB
Non-paged memory:110.68 MB
21.59 MB
Virtual memory:569.69 MB
140.96 MB
Virtual memory (peak):865.74 MB
169.69 MB
Working set:10.87 MB
18.61 MB
Working set (peak):119.43 MB
37.95 MB
Page faults:14,434,347/min
2,039/min
I/O
I/O read transfer:887.8 KB/sec
1.02 MB/min
I/O read operations:238/sec
343/min
I/O write transfer:628.27 KB/sec
274.99 KB/min
I/O write operations:146/sec
227/min
I/O other transfer:4.48 KB/sec
448.09 KB/min
I/O other operations:180/sec
1,671/min
Resource allocations
Threads:70
12
Handles:1173
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\bitdefender\bitdefender 2009\vsserv.exe" /service
Owner:SYSTEM
Windows Service
Service name:VSSERV
Display name:BitDefender Virus Shield
Description:“Scans media for viruses and other security threats”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
vsserv.exe (main module)
Total CPU:0.00966181%
0.272967%
Kernel CPU:0.00397105%
0.107585%
User CPU:0.00569076%
0.165382%
CPU cycles:346,358/sec
5,741,424/sec
Context switches:7/sec
79/sec
Memory:2.64 MB
1.16 MB
ntdll.dll
Total CPU:0.00122768%
Kernel CPU:0.00000000%
User CPU:0.00122768%
CPU cycles:1,965/sec
Memory:1.66 MB
midascomm.dll (BitDefender AntiVirus by BitDefender S.R.L. Bucharest, ROMANIA)
Total CPU:0.00064006%
Kernel CPU:0.00016351%
User CPU:0.00047655%
CPU cycles:7,478/sec
Memory:424 KB
sechost.dll (Host for SCM/SDDL/LSA Lookup APIs by Microsoft)
Total CPU:0.00006528%
Kernel CPU:0.00004943%
User CPU:0.00001585%
CPU cycles:1,445/sec
Memory:124 KB
MSVCR80.dll
Total CPU:0.00006339%
Kernel CPU:0.00000000%
User CPU:0.00006339%
CPU cycles:1,892/sec
Memory:804 KB
npcomm.dll (BitDefender 12 by BitDefender LLC)
Total CPU:0.00002986%
Kernel CPU:0.00001013%
User CPU:0.00001973%
CPU cycles:17,039/sec
Memory:76 KB
bdfltlib.dll (BitDefender AntiVirus by BitDefender S.R.L. Bucharest, ROMANIA)
Total CPU:0.00002827%
Kernel CPU:0.00002138%
User CPU:0.00000689%
CPU cycles:642/sec
Memory:296 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 60.00%
Windows Vista Home Premium 20.00%
Windows 7 Ultimate 20.00%

Distribution by countryDistribution by country

United States installs about 40.00% of BitDefender 2009.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE