Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

17.28.0.1186 104613 41.67%
17.22.0.975 102614 8.33%
17.21.0.908 102416 8.33%
17.20.0.873 102352 8.33%
17.18.0.799 102139 8.33%
17.13.0.537 101386 25.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
QueryServiceLockStatusW, RegDeleteKeyW, GetTokenInformation, IsValidSid, ConvertSidToStringSidW, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, SetTokenInformation, AdjustTokenPrivileges, CreateProcessAsUserW, AllocateAndInitializeSid, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumKeyExW, RegQueryInfoKeyW, RegEnumValueW, ImpersonateLoggedOnUser, RevertToSelf, CloseServiceHandle, EnumServicesStatusW, OpenSCManagerW, DeleteService, OpenServiceW, QueryServiceStatus, SetServiceStatus, StartServiceW, ControlService, RegisterServiceCtrlHandlerExW, UnlockServiceDatabase, ChangeServiceConfigW, LockServiceDatabase, CreateServiceW, StartServiceCtrlDispatcherW, RegQueryValueExA, RegOpenKeyExA, RegOpenKeyW, RegCreateKeyW, LookupAccountSidW, RegOpenCurrentUser, GetUserNameW, RegDeleteValueW
crypt32.dll
CryptUnprotectData
dnsapi.dll
DnsQuery_A, DnsFree
iphlpapi.dll
DeleteIpForwardEntry, GetIpForwardTable, CreateIpForwardEntry
kernel32.dll
GetDriveTypeW, GetLogicalDrives, InterlockedExchange, QueryPerformanceCounter, MoveFileExW, QueryPerformanceFrequency, FormatMessageW, GetVersionExW, LocalAlloc, GetCommandLineW, GetPrivateProfileStringW, CreateEventW, CreateThread, GetTempPathW, CreateProcessW, UnmapViewOfFile, WaitForMultipleObjects, MapViewOfFile, CreateFileMappingW, GetTickCount, SystemTimeToFileTime, GetSystemTime, GetProcessTimes, CreateFileW, GetExitCodeProcess, WritePrivateProfileStringW, GetFileSizeEx, CopyFileW, GetUserDefaultLCID, GetTimeFormatW, GetDateFormatW, GetProcessHeap, GetEnvironmentVariableW, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, GetPrivateProfileIntW, TerminateProcess, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer, HeapSize, HeapReAlloc, HeapDestroy, InitializeCriticalSectionAndSpinCount, RaiseException, LoadLibraryA, HeapAlloc, HeapFree, SetProcessWorkingSetSize, GetCurrentProcessId, LocalFree, GetModuleHandleW, LoadLibraryExW, GetCurrentProcess, GetFirmwareEnvironmentVariableW, WTSGetActiveConsoleSessionId, CreateToolhelp32Snapshot, Process32FirstW, Sleep, ProcessIdToSessionId, Process32NextW, OpenProcess, CreateDirectoryW, GetModuleFileNameW, lstrlenW, CloseHandle, SetEvent, lstrlenA, ExpandEnvironmentStringsW, MultiByteToWideChar, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, OutputDebugStringW, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, WaitForSingleObject, UnhandledExceptionFilter, CreateSemaphoreW, GetCurrentThreadId, ReleaseSemaphore, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, FindFirstFileW, DeleteFileW, FindNextFileW, FindClose, RemoveDirectoryW, GetFileAttributesW, SetFileAttributesW, GetLastError, CreateMutexW, LoadLibraryW, GetProcAddress, FreeLibrary, ReleaseMutex
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
StringFromGUID2, CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoGetObject
shell32.dll
ShellExecuteExW, ShellExecuteW, CommandLineToArgvW, SHGetFolderPathW
shlwapi.dll
PathFileExistsW, PathIsDirectoryW, PathAppendW, PathStripPathW, PathRemoveExtensionW, PathRemoveFileSpecW, PathIsRelativeW, PathAddBackslashW, PathQuoteSpacesW
userenv.dll
CreateEnvironmentBlock
winmm.dll
timeGetTime
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW
Export table
OPENSSL_Applink

vsserv.exe

Bitdefender 2014 by Bitdefender SRL (Signed)

Remove vsserv.exe
Version:   17.20.0.873 102352
MD5:   a6cc7575a4add6b55367dd5c1652d5d0
SHA1:   6b71acbd6e54d868fa0c0c0124512058efa2f5ba

Overview

vsserv.exe runs as a service under the name Bitdefender Virus Shield (VSSERV) with extensive SYSTEM privileges (full administrator access). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Bitdefender SRL which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:vsserv.exe
Publisher:Bitdefender
Product name:Bitdefender 2014
Description:Bitdefender Security Service
Typical file path:C:\Program Files\bitdefender\bitdefender\vsserv.exe
File version:17.20.0.873 102352
Size:1.44 MB (1,506,736 bytes)
Build date:10/14/2013 5:39 AM
Certificate
Issued to:Bitdefender SRL
Authority (CA):VeriSign
Effective date:Saturday, May 12, 2012
Expiration date:Thursday, May 1, 2014
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VSSERV' (Bitdefender Virus Shield)
Network connections
  • [TCP] push1.amz.vdc.bitdefender.net (54.235.219.195:4001)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00015368%
    0.028634%
    Kernel CPU:0.00012528%
    0.013761%
    User CPU:0.00002839%
    0.014873%
    Kernel CPU time:169,932 ms/min
    100,923,805ms/min
    CPU cycles:3,187,887/sec
    17,470,203/sec
    Memory
    Private memory:186.62 MB
    21.59 MB
    Private (maximum):69.46 MB
    Private (minimum):1.52 MB
    Non-paged memory:186.62 MB
    21.59 MB
    Virtual memory:831.62 MB
    140.96 MB
    Virtual memory (peak):1.68 GB
    169.69 MB
    Working set:6.04 MB
    18.61 MB
    Working set (peak):359.94 MB
    37.95 MB
    Page faults:9,194,884/min
    2,039/min
    I/O
    I/O read transfer:47.89 KB/sec
    1.02 MB/min
    I/O read operations:97/sec
    343/min
    I/O write transfer:35.75 KB/sec
    274.99 KB/min
    I/O write operations:70/sec
    227/min
    I/O other transfer:618.48 KB/sec
    448.09 KB/min
    I/O other operations:1,185/sec
    1,671/min
    Resource allocations
    Threads:76
    12
    Handles:1921
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command line:"C:\Program Files\bitdefender\bitdefender\vsserv.exe" /service
    Owner:SYSTEM
    Windows Service
    Service name:VSSERV
    Display name:Bitdefender Virus Shield
    Type:Win32OwnProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    apprep.dll (Bitdefender Security by Bitdefender)
    Total CPU:0.01661702%
    0.272967%
    Kernel CPU:0.00787608%
    0.107585%
    User CPU:0.00874094%
    0.165382%
    CPU cycles:449,649/sec
    5,741,424/sec
    Memory:332 KB
    1.16 MB
    bdpredir.dll (BitDefender Firewall by BitDefender)
    Total CPU:0.01013404%
    Kernel CPU:0.00483569%
    User CPU:0.00529835%
    CPU cycles:282,009/sec
    Memory:112 KB
    accessal.dll (Bitdefender Security by Bitdefender)
    Total CPU:0.00486167%
    Kernel CPU:0.00290105%
    User CPU:0.00196062%
    CPU cycles:127,082/sec
    Memory:344 KB
    gzfltum.dll (BitDefender by BitDefender)
    Total CPU:0.00218568%
    Kernel CPU:0.00038413%
    User CPU:0.00180155%
    CPU cycles:59,202/sec
    Memory:84 KB
    framework.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00124720%
    Kernel CPU:0.00113093%
    User CPU:0.00011627%
    CPU cycles:106,345/sec
    Memory:196 KB
    sechost.dll (Host for SCM/SDDL/LSA Lookup APIs by Microsoft)
    Total CPU:0.00108733%
    Kernel CPU:0.00024349%
    User CPU:0.00084384%
    CPU cycles:30,146/sec
    Memory:124 KB
    serverpush.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00084808%
    Kernel CPU:0.00057938%
    User CPU:0.00026870%
    CPU cycles:22,113/sec
    Memory:164 KB
    safeboxal.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00055006%
    Kernel CPU:0.00015536%
    User CPU:0.00039470%
    CPU cycles:88,203/sec
    Memory:260 KB
    npcomm.dll (BitDefender 16 by BitDefender LLC)
    Total CPU:0.00022810%
    Kernel CPU:0.00011475%
    User CPU:0.00011335%
    CPU cycles:24,264/sec
    Memory:136 KB
    bdnc.dll (BitDefender Nimbus Client by Bitdefender)
    Total CPU:0.00019731%
    Kernel CPU:0.00009656%
    User CPU:0.00010076%
    CPU cycles:8,266/sec
    Memory:2.01 MB
    avccore.dll (BitDefender AntiVirus by BitDefender S.R.L. Bucharest, ROMANIA)
    Total CPU:0.00014694%
    Kernel CPU:0.00011388%
    User CPU:0.00003306%
    CPU cycles:3,887/sec
    Memory:372 KB
    loggeral.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00011336%
    Kernel CPU:0.00010496%
    User CPU:0.00000840%
    CPU cycles:3,024/sec
    Memory:84 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 25.00%
    Windows 7 Ultimate 16.67%
    Windows 7 Professional 16.67%
    Windows 8.1 8.33%
    Windows 8.1 Pro with Media Center 8.33%
    Windows 8.1 Pro 8.33%
    Windows 7 Home Premium 8.33%
    Microsoft Windows XP 8.33%

    Distribution by countryDistribution by country

    United States installs about 58.33% of Bitdefender 2014.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Lenovo 30.77%
    Apple 30.77%
    Hewlett-Packard 23.08%
    Acer 7.69%
    Samsung 7.69%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE