Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

17.28.0.1186 104613 41.67%
17.22.0.975 102614 8.33%
17.21.0.908 102416 8.33%
17.20.0.873 102352 8.33%
17.18.0.799 102139 8.33%
17.13.0.537 101386 25.00%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
QueryServiceLockStatusW, RegDeleteKeyW, GetTokenInformation, IsValidSid, ConvertSidToStringSidW, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, SetTokenInformation, AdjustTokenPrivileges, CreateProcessAsUserW, AllocateAndInitializeSid, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumKeyExW, RegQueryInfoKeyW, RegEnumValueW, ImpersonateLoggedOnUser, RevertToSelf, CloseServiceHandle, EnumServicesStatusW, OpenSCManagerW, DeleteService, OpenServiceW, QueryServiceStatus, SetServiceStatus, StartServiceW, ControlService, RegisterServiceCtrlHandlerExW, UnlockServiceDatabase, ChangeServiceConfigW, LockServiceDatabase, CreateServiceW, StartServiceCtrlDispatcherW, RegQueryValueExA, RegOpenKeyExA, RegOpenKeyW, RegCreateKeyW, LookupAccountSidW, RegOpenCurrentUser, GetUserNameW, RegDeleteValueW
crypt32.dll
CryptUnprotectData
dnsapi.dll
DnsQuery_A, DnsFree
iphlpapi.dll
DeleteIpForwardEntry, GetIpForwardTable, CreateIpForwardEntry
kernel32.dll
GetDriveTypeW, GetLogicalDrives, InterlockedExchange, QueryPerformanceCounter, MoveFileExW, QueryPerformanceFrequency, FormatMessageW, GetVersionExW, LocalAlloc, GetCommandLineW, GetPrivateProfileStringW, CreateEventW, CreateThread, GetTempPathW, CreateProcessW, UnmapViewOfFile, WaitForMultipleObjects, MapViewOfFile, CreateFileMappingW, GetTickCount, SystemTimeToFileTime, GetSystemTime, GetProcessTimes, CreateFileW, GetExitCodeProcess, WritePrivateProfileStringW, GetFileSizeEx, CopyFileW, GetUserDefaultLCID, GetTimeFormatW, GetDateFormatW, GetProcessHeap, GetEnvironmentVariableW, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, GetPrivateProfileIntW, TerminateProcess, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer, HeapSize, HeapReAlloc, HeapDestroy, InitializeCriticalSectionAndSpinCount, RaiseException, LoadLibraryA, HeapAlloc, HeapFree, SetProcessWorkingSetSize, GetCurrentProcessId, LocalFree, GetModuleHandleW, LoadLibraryExW, GetCurrentProcess, GetFirmwareEnvironmentVariableW, WTSGetActiveConsoleSessionId, CreateToolhelp32Snapshot, Process32FirstW, Sleep, ProcessIdToSessionId, Process32NextW, OpenProcess, CreateDirectoryW, GetModuleFileNameW, lstrlenW, CloseHandle, SetEvent, lstrlenA, ExpandEnvironmentStringsW, MultiByteToWideChar, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, OutputDebugStringW, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, WaitForSingleObject, UnhandledExceptionFilter, CreateSemaphoreW, GetCurrentThreadId, ReleaseSemaphore, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, FindFirstFileW, DeleteFileW, FindNextFileW, FindClose, RemoveDirectoryW, GetFileAttributesW, SetFileAttributesW, GetLastError, CreateMutexW, LoadLibraryW, GetProcAddress, FreeLibrary, ReleaseMutex
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
StringFromGUID2, CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoGetObject
shell32.dll
ShellExecuteExW, ShellExecuteW, CommandLineToArgvW, SHGetFolderPathW
shlwapi.dll
PathFileExistsW, PathIsDirectoryW, PathAppendW, PathStripPathW, PathRemoveExtensionW, PathRemoveFileSpecW, PathIsRelativeW, PathAddBackslashW, PathQuoteSpacesW
userenv.dll
CreateEnvironmentBlock
winmm.dll
timeGetTime
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW
Export table
OPENSSL_Applink

vsserv.exe

Bitdefender 2014 by Bitdefender SRL (Signed)

Remove vsserv.exe
Version:   17.21.0.908 102416
MD5:   c07943fa436c21a49bca9709d8299943
SHA1:   ad714e3df65f9dc1fd72103964104da1923ce4aa

Overview

vsserv.exe runs as a service under the name Bitdefender Virus Shield (VSSERV) with extensive SYSTEM privileges (full administrator access). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Bitdefender SRL which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:vsserv.exe
Publisher:Bitdefender
Product name:Bitdefender 2014
Description:Bitdefender Security Service
Typical file path:C:\Program Files\bitdefender\bitdefender\vsserv.exe
File version:17.21.0.908 102416
Size:1.44 MB (1,506,736 bytes)
Build date:10/23/2013 6:27 AM
Certificate
Issued to:Bitdefender SRL
Authority (CA):VeriSign
Effective date:Saturday, May 12, 2012
Expiration date:Thursday, May 1, 2014
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'VSSERV' (Bitdefender Virus Shield)
Network connections
  • [TCP] push1.amz.vdc.bitdefender.net (54.235.219.195:4001)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00006731%
    0.028634%
    Kernel CPU:0.00002090%
    0.013761%
    User CPU:0.00004641%
    0.014873%
    Kernel CPU time:657,656 ms/min
    100,923,805ms/min
    CPU cycles:25,145,075/sec
    17,470,203/sec
    Memory
    Private memory:216.17 MB
    21.59 MB
    Private (maximum):92.84 MB
    Private (minimum):2.12 MB
    Non-paged memory:216.17 MB
    21.59 MB
    Virtual memory:893.03 MB
    140.96 MB
    Virtual memory (peak):666.19 MB
    169.69 MB
    Working set:65.3 MB
    18.61 MB
    Working set (peak):202.62 MB
    37.95 MB
    Page faults:52,419,105/min
    2,039/min
    I/O
    I/O read transfer:802.06 KB/sec
    1.02 MB/min
    I/O read operations:503/sec
    343/min
    I/O write transfer:419.17 KB/sec
    274.99 KB/min
    I/O write operations:377/sec
    227/min
    I/O other transfer:2.53 MB/sec
    448.09 KB/min
    I/O other operations:6,332/sec
    1,671/min
    Resource allocations
    Threads:87
    12
    Handles:2320
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:64-bit
    Command line:"C:\Program Files\bitdefender\bitdefender\vsserv.exe" /service
    Owner:SYSTEM
    Windows Service
    Service name:VSSERV
    Display name:Bitdefender Virus Shield
    Type:Win32OwnProcess

    ResourcesThreads

    Averages
     
    framework.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.09789823%
    0.272967%
    Kernel CPU:0.03457497%
    0.107585%
    User CPU:0.06332326%
    0.165382%
    CPU cycles:2,652,058/sec
    5,741,424/sec
    Context switches:5/sec
    79/sec
    Memory:196 KB
    1.16 MB
    bdpredir.dll (BitDefender Firewall by BitDefender)
    Total CPU:0.06694560%
    Kernel CPU:0.02175513%
    User CPU:0.04519047%
    CPU cycles:1,732,881/sec
    Context switches:8/sec
    Memory:112 KB
    ondemandal.dll (Bitdefender Security by Bitdefender)
    Total CPU:0.03017326%
    Kernel CPU:0.00795296%
    User CPU:0.02222030%
    CPU cycles:753,168/sec
    Memory:2.8 MB
    gzfltum.dll (BitDefender by BitDefender)
    Total CPU:0.02034568%
    Kernel CPU:0.00227297%
    User CPU:0.01807271%
    CPU cycles:516,600/sec
    Memory:84 KB
    ntdll.dll
    Total CPU:0.01039131%
    Kernel CPU:0.00604347%
    User CPU:0.00434783%
    CPU cycles:199,294/sec
    Memory:1.66 MB
    safeboxal.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00670776%
    Kernel CPU:0.00293127%
    User CPU:0.00377649%
    CPU cycles:476,176/sec
    Context switches:3/sec
    Memory:260 KB
    serverpush.dll (Bitdefender 2014 by Bitdefender)
    Total CPU:0.00463229%
    Kernel CPU:0.00339781%
    User CPU:0.00123448%
    CPU cycles:116,531/sec
    Memory:164 KB
    apprep.dll (Bitdefender Security by Bitdefender)
    Total CPU:0.00249273%
    Kernel CPU:0.00056326%
    User CPU:0.00192947%
    CPU cycles:61,482/sec
    Memory:332 KB
    combase.dll
    Total CPU:0.00240543%
    Kernel CPU:0.00083448%
    User CPU:0.00157095%
    CPU cycles:53,654/sec
    Memory:1.84 MB
    npcomm.dll (BitDefender 16 by BitDefender LLC)
    Total CPU:0.00229494%
    Kernel CPU:0.00148153%
    User CPU:0.00081342%
    CPU cycles:128,311/sec
    Context switches:1/sec
    Memory:136 KB
    accessal.dll (Bitdefender Security by Bitdefender)
    Total CPU:0.00203932%
    Kernel CPU:0.00111054%
    User CPU:0.00092878%
    CPU cycles:54,143/sec
    Memory:344 KB
    sechost.dll
    Total CPU:0.00098868%
    Kernel CPU:0.00022170%
    User CPU:0.00076698%
    CPU cycles:22,952/sec
    Memory:348 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8 25.00%
    Windows 7 Ultimate 16.67%
    Windows 7 Professional 16.67%
    Windows 8.1 8.33%
    Windows 8.1 Pro with Media Center 8.33%
    Windows 8.1 Pro 8.33%
    Windows 7 Home Premium 8.33%
    Microsoft Windows XP 8.33%

    Distribution by countryDistribution by country

    United States installs about 58.33% of Bitdefender 2014.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Lenovo 30.77%
    Apple 30.77%
    Hewlett-Packard 23.08%
    Acer 7.69%
    Samsung 7.69%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE