Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

1.4.5.83 90.00%
1.4.5.73 10.00%

Relationships

Parent processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteValueW, RegEnumValueW, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, OpenThreadToken, OpenProcessToken, RegEnumKeyExW, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, IsValidSid, GetLengthSid, CopySid, RegQueryInfoKeyW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteKeyW, CreateServiceW, ChangeServiceConfig2W, ControlService, DeleteService, StartServiceW, OpenSCManagerW, OpenServiceW, CloseServiceHandle
kernel32.dll
HeapSize, HeapReAlloc, HeapAlloc, HeapDestroy, lstrlenA, GetVersionExW, GetProcessHeap, HeapFree, WideCharToMultiByte, GetCommandLineW, SetEvent, InterlockedDecrement, InterlockedIncrement, MultiByteToWideChar, CreateEventW, CreateThread, GetCurrentThreadId, GetModuleHandleW, Sleep, GetCurrentThread, GetCurrentProcess, GetModuleFileNameW, WaitForSingleObject, CloseHandle, lstrcmpiW, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, GetFileAttributesW, LoadLibraryExW, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, GetLastError, CreateFileA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, LoadLibraryA, GetStringTypeW, GetStringTypeA, GetConsoleMode, GetConsoleCP, LCMapStringW, LCMapStringA, GetSystemTimeAsFileTime, QueryPerformanceCounter, GetStartupInfoA, GetFileType, SetHandleCount, GetCommandLineA, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeLibrary, GetProcAddress, FreeEnvironmentStringsA, GetModuleFileNameA, GetStdHandle, HeapCreate, EnterCriticalSection, LeaveCriticalSection, GetVersionExA, InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale, WaitForMultipleObjects, WaitForMultipleObjectsEx, GetTickCount, GetLocalTime, GetCurrentProcessId, OutputDebugStringW, WriteFile, CreateFileW, SetFilePointer, FlushFileBuffers, lstrcpyW, lstrcatW, CreateMutexW, OpenMutexW, ReleaseMutex, GetSystemDirectoryW, GetSystemInfo, VirtualAlloc, VirtualFree, InterlockedExchangeAdd, TerminateProcess, SetUnhandledExceptionFilter, CreateSemaphoreW, ReleaseSemaphore, RtlUnwind, UnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCPInfo, GetOEMCP, IsValidCodePage, ExitProcess
ole32.dll
CoInitialize, CoCreateInstance, CoInitializeSecurity, CoUninitialize, CoTaskMemFree, CoRegisterClassObject, CoRevokeClassObject, CoTaskMemRealloc, CoTaskMemAlloc, StringFromGUID2
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathAddBackslashW
user32.dll
DispatchMessageA, MsgWaitForMultipleObjectsEx, GetMessageA, IsWindowUnicode, PeekMessageW, TranslateMessage, UnregisterClassA, GetMessageW, CharNextW, LoadStringW, CharUpperW, PostThreadMessageW, MessageBoxW, DispatchMessageW

pifsvc.exe

LiveUpdate Notice by Symantec Corporation (Signed)

Remove pifsvc.exe
Version:   1.4.5.83
MD5:   2d1389e05a807d956829f44bd4b60389
SHA1:   d9ed368fb21d68b26b11e2b8bef1dd281c1835d1
SHA256:   8496fcccf2c96550f67f53f91592e3ba7b74654abd1d84794f6b63a79bc357b2

Overview

pifsvc.exe runs as a service under the name LiveUpdate Notice Service with extensive SYSTEM privileges (full administrator access) as a shared service. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:pifsvc.exe
Publisher:Symantec Corporation
Product name:LiveUpdate Notice
Description:LiveUpdate Notice Service
Typical file path:C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe
Original name:PIFSvc.dll
File version:1.4.5.83
Product version:1.4
Size:569.38 KB (583,048 bytes)
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Tuesday, October 30, 2007
Expiration date:Wednesday, November 24, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'LiveUpdate Notice Service'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Symantec PIF AlertEng' → "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Al

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00008247%
0.028634%
Kernel CPU:0.00006956%
0.013761%
User CPU:0.00001291%
0.014873%
Kernel CPU time:536 ms/min
100,923,805ms/min
CPU cycles:9,137/sec
17,470,203/sec
Memory
Private memory:3.33 MB
21.59 MB
Private (maximum):3.34 MB
Private (minimum):88.67 KB
Non-paged memory:3.33 MB
21.59 MB
Virtual memory:73.87 MB
140.96 MB
Virtual memory (peak):76.66 MB
169.69 MB
Working set:855.33 KB
18.61 MB
Working set (peak):4.83 MB
37.95 MB
Page faults:38,854/min
2,039/min
I/O
I/O read transfer:2 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:4 Bytes/sec
448.09 KB/min
I/O other operations:2/sec
1,671/min
Resource allocations
Threads:6
12
Handles:173
600
GUI GDI count:9
103
GUI USER count:3
49

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command lines:
  • "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /m "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifeng.dll"
  • "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\alerteng.dll"
Owner:SYSTEM
Windows Service
Service name:LiveUpdate Notice Service
Description:“Manages Norton product notices.”
Type:Win32ShareProcess
Parent processes:

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.00013192%
0.272967%
Kernel CPU:0.00013192%
0.107585%
User CPU:0.00000000%
0.165382%
CPU cycles:496/sec
5,741,424/sec
Memory:1.16 MB
1.16 MB
pifeng.dll (LiveUpdate Notice by Symantec)
Total CPU:0.00010124%
Kernel CPU:0.00009079%
User CPU:0.00001045%
CPU cycles:1,856/sec
Memory:528 KB
alerteng.dll (LiveUpdate Notice by Symantec)
Total CPU:0.00006366%
Kernel CPU:0.00005181%
User CPU:0.00001184%
CPU cycles:699/sec
Memory:392 KB
PollMgr.dll (LiveUpdate Notice by Symantec)
Total CPU:0.00005989%
Kernel CPU:0.00005722%
User CPU:0.00000267%
CPU cycles:3,514/sec
Memory:600 KB
ADVAPI32.dll
Total CPU:0.00003160%
Kernel CPU:0.00002378%
User CPU:0.00000782%
CPU cycles:601/sec
Memory:792 KB
PIFSvc.exe (main module)
Total CPU:0.00001079%
Kernel CPU:0.00000313%
User CPU:0.00000766%
CPU cycles:126/sec
Memory:572 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows Vista Home Premium 50.00%
Windows Vista Ultimate 40.00%
Microsoft Windows XP 10.00%

Distribution by countryDistribution by country

Canada installs about 50.00% of LiveUpdate Notice.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE