pifsvc.exe
LiveUpdate Notice by Symantec Corporation (Signed)
Version: | 1.4.5.73 |
MD5: | deb2a99c1ad9b9190c78e895ae60a745 |
SHA1: | 6af9ded3b74613a798b05ed010c222ebc233788b |
SHA256: | d003bea585eac0110bfc69e127d8c1c0ba1e76e51ec7c7b844ead7b6daccbaf6 |
Overview
pifsvc.exe runs as a service under the name LiveUpdate Notice Service with extensive SYSTEM privileges (full administrator access) as a shared service. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).
Details
File name: | pifsvc.exe |
Publisher: | Symantec Corporation |
Product name: | LiveUpdate Notice |
Description: | LiveUpdate Notice Service |
Typical file path: | C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe |
Original name: | PIFSvc.dll |
File version: | 1.4.5.73 |
Product version: | 1.4 |
Size: | 569.38 KB (583,048 bytes) |
Certificate |
Issued to: | Symantec Corporation |
Authority (CA): | VeriSign |
Effective date: | Tuesday, October 30, 2007 |
Expiration date: | Wednesday, November 24, 2010 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
.NET CLR: | No |
More details
Behaviors
Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
- 'LiveUpdate Notice Service'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Symantec PIF AlertEng' → "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Al
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00006248% | |
Kernel CPU: | 0.00004741% | |
User CPU: | 0.00001507% | |
Kernel CPU time: | 867 ms/min | |
Memory |
Private memory: | 1.89 MB | |
Private (maximum): | 1.38 MB | |
Private (minimum): | 156 KB | |
Non-paged memory: | 1.89 MB | |
Virtual memory: | 40.25 MB | |
Virtual memory (peak): | 43.72 MB | |
Working set: | 206 KB | |
Working set (peak): | 3.68 MB | |
Page faults: | 70,098/min | |
I/O |
I/O read transfer: | 329 Bytes/sec | |
I/O read operations: | 1/sec | |
I/O write transfer: | 0 Bytes/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 5 Bytes/sec | |
I/O other operations: | 1/sec | |
Resource allocations |
Threads: | 4 | |
Handles: | 129 | |
GUI GDI count: | 5 | |
GUI USER count: | 4 | |
Process properties
Integrety level: | Undefined |
Platform: | 32-bit |
Command lines: |
- "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /m pifeng.dll
- "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "C:\Program Files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\alerteng.dll"
|
Owner: | SYSTEM |
Windows Service |
Service name: | LiveUpdate Notice Service |
Description: | “Manages Norton product notices.” |
Type: | Win32ShareProcess |
Parent processes: |
|
Threads
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Windows Vista Home Premium |
50.00% |
|
Windows Vista Ultimate |
40.00% |
|
Microsoft Windows XP |
10.00% |
|
Distribution by country
Canada installs about 50.00% of LiveUpdate Notice.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
100.00% |
|