tfservice.exe
ThreatFire by PC Tools (Signed)
Version: | 4.11.2.22 |
MD5: | 895a08f39617485f13796263990c8ba5 |
SHA1: | e76261202edc1226d647908142663c086fcc1c62 |
SHA256: | 3b82c175b33c47c8be1bfb892a40ae33bad6caf1e72bd803c8a140ee4b261752 |
What is tfservice.exe?
PC Tools Security which offers protection from online threats, is regularly updated, and even includes some useful extras like Web site ratings, phishing alerts, and spyware, adware and malware protection.
About tfservice.exe (from PC Tools)
“PC Tools Security is a full antivirus and antispyware package designed to protect from known viruses, worms, Trojans and other threats while defending against spyware, adware, bots, keyloggers and oth”
Details
File name: | tfservice.exe |
Publisher: | PC Tools |
Product name: | ThreatFire |
Description: | PC Tools ThreatFire Service |
Typical file path: | C:\Program Files\pc tools\pc tools security\tfengine\tfservice.exe |
Original name: | OCService.dll |
File version: | 4.11.2.22 |
Product version: | 4.7.0.53 |
Size: | 69.27 KB (70,928 bytes) |
Build date: | 2/22/2011 2:53 AM |
Certificate |
Issued to: | PC Tools |
Authority (CA): | VeriSign |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
Code language: | Microsoft Visual C++ 8.0 |
.NET CLR: | No |
More details
Programs
The following program will install this file
“Traditional antivirus solutions cannot protect you until after they have discovered a new threat and produced a signature to counter it. ThreatFire does not rely on signatures, but instead provides behavior-based protection. It is designed to be used alongside your existing antivirus software and it fills the gap in protection between your antivirus signature updates. ThreatFire protects you against major security threats including viru...”
Behaviors
Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00240596% | |
Kernel CPU: | 0.00055794% | |
User CPU: | 0.00184802% | |
Kernel CPU time: | 32,270 ms/min | |
Context switches: | 107/sec | |
Memory |
Private memory: | 14.69 MB | |
Private (maximum): | 5.85 MB | |
Private (minimum): | 3.74 MB | |
Non-paged memory: | 14.69 MB | |
Virtual memory: | 143.61 MB | |
Virtual memory (peak): | 168.22 MB | |
Working set: | 5.13 MB | |
Working set (peak): | 28.51 MB | |
Resource allocations |
Threads: | 36 | |
Handles: | 507 | |
GUI GDI count: | 14 | |
GUI USER count: | 20 | |
Process properties
Integrety level: | System |
Platform: | 64-bit |
Command line: | "C:\Program Files\threatfire\tfservice.exe" service |
Owner: | SYSTEM |
Windows Service |
Service name: | ThreatFire |
Description: | “The ThreatFire engine responsible for monitoring your system for viruses, spyware, and other malware. Turning this service off makes your machine vulnerable to such attacks.” |
Type: | Win32OwnProcess, InteractiveProcess |
Parent process: | services.exe (Services and Controller app by Microsoft) |
Threads
Averages
MSVCR80.dll |
Total CPU: | 0.41660924% | |
Kernel CPU: | 0.39001528% | |
User CPU: | 0.02659397% | |
Context switches: | 3/sec | |
Memory: | 620 KB | |
advapi32.dll (Advanced Windows 32 Base API by Microsoft) |
Total CPU: | 0.32022494% | |
Kernel CPU: | 0.23040575% | |
User CPU: | 0.08981919% | |
Context switches: | 8/sec | |
Memory: | 620 KB | |
tfmon.dll (ThreatFire by PC Tools) |
Total CPU: | 0.02711430% | |
Kernel CPU: | 0.01410927% | |
User CPU: | 0.01300503% | |
Context switches: | 2/sec | |
Memory: | 56 KB | |
TFService.exe (main module) |
Total CPU: | 0.00869491% | |
Kernel CPU: | 0.00644466% | |
User CPU: | 0.00225025% | |
CPU cycles: | 330,703/sec | |
Context switches: | 4/sec | |
Memory: | 64 KB | |
tfe.dll (ThreatFire by PC Tools) |
Total CPU: | 0.00203149% | |
Kernel CPU: | 0.00203149% | |
User CPU: | 0.00000000% | |
Memory: | 836 KB | |
wow64.dll |
Total CPU: | 0.00200314% | |
Kernel CPU: | 0.00171000% | |
User CPU: | 0.00029314% | |
CPU cycles: | 271,363/sec | |
Context switches: | 1/sec | |
Memory: | 252 KB | |
ntdll.dll |
Total CPU: | 0.00004894% | |
Kernel CPU: | 0.00000000% | |
User CPU: | 0.00004894% | |
CPU cycles: | 34/sec | |
Memory: | 1.66 MB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Microsoft Windows XP |
40.00% |
|
Windows 7 Home Premium |
30.00% |
|
Windows Vista Home Premium |
10.00% |
|
Windows 7 Ultimate N |
10.00% |
|
Windows 7 Professional |
10.00% |
|
Distribution by country
United States installs about 40.00% of ThreatFire.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Dell |
50.00% |
|
Intel |
25.00% |
|
Hewlett-Packard |
12.50% |
|
American Megatrends |
12.50% |
|