DptfPolicyLpmServiceHelper.exe

Intel Dynamic Platform and Thermal Framework

Intel Corporation

The executable DptfPolicyLpmServiceHelper.exe, “Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Helper” has been detected as malware by 9 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DptfPolicyLpmServiceHelper’.
Publisher:
Intel Corporation  (signed and verified)

Product:
Intel(R) Dynamic Platform and Thermal Framework

Description:
Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Helper

Version:
7.1.0.2105

MD5:
4112b9b4f6e9955df9ee4a93099069d2

SHA-1:
279cddab96473c1caf476362fb8ec057b66a7c6b

SHA-256:
a5caf3662287b7e1851b1e291a4af1cd6bae18e2c85d039b93ae2e5cae29badc

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
4/20/2024 12:58:09 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Patched-HO [Trj]
160327-1

AVG
Win32/Slugin.A
2015.0.4355

Dr.Web
Trojan.MulDrop3.48024
9.0.1.05190

Emsisoft Anti-Malware
Win32.SlugIn.A.Dam
11.5.0.6191

F-Prot
W32/Slugin.A.gen!Eldorado (generic, damaged, not disinfectable)
4.6.5.141

F-Secure
Win32.SlugIn.A.Dam
5.15.21

Microsoft Security Essentials
Threat.Undefined
1.217.1621.0

Norman
Win32.SlugIn.A.Dam
02.04.2016 17:35:19

VIPRE Antivirus
Threat.4314869
48132

File size:
203.8 KB (208,739 bytes)

Product version:
7.1.0.2105

Copyright:
Copyright(C) 2003-2013 Intel Corporation

Original file name:
DptfPolicyLpmServiceHelper.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\dptfpolicylpmservicehelper.exe

Digital Signature
Authority:
Intel Corporation

Valid from:
4/3/2013 10:05:21 PM

Valid to:
3/18/2016 10:05:21 PM

Subject:
CN=Intel(R) Software, O=Intel Corporation, L=Santa Clara, S=CA, C=US

Issuer:
CN=Intel External Basic Issuing CA 3A, O=Intel Corporation, L=Santa Clara, S=CA, C=US

Serial number:
3300009D4320E74C7AF0250102000300009D43

File PE Metadata
Compilation timestamp:
9/29/2013 8:53:58 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:UdXiTjhzt71JdRo+tChLWp39lfPP54PXp4hYZ4s1sxtbjIUWnoRzk:iiT9thRLwhLkvfX5YRZ4sytbLw

Entry address:
0x1E9C

Entry point:
48, 83, EC, 28, E8, 77, 1F, 00, 00, 48, 83, C4, 28, E9, 02, 00, 00, 00, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 30, E8, BC, 22, 00, 00, 0F, B7, F0, B9, 02, 00, 00, 00, E8, 03, 1F, 00, 00, B8, 4D, 5A, 00, 00, 48, 8D, 3D, 23, E1, FF, FF, 66, 39, 05, 1C, E1, FF, FF, 74, 04, 33, DB, EB, 31, 48, 63, 05, 4B, E1, FF, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 75, EA, B9, 0B, 02, 00, 00, 66, 39, 48, 18, 75, DF, 33, DB, 83, B8, 84, 00, 00, 00, 0E, 76, 09, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89...
 
[+]

Entropy:
6.2538

Code size:
51.5 KB (52,736 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DptfPolicyLpmServiceHelper

Command:
C:\Windows\System32\dptfpolicylpmservicehelper.exe


Remove DptfPolicyLpmServiceHelper.exe - Powered by Reason Core Security