DptfPolicyLpmServiceHelper.exe

Intel Dynamic Platform and Thermal Framework

Intel Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DptfPolicyLpmServiceHelper’.
Publisher:
Intel Corporation  (signed and verified)

Product:
Intel(R) Dynamic Platform and Thermal Framework

Description:
Intel(R) Dynamic Platform and Thermal Framework LPM Policy Service Helper

Version:
7.1.0.2105

MD5:
37639a5b745a48ea6e3e7f52cb61ed5e

SHA-1:
aec8947bd2d880a6e1d21dda75f4b6ac0b9f1964

SHA-256:
8c55e7bcc75d5513485e2e4df6863a930ee14f9f4ac7f8f86ac3b9271b6e3594

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:05:29 PM UTC  (today)

File size:
1.2 MB (1,232,256 bytes)

Product version:
7.1.0.2105

Copyright:
Copyright(C) 2003-2013 Intel Corporation

Original file name:
DptfPolicyLpmServiceHelper.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\dptfpolicylpmservicehelper.exe

Digital Signature
Authority:
Intel Corporation

Valid from:
4/3/2013 10:05:21 PM

Valid to:
3/18/2016 10:05:21 PM

Subject:
CN=Intel(R) Software, O=Intel Corporation, L=Santa Clara, S=CA, C=US

Issuer:
CN=Intel External Basic Issuing CA 3A, O=Intel Corporation, L=Santa Clara, S=CA, C=US

Serial number:
3300009D4320E74C7AF0250102000300009D43

File PE Metadata
Compilation timestamp:
9/29/2013 7:53:58 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:UdXiTjhzt71JdRo+tChLWp39lfPP54PXp:iiT9thRLwhLkvfX5Y

Entry address:
0x1E9C

Entry point:
48, 83, EC, 28, E8, 77, 1F, 00, 00, 48, 83, C4, 28, E9, 02, 00, 00, 00, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 30, E8, BC, 22, 00, 00, 0F, B7, F0, B9, 02, 00, 00, 00, E8, 03, 1F, 00, 00, B8, 4D, 5A, 00, 00, 48, 8D, 3D, 23, E1, FF, FF, 66, 39, 05, 1C, E1, FF, FF, 74, 04, 33, DB, EB, 31, 48, 63, 05, 4B, E1, FF, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 75, EA, B9, 0B, 02, 00, 00, 66, 39, 48, 18, 75, DF, 33, DB, 83, B8, 84, 00, 00, 00, 0E, 76, 09, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89...
 
[+]

Entropy:
0.8108

Code size:
51.5 KB (52,736 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DptfPolicyLpmServiceHelper

Command:
C:\Windows\System32\dptfpolicylpmservicehelper.exe


Scan DptfPolicyLpmServiceHelper.exe - Powered by Reason Core Security