IGFXPPH.DLL

Intel Common User Interface

Intel Corporation

It is registered as a context menu handler (displays a menu when right-clicked in Explorer) named “igfxcui”.
Publisher:
Intel Corporation

Product:
Intel(R) Common User Interface

Description:
igfxpph Module

Version:
8.15.10.2712

MD5:
5fe53ad7b35bc92047c7e3f86f8379f9

SHA-1:
810a9429675840c3f12b683f2e733e62bc11d07e

SHA-256:
b0ca42caa2ca97b6af55e12bdd6b1bfe809d7712392f73a9aff0a00d90b57208

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/6/2024 4:19:55 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.Ramnit-1847
0.98/23207

File size:
526.4 KB (539,047 bytes)

Product version:
8.15.10.2712

Copyright:
Copyright 1999-2006, Intel Corporation

Original file name:
IGFXPPH.DLL

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\igfxpph.dll

Registration
CLSID:
{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}

ProgID:
igfxpph.GraphicsShellExt.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
3/26/2012 5:36:26 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x51000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, A8, A6, 01, 20, 2B, 85, 0F, AE, 01, 20, 89, 85, 0B, AE, 01, 20, B0, 00, 86, 85, 40, B0, 01, 20, 3C, 01, 0F, 85, BC, 01, 00, 00, 83, BD, 3B, AF, 01, 20, 00, 74, 33, 83, BD, 3F, AF, 01, 20, 00, 74, 2A, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3B, AF, 01, 20, 8B, 00, 89, 85, 78, AF, 01, 20, 8B, 85, 0B, AE, 01, 20, 2B, 85, 3F, AF, 01, 20, 8B, 00, 89, 85, 7C, AF, 01, 20, EB, 61, 83, BD, 43, AF, 01, 20, 00, 74, 58, 8B, 85, 0B, AE, 01, 20, 2B, 85, 43, AF, 01, 20, FF, 30, 8D, 85...
 
[+]

Entropy:
6.4480

Packer / compiler:
ASPack v1.08.04

Code size:
179 KB (183,296 bytes)

Context Menu Handler
Display name:
igfxcui

CLSID:
{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}

CLSID name:
GraphicsShellExt Class


Scan IGFXPPH.DLL - Powered by Reason Core Security