IGFXPERS.EXE

Intel Common User Interface

Intel Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Persistence’.
Publisher:
Intel Corporation

Product:
Intel(R) Common User Interface

Description:
persistence Module

Version:
8.15.10.2021

MD5:
7b3c8051b7d3da4bd0b17e2fa4334d51

SHA-1:
755e0ded0da35aac1d6c14219972503842a36cf2

SHA-256:
4142df03194a1d8f420ea9c0ce9f833169228bcfbc911f73379cfbf9778c4552

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/6/2024 5:18:02 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.IntelCorporation.Startup
188838

File size:
243 KB (248,856 bytes)

Product version:
8.15.10.2021

Copyright:
Copyright 1999-2006, Intel Corporation

Original file name:
IGFXPERS.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\igfxpers.exe

File PE Metadata
Compilation timestamp:
12/15/2009 4:48:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:UE1f7YaUM6KRKIrNctcCcLAeL/28mzb+uP+4EA3i3h4FXq2wf:lSaTDQlcLhiXXPVi3oq2K

Entry address:
0x122DC

Entry point:
BB, 4F, 54, D1, 9D, 56, 68, 3E, 00, 71, 00, 0C, 5D, 84, F3, 87, D6, 0F, AF, C5, 45, B7, D0, 86, C8, 0F, AF, F9, E8, 78, 00, 00, 00, 86, D0, 81, EF, 6C, 44, 72, 62, 86, E1, 89, F8, F2, 69, D7, 31, AB, 1D, 67, 8A, CD, 49, 8B, C8, 80, E2, 9A, 42, F3, 84, FB, 87, EA, BE, 3D, 71, 00, 00, C7, C2, A7, 44, FD, E2, 81, EE, 72, 1D, 00, 00, 81, CD, 52, A7, 9D, EE, 80, FD, CE, 0B, CB, 86, ED, 8B, FE, 3A, EB, 0F, B7, E8, 81, EF, 03, 01, 00, 00, 46, F2, 57, 69, CE, 03, A6, F8, 79, 84, EB, F7, C3, EF, 14, C9, 71, 58, 4D...
 
[+]

Entropy:
7.2414

Code size:
125 KB (128,000 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Persistence

Command:
C:\Windows\System32\igfxpers.exe


Scan IGFXPERS.EXE - Powered by Reason Core Security