esif_uf.exe file report

MD5 2856859703296ba2c27ef306e24aaf21
Latest seen 2024-12-27 23:01:41 (a year ago)
First seen 2024-12-27 23:01:41 (a year ago)
Size 2 MB
Publisher Intel Corporation

Why it matters

Evidence available for this file

Detection

Latest status is clean for this hash.

Timeline

First seen 2024-12-27 23:01:41 (a year ago); latest analysis 2024-12-27 23:01:41 (a year ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel(R) Dynamic Platform and Thermal Framework.

Digital signature

Signed by Intel Corporation - pGFX. ThreatInfo marks this publisher as trusted for this record.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Confirm the hash and publisher match the expected software.
  2. Review the observed locations and signature information below.
  3. Rescan if the file was downloaded from an unknown source or appears in an unusual path.

esif_uf.exe is a Windows file recorded in the ThreatInfo database. It is associated with Intel(R) Dynamic Platform and Thermal Framework. The reported company name is Intel Corporation. The current detection status is Clean, based on the latest analysis from 2024-12-27 23:01:41 (a year ago).

This record is currently marked as clean, but file reputation can depend on the exact path, hash, and source. Compare the MD5 and publisher data below with the file on your system.

Product Name: Intel(R) Dynamic Platform and Thermal Framework
Company Name: Intel Corporation
MD5: 2856859703296ba2c27ef306e24aaf21
Size: 2 MB
First Published: 2024-12-27 23:01:41 (a year ago)
Latest Published: 2024-12-27 23:01:41 (a year ago)
Status: Clean (on last analysis)
Analysis Date: 2024-12-27 23:01:41 (a year ago)
Signed By: Intel Corporation - pGFX
Status: Trusted Publisher

ThreatInfo marks this publisher as trusted for this record, but the file hash and source should still match the expected software distribution.

%localappdata%\slimware utilities inc\driverupdate\backups\20180305t090738920\acpi

ThreatInfo has observed esif_uf.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is United States with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for esif_uf.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

esif_uf.exe is identified as pe for 64 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000011ae

PE Sections:

Name Size of data MD5
.text 1155584 b2068805825ff852c33e00230e21d72e
.rdata 304128 ae698f00616162c193b8bd2f8b8554d6
.data 27136 2944c13fc06eb6ffc8ed98b604b693ba
.pdata 54272 a6004482abbd426c8d0a81c0bc439601
.idata 12288 ca539efbac1cebb0ac3c237ddf4a463d
.gfids 1536 e1d447bde0d76ccd741e6d13477f5404
.00cfg 512 f0b113a8688e6def58cd0aeb0478a147
.rsrc 633856 1ac0b7c7c1e7380a301a1205c5ba6e57
.reloc 10752 7e4d076c2542b3a7f266cf08360465c8

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: