False positive or legit? esif_assist_64.exe

Discussion in 'Windows 7' started by weva87, Oct 23, 2016.

  1. weva87

    weva87 MDL Novice

    Oct 18, 2016
    2
    0
    0
    hello, each time I run roguekiller in normal mode, it finds esif_assist_64.exe in C:/Windows/Temp/DPTF/ folder.

    Detection is labeled as Suspicious.Path, and type is Process.

    Each time I click on delete it does not get deleted, instead it gets "killed".

    File shows up every time I boot computer and shows time of creation time I booted the computer.

    Description of the file is: Intel (R) Dynamic Platform and Thermal Framework Utility Application.

    File does not show up in the folder when I boot computer in safe mode, and neithet does it get detected by roguekiller. It gets detected only when I run it in normal mode.


    I ran it through virustotal and it came in clean, however I checked the details and it shows all certificates as legit except the first one. Also, it specified it as a Portable execution file.

    Is it legit? Thanks
     
  2. weva87

    weva87 MDL Novice

    Oct 18, 2016
    2
    0
    0
    Virustotal and other antivirus/antimalware programs I used however never found it to be a problem, except for roguekiller.

    Any idea, if it is a virus it managed to get into my computer? I had it freshly reinstalled. Thanks.