"PEFService.exe" Process on Windows 7

Q

What is the "PEFService.exe" process on windows 7? Is the "PEFService.exe" process a virus? Can I terminate the "PEFService.exe" process?

✍: FYIcenter.com

A

"PEFService.exe" process represents "Intel Security PEF Service" program. "PEFService.exe" process is created by the "Intel Security PEF Service" service.

"PEFService.exe" process is normally running under the parent process "services" as shown in the process tree below:

Boot
   wininit
      services
         PEFService

On the Processes tab of "Task Manager", "PEFService.exe" process may be listed as:

Image Name                 Memory   Description
--------------------   ----------   -----------
PEFService.exe           10,904 K   Intel Security PEF Service

Additional information about "PEFService.exe" process:

Command line:
   "C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe"

Programe file information:
   Name: PEFService.exe
   Location: C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
   Description: Intel Security PEF Service
   Version: 1,2,130,0
   Size: 1045336 bytes
   Last modified: 5/25/2016 6:22:56 AM
   Company Name: Intel Security, Inc.
   
Some data files used:
C:\Windows\System32
C:\Windows\System32\en-US\setupapi.dll.mui
C:\ProgramData\Intel Security\PEF\pefdata.dat
C:\Windows\System32\en-US\crypt32.dll.mui
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My

Some registry keys used:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER
HKLM\SYSTEM\ControlSet001\services\crypt32
HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT
HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My
HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA
HKLM\SOFTWARE\Microsoft\SystemCertificates\CA
HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA

Some DLL libraries used:
C:\windows\SYSTEM32\ntdll.dll
C:\windows\system32\kernel32.dll
C:\windows\system32\KERNELBASE.dll
C:\windows\system32\WINTRUST.dll
C:\windows\system32\msvcrt.dll
C:\windows\system32\CRYPT32.dll
C:\windows\system32\MSASN1.dll
C:\windows\system32\RPCRT4.dll
C:\windows\system32\POWRPROF.dll
C:\windows\system32\SETUPAPI.dll

"PEFService.exe" process is not a virus. You should not terminate "PEFService.exe" process.

 

System Service Processes on Windows 7

⇒⇒Windows 7 Processes Tutorials

2016-12-21, 453👍, 0💬