Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 2.64%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.22%
6.3.9600.16384 (winblue_rtm.130821-1623) 3.96%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.33%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.11%
6.2.9200.16384 (win8_rtm.120725-1247) 2.53%
6.2.9200.16384 (win8_rtm.120725-1247) 8.36%
6.2.9200.16384 (win8_rtm.120725-1247) 8.25%
6.2.9200.16384 (win8_rtm.120725-1247) 1.21%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.11%
6.1.7600.16385 (win7_rtm.090713-1255) 18.04%
6.1.7600.16385 (win7_rtm.090713-1255) 3.74%
6.1.7600.16385 (win7_rtm.090713-1255) 16.61%
6.1.7600.16385 (win7_rtm.090713-1255) 2.86%
6.1.7600.16385 (win7_rtm.090713-1255) 14.41%
6.1.7600.16385 (win7_rtm.090713-1255) 5.17%
6.1.7600.16385 (win7_rtm.090713-1255) 0.22%
6.0.6001.18000 (longhorn_rtm.080118-1840) 1.32%
6.0.6001.18000 (longhorn_rtm.080118-1840) 9.35%
6.0.6000.16386 (vista_rtm.061101-2205) 0.55%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetTokenInformation, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, SetTokenInformation, RegisterServiceCtrlHandlerExW, RegCloseKey, RegQueryValueExW, ConvertSecurityDescriptorToStringSecurityDescriptorW, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW, CheckTokenMembership, CreateProcessAsUserW, SetKernelObjectSecurity, ImpersonateLoggedOnUser, RevertToSelf, RegGetValueW, RegOpenKeyExW, SetServiceStatus
api-ms-win-core-appcompat-l1-1-1.dll
BaseReadAppCompatDataForProcess, BaseFreeAppCompatDataForProcess
api-ms-win-core-localregistry-l1-1-0.dll
RegGetValueW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey
api-ms-win-core-processthreads-l1-1-0.dll
TerminateProcess, GetExitCodeProcess, GetCurrentProcessId, DeleteProcThreadAttributeList, GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, CreateProcessAsUserW, ResumeThread
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, CreateProcessAsUserW, DeleteProcThreadAttributeList, ResumeThread, GetCurrentProcessId, TerminateProcess, GetExitCodeProcess, UpdateProcThreadAttribute, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
GetExitCodeProcess, GetCurrentProcessId, ResumeThread, DeleteProcThreadAttributeList, UpdateProcThreadAttribute, CreateProcessAsUserW, TerminateProcess, GetCurrentThreadId, GetCurrentProcess, InitializeProcThreadAttributeList
api-ms-win-core-registry-l1-1-0.dll
RegQueryValueExW, RegGetValueW, RegOpenKeyExW, RegCloseKey
api-ms-win-security-base-l1-1-0.dll
ImpersonateLoggedOnUser, GetTokenInformation, CheckTokenMembership, SetTokenInformation, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, RevertToSelf
api-ms-win-security-base-l1-2-0.dll
GetSidSubAuthority, GetTokenInformation, SetTokenInformation, GetSidLengthRequired, InitializeSid, CheckTokenMembership, RevertToSelf, ImpersonateLoggedOnUser
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
kernel32.dll
GetLastError, InterlockedIncrement, LocalFree, WaitForSingleObject, InterlockedDecrement, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetSystemTimeAsFileTime, QueryPerformanceCounter, Sleep, InterlockedExchange, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetProcAddress, DelayLoadFailureHook, lstrlenW, GetTempPathW, GetSystemDirectoryW, GetEnvironmentVariableW, CreateFileMappingW, MapViewOfFile, CreateActCtxW, QueryActCtxSettingsW, ReleaseActCtx, UnmapViewOfFile, GetLongPathNameW, CheckElevationEnabled, CreateFileW, CheckElevation, GetFullPathNameW, GetFileAttributesW, ReadProcessMemory, ReleaseMutex, CreateMutexW, LocalAlloc, CreateEventW, CloseHandle, GetTickCount, UnregisterWait, SetEvent, GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, DeleteProcThreadAttributeList, GetTempFileNameW, ReadFile, WriteFile, DeleteFileW, GetCurrentProcessId, ResumeThread, GetExitCodeProcess, TerminateProcess, ResolveDelayLoadedAPI, DuplicateHandle, SetLastError, VirtualProtect, VirtualAlloc, VirtualFree, OutputDebugStringW, VirtualQuery
msvcrt.dll
DllMain
ntdll.dll
EtwTraceMessage, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwEventWrite, NtQuerySecurityObject, NtSetSecurityObject, RtlCreateServiceSid, RtlDosPathNameToRelativeNtPathName_U_WithStatus, RtlReleaseRelativeName, RtlFreeUnicodeString, RtlInitUnicodeStringEx, RtlPrefixUnicodeString, RtlQueryEnvironmentVariable, RtlInitUnicodeString, LdrOpenImageFileOptionsKey, LdrQueryImageFileKeyOption, RtlExpandEnvironmentStrings, RtlDestroyEnvironment, RtlCreateEnvironmentEx, RtlSetEnvironmentVar, NtOpenProcess, NtOpenThreadToken, NtQueryInformationToken, NtDuplicateObject, RtlRegisterWait, NtQuerySystemInformation, NtQueryInformationProcess, NtReadVirtualMemory, RtlNtStatusToDosErrorNoTeb, RtlImageNtHeaderEx, RtlDeregisterWaitEx, RtlDeregisterWait, RtlAcquireSRWLockExclusive, RtlReleaseSRWLockExclusive, RtlAcquireSRWLockShared, RtlReleaseSRWLockShared, NtOpenProcessToken, NtDuplicateToken, NtSetInformationToken, RtlRemovePrivileges, RtlNtStatusToDosError, NtClose, RtlInitializeSRWLock, EtwEventRegister, EtwEventUnregister, RtlSetDaclSecurityDescriptor, RtlAddAccessAllowedAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlLengthSid, NtOpenKey, RtlAppendUnicodeToString, RtlAppendUnicodeStringToString, NtQueryValueKey, DbgPrintEx, RtlFormatCurrentUserKeyPath, RtlExpandEnvironmentStrings_U, RtlAnsiStringToUnicodeString, NtMapViewOfSection, RtlFreeHeap, RtlInitAnsiString, RtlGetVersion, NtQueryInformationFile, NtUnmapViewOfSection, NtCreateFile, RtlAllocateHeap, RtlGetNativeSystemInformation, RtlUnicodeStringToInteger, NtCreateSection
rpcrt4.dll
RpcRevertToSelf, RpcImpersonateClient, I_RpcBindingInqLocalClientPID, RpcServerUseProtseqW, RpcAsyncCompleteCall, RpcServerInqBindings, RpcServerRegisterIfEx, RpcEpRegisterW, RpcServerUnregisterIf, RpcEpUnregister, RpcBindingVectorFree, NdrAsyncServerCall, NdrServerCall2
secur32.dll
GetUserNameExW
user32.dll
MonitorFromPoint
userenv.dll
UnloadUserProfile, DestroyEnvironmentBlock, CreateEnvironmentBlock, LoadUserProfileW
Export table
ServiceMain
SvchostPushServiceGlobals

appinfo.dll

Application Information Service by Microsoft

Remove appinfo.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   9651b55594f10f65d6d4498b89e5a4c5
SHA1:   c693e335b24252cf2a13651e2acdc5d257da8bfe
SHA256:   0726f44a81298116e61dcf720383c2e295ea96c79364a19b1ed1c274d20b3d77
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is appinfo.dll?

The Application Information service (AIS) is responsible for creating a new process to run applications with elevated privileges, typically when running an administrative application while having UAC turned on. Application Information service the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.

Overview

appinfo.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7.

DetailsDetails

File name:appinfo.dll
Publisher:Microsoft Corporation
Product name:Application Information Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\appinfo.dll
Original name:appinfo.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:69 KB (70,656 bytes)
Build date:2/27/2013 7:17 AM
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 31.50%
Windows 8.1 17.50%
Windows 7 Ultimate 9.00%
Windows 8.1 Pro 8.50%
Windows 8 8.00%
Windows 8 Pro 6.00%
Windows 7 Professional 3.50%
Windows Vista Home Premium 3.00%
Windows 8.1 Single Language 2.50%
Windows 7 Home Basic 2.00%
Windows 8 Single Language 2.00%
Windows 8.1 Pro with Media Center 1.00%
Windows 7 Starter 1.00%
Windows 8.1 Pro Preview 1.00%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 8.1 Enterprise 0.50%
Windows 8 Enterprise Evaluation 0.50%
Windows 8 Pro with Media Center 0.50%
Windows Vista Business 0.50%
Windows 8 Pro N 0.50%
Windows 8 Enterprise 0.50%
21 other Windows OS version

Distribution by countryDistribution by country

United States installs about 46.67% of Application Information Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 19.05%
Hewlett-Packard 17.22%
ASUS 16.12%
Acer 10.62%
Toshiba 10.26%
Lenovo 8.79%
Sony 7.33%
Samsung 2.56%
Intel 2.20%
GIGABYTE 1.83%
Medion 1.47%
Alienware 1.10%
MSI 0.73%
American Megatrends 0.73%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE