Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 2.64%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.22%
6.3.9600.16384 (winblue_rtm.130821-1623) 3.96%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.33%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.11%
6.2.9200.16384 (win8_rtm.120725-1247) 2.53%
6.2.9200.16384 (win8_rtm.120725-1247) 8.36%
6.2.9200.16384 (win8_rtm.120725-1247) 8.25%
6.2.9200.16384 (win8_rtm.120725-1247) 1.21%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.11%
6.1.7600.16385 (win7_rtm.090713-1255) 18.04%
6.1.7600.16385 (win7_rtm.090713-1255) 3.74%
6.1.7600.16385 (win7_rtm.090713-1255) 16.61%
6.1.7600.16385 (win7_rtm.090713-1255) 2.86%
6.1.7600.16385 (win7_rtm.090713-1255) 14.41%
6.1.7600.16385 (win7_rtm.090713-1255) 5.17%
6.1.7600.16385 (win7_rtm.090713-1255) 0.22%
6.0.6001.18000 (longhorn_rtm.080118-1840) 1.32%
6.0.6001.18000 (longhorn_rtm.080118-1840) 9.35%
6.0.6000.16386 (vista_rtm.061101-2205) 0.55%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetTokenInformation, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, SetTokenInformation, RegisterServiceCtrlHandlerExW, RegCloseKey, RegQueryValueExW, ConvertSecurityDescriptorToStringSecurityDescriptorW, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW, CheckTokenMembership, CreateProcessAsUserW, SetKernelObjectSecurity, ImpersonateLoggedOnUser, RevertToSelf, RegGetValueW, RegOpenKeyExW, SetServiceStatus
api-ms-win-core-appcompat-l1-1-1.dll
BaseReadAppCompatDataForProcess, BaseFreeAppCompatDataForProcess
api-ms-win-core-localregistry-l1-1-0.dll
RegGetValueW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey
api-ms-win-core-processthreads-l1-1-0.dll
TerminateProcess, GetExitCodeProcess, GetCurrentProcessId, DeleteProcThreadAttributeList, GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, CreateProcessAsUserW, ResumeThread
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, CreateProcessAsUserW, DeleteProcThreadAttributeList, ResumeThread, GetCurrentProcessId, TerminateProcess, GetExitCodeProcess, UpdateProcThreadAttribute, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
GetExitCodeProcess, GetCurrentProcessId, ResumeThread, DeleteProcThreadAttributeList, UpdateProcThreadAttribute, CreateProcessAsUserW, TerminateProcess, GetCurrentThreadId, GetCurrentProcess, InitializeProcThreadAttributeList
api-ms-win-core-registry-l1-1-0.dll
RegQueryValueExW, RegGetValueW, RegOpenKeyExW, RegCloseKey
api-ms-win-security-base-l1-1-0.dll
ImpersonateLoggedOnUser, GetTokenInformation, CheckTokenMembership, SetTokenInformation, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, RevertToSelf
api-ms-win-security-base-l1-2-0.dll
GetSidSubAuthority, GetTokenInformation, SetTokenInformation, GetSidLengthRequired, InitializeSid, CheckTokenMembership, RevertToSelf, ImpersonateLoggedOnUser
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
kernel32.dll
GetLastError, InterlockedIncrement, LocalFree, WaitForSingleObject, InterlockedDecrement, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetSystemTimeAsFileTime, QueryPerformanceCounter, Sleep, InterlockedExchange, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetProcAddress, DelayLoadFailureHook, lstrlenW, GetTempPathW, GetSystemDirectoryW, GetEnvironmentVariableW, CreateFileMappingW, MapViewOfFile, CreateActCtxW, QueryActCtxSettingsW, ReleaseActCtx, UnmapViewOfFile, GetLongPathNameW, CheckElevationEnabled, CreateFileW, CheckElevation, GetFullPathNameW, GetFileAttributesW, ReadProcessMemory, ReleaseMutex, CreateMutexW, LocalAlloc, CreateEventW, CloseHandle, GetTickCount, UnregisterWait, SetEvent, GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, DeleteProcThreadAttributeList, GetTempFileNameW, ReadFile, WriteFile, DeleteFileW, GetCurrentProcessId, ResumeThread, GetExitCodeProcess, TerminateProcess, ResolveDelayLoadedAPI, DuplicateHandle, SetLastError, VirtualProtect, VirtualAlloc, VirtualFree, OutputDebugStringW, VirtualQuery
msvcrt.dll
DllMain
ntdll.dll
EtwTraceMessage, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwEventWrite, NtQuerySecurityObject, NtSetSecurityObject, RtlCreateServiceSid, RtlDosPathNameToRelativeNtPathName_U_WithStatus, RtlReleaseRelativeName, RtlFreeUnicodeString, RtlInitUnicodeStringEx, RtlPrefixUnicodeString, RtlQueryEnvironmentVariable, RtlInitUnicodeString, LdrOpenImageFileOptionsKey, LdrQueryImageFileKeyOption, RtlExpandEnvironmentStrings, RtlDestroyEnvironment, RtlCreateEnvironmentEx, RtlSetEnvironmentVar, NtOpenProcess, NtOpenThreadToken, NtQueryInformationToken, NtDuplicateObject, RtlRegisterWait, NtQuerySystemInformation, NtQueryInformationProcess, NtReadVirtualMemory, RtlNtStatusToDosErrorNoTeb, RtlImageNtHeaderEx, RtlDeregisterWaitEx, RtlDeregisterWait, RtlAcquireSRWLockExclusive, RtlReleaseSRWLockExclusive, RtlAcquireSRWLockShared, RtlReleaseSRWLockShared, NtOpenProcessToken, NtDuplicateToken, NtSetInformationToken, RtlRemovePrivileges, RtlNtStatusToDosError, NtClose, RtlInitializeSRWLock, EtwEventRegister, EtwEventUnregister, RtlSetDaclSecurityDescriptor, RtlAddAccessAllowedAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlLengthSid, NtOpenKey, RtlAppendUnicodeToString, RtlAppendUnicodeStringToString, NtQueryValueKey, DbgPrintEx, RtlFormatCurrentUserKeyPath, RtlExpandEnvironmentStrings_U, RtlAnsiStringToUnicodeString, NtMapViewOfSection, RtlFreeHeap, RtlInitAnsiString, RtlGetVersion, NtQueryInformationFile, NtUnmapViewOfSection, NtCreateFile, RtlAllocateHeap, RtlGetNativeSystemInformation, RtlUnicodeStringToInteger, NtCreateSection
rpcrt4.dll
RpcRevertToSelf, RpcImpersonateClient, I_RpcBindingInqLocalClientPID, RpcServerUseProtseqW, RpcAsyncCompleteCall, RpcServerInqBindings, RpcServerRegisterIfEx, RpcEpRegisterW, RpcServerUnregisterIf, RpcEpUnregister, RpcBindingVectorFree, NdrAsyncServerCall, NdrServerCall2
secur32.dll
GetUserNameExW
user32.dll
MonitorFromPoint
userenv.dll
UnloadUserProfile, DestroyEnvironmentBlock, CreateEnvironmentBlock, LoadUserProfileW
Export table
ServiceMain
SvchostPushServiceGlobals

appinfo.dll

Application Information Service by Microsoft

Remove appinfo.dll
Version:   6.3.9431.0 (winmain_bluemp.130615-1214)
MD5:   e460ddd1f3f30b86360e9b5c0ab63f2b
SHA1:   448829cd8b1b3036d3098e6b8d441c42f7bb0acb
SHA256:   a1b2c419c90ab4412c0c907bdc5d6b998b79b1575dfbbdc2c2787f739aa19cea
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is appinfo.dll?

The Application Information service (AIS) is responsible for creating a new process to run applications with elevated privileges, typically when running an administrative application while having UAC turned on. Application Information service the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.

Overview

appinfo.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). .

DetailsDetails

File name:appinfo.dll
Publisher:Microsoft Corporation
Product name:Application Information Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\appinfo.dll
Original name:appinfo.dll.mui
File version:6.3.9431.0 (winmain_bluemp.130615-1214)
Product version:6.3.9431.0
Size:87 KB (89,088 bytes)
Build date:6/15/2013 4:23 PM
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 31.50%
Windows 8.1 17.50%
Windows 7 Ultimate 9.00%
Windows 8.1 Pro 8.50%
Windows 8 8.00%
Windows 8 Pro 6.00%
Windows 7 Professional 3.50%
Windows Vista Home Premium 3.00%
Windows 8.1 Single Language 2.50%
Windows 7 Home Basic 2.00%
Windows 8 Single Language 2.00%
Windows 8.1 Pro with Media Center 1.00%
Windows 7 Starter 1.00%
Windows 8.1 Pro Preview 1.00%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 8.1 Enterprise 0.50%
Windows 8 Enterprise Evaluation 0.50%
Windows 8 Pro with Media Center 0.50%
Windows Vista Business 0.50%
Windows 8 Pro N 0.50%
Windows 8 Enterprise 0.50%
21 other Windows OS version

Distribution by countryDistribution by country

United States installs about 46.67% of Application Information Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 19.05%
Hewlett-Packard 17.22%
ASUS 16.12%
Acer 10.62%
Toshiba 10.26%
Lenovo 8.79%
Sony 7.33%
Samsung 2.56%
Intel 2.20%
GIGABYTE 1.83%
Medion 1.47%
Alienware 1.10%
MSI 0.73%
American Megatrends 0.73%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE