Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 2.64%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.22%
6.3.9600.16384 (winblue_rtm.130821-1623) 3.96%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.33%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.11%
6.2.9200.16384 (win8_rtm.120725-1247) 2.53%
6.2.9200.16384 (win8_rtm.120725-1247) 8.36%
6.2.9200.16384 (win8_rtm.120725-1247) 8.25%
6.2.9200.16384 (win8_rtm.120725-1247) 1.21%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.11%
6.1.7600.16385 (win7_rtm.090713-1255) 18.04%
6.1.7600.16385 (win7_rtm.090713-1255) 3.74%
6.1.7600.16385 (win7_rtm.090713-1255) 16.61%
6.1.7600.16385 (win7_rtm.090713-1255) 2.86%
6.1.7600.16385 (win7_rtm.090713-1255) 14.41%
6.1.7600.16385 (win7_rtm.090713-1255) 5.17%
6.1.7600.16385 (win7_rtm.090713-1255) 0.22%
6.0.6001.18000 (longhorn_rtm.080118-1840) 1.32%
6.0.6001.18000 (longhorn_rtm.080118-1840) 9.35%
6.0.6000.16386 (vista_rtm.061101-2205) 0.55%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetTokenInformation, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, SetTokenInformation, RegisterServiceCtrlHandlerExW, RegCloseKey, RegQueryValueExW, ConvertSecurityDescriptorToStringSecurityDescriptorW, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW, CheckTokenMembership, CreateProcessAsUserW, SetKernelObjectSecurity, ImpersonateLoggedOnUser, RevertToSelf, RegGetValueW, RegOpenKeyExW, SetServiceStatus
api-ms-win-core-appcompat-l1-1-1.dll
BaseReadAppCompatDataForProcess, BaseFreeAppCompatDataForProcess
api-ms-win-core-localregistry-l1-1-0.dll
RegGetValueW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey
api-ms-win-core-processthreads-l1-1-0.dll
TerminateProcess, GetExitCodeProcess, GetCurrentProcessId, DeleteProcThreadAttributeList, GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, CreateProcessAsUserW, ResumeThread
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, CreateProcessAsUserW, DeleteProcThreadAttributeList, ResumeThread, GetCurrentProcessId, TerminateProcess, GetExitCodeProcess, UpdateProcThreadAttribute, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
GetExitCodeProcess, GetCurrentProcessId, ResumeThread, DeleteProcThreadAttributeList, UpdateProcThreadAttribute, CreateProcessAsUserW, TerminateProcess, GetCurrentThreadId, GetCurrentProcess, InitializeProcThreadAttributeList
api-ms-win-core-registry-l1-1-0.dll
RegQueryValueExW, RegGetValueW, RegOpenKeyExW, RegCloseKey
api-ms-win-security-base-l1-1-0.dll
ImpersonateLoggedOnUser, GetTokenInformation, CheckTokenMembership, SetTokenInformation, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, RevertToSelf
api-ms-win-security-base-l1-2-0.dll
GetSidSubAuthority, GetTokenInformation, SetTokenInformation, GetSidLengthRequired, InitializeSid, CheckTokenMembership, RevertToSelf, ImpersonateLoggedOnUser
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
kernel32.dll
GetLastError, InterlockedIncrement, LocalFree, WaitForSingleObject, InterlockedDecrement, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetSystemTimeAsFileTime, QueryPerformanceCounter, Sleep, InterlockedExchange, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetProcAddress, DelayLoadFailureHook, lstrlenW, GetTempPathW, GetSystemDirectoryW, GetEnvironmentVariableW, CreateFileMappingW, MapViewOfFile, CreateActCtxW, QueryActCtxSettingsW, ReleaseActCtx, UnmapViewOfFile, GetLongPathNameW, CheckElevationEnabled, CreateFileW, CheckElevation, GetFullPathNameW, GetFileAttributesW, ReadProcessMemory, ReleaseMutex, CreateMutexW, LocalAlloc, CreateEventW, CloseHandle, GetTickCount, UnregisterWait, SetEvent, GetCurrentProcess, GetCurrentThreadId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, DeleteProcThreadAttributeList, GetTempFileNameW, ReadFile, WriteFile, DeleteFileW, GetCurrentProcessId, ResumeThread, GetExitCodeProcess, TerminateProcess, ResolveDelayLoadedAPI, DuplicateHandle, SetLastError, VirtualProtect, VirtualAlloc, VirtualFree, OutputDebugStringW, VirtualQuery
msvcrt.dll
DllMain
ntdll.dll
EtwTraceMessage, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwEventWrite, NtQuerySecurityObject, NtSetSecurityObject, RtlCreateServiceSid, RtlDosPathNameToRelativeNtPathName_U_WithStatus, RtlReleaseRelativeName, RtlFreeUnicodeString, RtlInitUnicodeStringEx, RtlPrefixUnicodeString, RtlQueryEnvironmentVariable, RtlInitUnicodeString, LdrOpenImageFileOptionsKey, LdrQueryImageFileKeyOption, RtlExpandEnvironmentStrings, RtlDestroyEnvironment, RtlCreateEnvironmentEx, RtlSetEnvironmentVar, NtOpenProcess, NtOpenThreadToken, NtQueryInformationToken, NtDuplicateObject, RtlRegisterWait, NtQuerySystemInformation, NtQueryInformationProcess, NtReadVirtualMemory, RtlNtStatusToDosErrorNoTeb, RtlImageNtHeaderEx, RtlDeregisterWaitEx, RtlDeregisterWait, RtlAcquireSRWLockExclusive, RtlReleaseSRWLockExclusive, RtlAcquireSRWLockShared, RtlReleaseSRWLockShared, NtOpenProcessToken, NtDuplicateToken, NtSetInformationToken, RtlRemovePrivileges, RtlNtStatusToDosError, NtClose, RtlInitializeSRWLock, EtwEventRegister, EtwEventUnregister, RtlSetDaclSecurityDescriptor, RtlAddAccessAllowedAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlLengthSid, NtOpenKey, RtlAppendUnicodeToString, RtlAppendUnicodeStringToString, NtQueryValueKey, DbgPrintEx, RtlFormatCurrentUserKeyPath, RtlExpandEnvironmentStrings_U, RtlAnsiStringToUnicodeString, NtMapViewOfSection, RtlFreeHeap, RtlInitAnsiString, RtlGetVersion, NtQueryInformationFile, NtUnmapViewOfSection, NtCreateFile, RtlAllocateHeap, RtlGetNativeSystemInformation, RtlUnicodeStringToInteger, NtCreateSection
rpcrt4.dll
RpcRevertToSelf, RpcImpersonateClient, I_RpcBindingInqLocalClientPID, RpcServerUseProtseqW, RpcAsyncCompleteCall, RpcServerInqBindings, RpcServerRegisterIfEx, RpcEpRegisterW, RpcServerUnregisterIf, RpcEpUnregister, RpcBindingVectorFree, NdrAsyncServerCall, NdrServerCall2
secur32.dll
GetUserNameExW
user32.dll
MonitorFromPoint
userenv.dll
UnloadUserProfile, DestroyEnvironmentBlock, CreateEnvironmentBlock, LoadUserProfileW
Export table
ServiceMain
SvchostPushServiceGlobals

appinfo.dll

Application Information Service by Microsoft

Remove appinfo.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   eacfdf31921f51c097629f1f3c9129b4
SHA1:   383b152095312686b68c8514a155bb93918a841e
SHA256:   24138755d823e69760579ecbd672421192457cdc9941b2bc499c2d34d83e86c3
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is appinfo.dll?

The Application Information service (AIS) is responsible for creating a new process to run applications with elevated privileges, typically when running an administrative application while having UAC turned on. Application Information service the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.

Overview

appinfo.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7.

DetailsDetails

File name:appinfo.dll
Publisher:Microsoft Corporation
Product name:Application Information Service
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\appinfo.dll
Original name:appinfo.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:46 KB (47,104 bytes)
Build date:2/26/2013 11:50 PM
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'
  • Shared name is 'Appinfo'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 31.50%
Windows 8.1 17.50%
Windows 7 Ultimate 9.00%
Windows 8.1 Pro 8.50%
Windows 8 8.00%
Windows 8 Pro 6.00%
Windows 7 Professional 3.50%
Windows Vista Home Premium 3.00%
Windows 8.1 Single Language 2.50%
Windows 7 Home Basic 2.00%
Windows 8 Single Language 2.00%
Windows 8.1 Pro with Media Center 1.00%
Windows 7 Starter 1.00%
Windows 8.1 Pro Preview 1.00%
Windows 8.1 Enterprise Evaluation 0.50%
Windows 8.1 Enterprise 0.50%
Windows 8 Enterprise Evaluation 0.50%
Windows 8 Pro with Media Center 0.50%
Windows Vista Business 0.50%
Windows 8 Pro N 0.50%
Windows 8 Enterprise 0.50%
21 other Windows OS version

Distribution by countryDistribution by country

United States installs about 46.67% of Application Information Service.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 19.05%
Hewlett-Packard 17.22%
ASUS 16.12%
Acer 10.62%
Toshiba 10.26%
Lenovo 8.79%
Sony 7.33%
Samsung 2.56%
Intel 2.20%
GIGABYTE 1.83%
Medion 1.47%
Alienware 1.10%
MSI 0.73%
American Megatrends 0.73%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE