Information and startup locations can be examined on this page: verify all your files to make sure that they are legitimate, digitally signed and from the company Microsoft Corporation to which they should belong.
inetinfo.exe security and file info
Internet Information Services
- Internet Information Services
- Microsoft Corporation
 |
 |
 |
| Filetype : executable |
An executable file is a program that can be executed in your windows environment.
|
|
What is inetinfo.exe?
Inetinfo.exe, or the IIS Admin Service Helper, is a part of Microsoft Internet Information Services (IIS) that is used for debugging purposes. IIS is Microsoft's server software; however, components such as this have been known to have been installed with other third-party server software.
This executable is not essential to the proper operation of the system. If you are knowingly running IIS, however, do not disable this process, as it will bring your server down. If you are not running IIS or a server that depends on this executable, you can and should disable and uninstall IIS and with it this process.
Dangers of inetinfo
As this is a relatively common legitimate process, it is common for virus writers and spyware vendors to disguise their malware as the genuine one.
Some malicious files may have the same name but be stored somewhere other than in %SystemRoot%\System32. Other malware may use a name that appears similar to it but with slight differences in spelling or with appended digits. The following malware is known to disguise itself as the genuine inetinfo.exe:
- Trojan.W32.RONTOKBRO (%ApplicationData%)
- This is a Trojan that includes an SMTP engine such that it can easily spread itself.
There should not be more than one instance this process running at any given time. The presence of multiple instances may be an indicator of a malware infection. If this process is running without any servers running on your machine, your system may be infected.
Common problems
- Inetinfo prevents any other applications from using common server ports
- If you are not using IIS, disable the IIS Admin Service Helper service and uninstall any IIS-related software.
- If you are using IIS, this is by design.
- This process is using 100% CPU time
- If you are knowingly running IIS, make sure your SMTP server is not open (go into the IIS Console and check SMTP Virtual Server). If it is, it is possible that your machine is being used as a spam relay.
- If you are not knowingly running IIS, inetinfo.exe may be continuously trying to connect to localhost. Disable the IIS Admin Service Helper service and uninstall anything related to IIS.
|
|
|
|
|
|
| MD5 File security rating |
A MD5 hash is a unique fingerprint of a file.
Different files/versions can have the same filenames. The MD5 hash verifies that the legitimate file is not altered.
Runscanner (Freeware) can help you checking the file's MD5 hashes
| Inetinfo.exe files in Runscanner database |
 |
|
15 different item(s) in database |
 |
|
2 different item(s) in database |
 |
|
127 different item(s) in database |
|
 |
Green items are verified safe to use |
 |
Unrated items are not yet checked for safety. |
 |
Red items are not safe (typically virusses, spyware or other malware) |
 |
This file is digitally signed by it's publisher.
This means that the file is from the company claiming to created it, this does not mean by default that the file is safe
|
|
|
|
| General file info |
| Product name: |
Internet Information Services
|
| Description: |
Internet Information Services
|
| Company: |
Microsoft Corporation
|
| Fix INETINFO.EXE errors: Free registry scan |
|
|
|
| Pacman startup database |
|
Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more) |
|
Added by the BINGHE TROJAN! |
|
Added by the PARDROP-A TROJAN! |
| info provided by sysinfo.org |
|
|
|
Automatic startup locations
 |
| |
 |
001 Running Processes |
| |
 |
002 Autorun registry entries local machine |
| |
 |
003 Autorun registry entries Current User |
| |
 |
010 Installed services |
| |
 |
139 Windows\load |
| |
 |
166 HKCU Policies\Explorer\Run |
| |
 |
167 HKLM Policies\Explorer\Run |
User comments for this file
More system processes
|
|
| Filename / Process |
|
| Guid / CLSID |
|
| MD5 hash |
|
|
|
144 MD5 version(s) found
only top 10 displayed
|
|
|
| Check your autostart files
|
|
|
|