Windows malware analysis workstation

Turn one suspicious Windows endpoint into evidence you can explain.

Malware INFO is a local-first security and incident-analysis application for reputation lookup, Threat Lookup, Rapid Scan, Deep Signature Scan, Zero-Day Analysis, Protection Matrix, Quarantine Vault, Ransomware Shield, Security Connectors, Startup & Persistence Manager, selected-process memory recovery, API/DLL Trace workflows, and verified technical and executive reporting.

Public release

The public Free download is coming soon. Professional and Enterprise licenses are activated through the customer Portal.

Evidence boundary
Local-first by design
Primary users
SOC, DFIR, analysts
Platform
Windows workstation
Malware INFO Command Center showing protection and product status
Malware INFO Command Center

Clear positioning

A focused analyst workstation, not an EDR/XDR replacement.

Malware INFO complements antivirus, EDR, XDR, and SIEM platforms. It is designed for fast internal incident response when those platforms do not expose enough detail about a file, process, persistence artifact, or memory region. It does not replace an organization's existing endpoint protection.

The product turns deep evidence into a guided workflow so a user with foundational cybersecurity knowledge can investigate and respond more effectively. The stronger the operator's knowledge and judgment, the more value Malware INFO can provide; the software supports, but never replaces, human decisions.

Working files, memory captures, Live Protection history, and API Trace evidence do not need to be copied to a Malware INFO analysis cloud. Network actions remain explicit and tied to the feature the analyst chooses.

Company and accountability

Malware INFO is developed by United Info-Sec Co., Ltd.

Established in 2017, United Info-Sec is a Myanmar cybersecurity and total IT solutions company. Its stated work includes cybersecurity services, IT infrastructure support, secure digital services, and cybersecurity knowledge and awareness.

A public Myanmar International TV report dated 2 September 2022 records a meeting between officials from United Info-Sec and the Union Minister for Information, including a presentation concerning the MTube video-sharing and live-streaming platform.

Nay Pyi Taw Office United Info-Sec Co., Ltd No.(14), (X-5), Thukha Taw Win Housing Zabu Thiri Township, Nay Pyi Taw +95-9886440022 [email protected]

Current product

One investigation surface, from indicator to handoff.

The in-app Help covers every area below. Availability depends on edition, Windows access, target eligibility, provider rights, and the quality of available evidence.

Command Center

Protection, scan, update, and license status at a glance

Review the current protection state, recent activity, product and signature status, edition access, and the next investigation workspace from one starting point.

Threat Lookup

Hashes, files, URLs, domains, and IPs

Review summary, detections, comments, relationships, pivots, raw JSON, and license-aware VirusTotal API Explorer workflows.

Scan Studio

Hash, HEX, YARA, memory, and persistence

Combine known-bad hashes, signature rules, YARA, custom scopes, memory paths, persistence review, and analyst-controlled quarantine.

Zero-Day Analysis

Behavioral triage with careful verdicts

Score suspicious process, command-line, persistence, network, trust, and PE context without treating heuristic evidence as automatic proof.

Protection Matrix

Live file, process, registry, network, memory, and timeline evidence

Use the background Guard Service, visible engine state, focused monitor tabs, incident timelines, live executable-memory transitions, and analyst-controlled evidence capture.

Threat context

Threat Intelligence, Threat Briefing, and Vulnerability Alerts

Hunt with query templates, read trusted-source news, prioritize NVD/CISA KEV/FIRST EPSS evidence, save items, and export reader views.

Licensed providers

Dark Web Intelligence and organization-owned feeds

Normalize approved licensed-provider claims without direct onion crawling. Provider licensing, quotas, attribution, and retention remain the organization’s responsibility.

Containment

Quarantine Vault, restore, delete, and exceptions

Preserve original path, SHA-256, source, timestamps, and status. Keep containment separate from permanent deletion and review exceptions carefully.

Professional defense

Ransomware Shield

Protect selected folders with canary files, exact allowed-writer paths, mass-change thresholds, attributed response, logs, and safe verification steps.

Enterprise integrations

Security Connectors

Send normalized, authorized threat events and approved containment requests to organization-controlled HTTPS SIEM, XDR, SOAR, firewall, IDS/IPS, or integration gateways.

Enterprise remediation

Startup & Persistence Manager

Inventory Registry Run/RunOnce entries, Startup Folder items, and executable Scheduled Tasks; remove or disable selected persistence with a transaction-backed restore journal.

Enterprise analysis

Memory Payload Capture and Payload & Memory Analyzer

Recover bounded executable-memory evidence from one selected process, then correlate static PE/raw-memory findings, strings, bounded HEX, and matching session evidence in a local HTML report.

Enterprise tracing

Guided API Trace and Deep API Trace

Capture selected-process timelines, supported parameters and return values, memory snapshots, behavior chains, diagnostics, verified ZIP evidence, and an offline Final Report.

Enterprise

Final Report to CISO

Validate supported evidence packages from API Trace, Live Protection, and Payload & Memory Analyzer, correlate independent evidence, require analyst approval, and export a redacted offline HTML/PDF executive report with hashes, evidence links, contradictions, and collection gaps. It does not scan, contain, upload evidence, or make an automatic malware verdict.

Enterprise DLL analysis

DLL Behavior Trace

Preflight a native x86/x64 DLL without loading it, then use an explicit matching-bitness controlled host for an approved export, supported exact API evidence, memory capture, diagnostics, and verified HTML/ZIP reporting in an isolated lab.

Private intelligence

Administration and Detection Library

Import, validate, clean, and organize rules; build encrypted private hash/signature/YARA packages; and separate normal database work from Enterprise distribution.

Operations

Reports & Evidence, Update Center, and App Lock

Separate final evidence from operational diagnostics, stage program and public-signature updates, use Enterprise-controlled local detection packages, and protect Enterprise UI access.

In-development preview

Offline Windows Memory Forensics

Version 1.2.1 can show this workspace and its Help guide, but public analysis is not generally available. No real Windows build or production memory-image format is currently claimed as supported; this is distinct from the available live Memory Payload Capture workflow.

Public release

The Free download is coming soon.

Public release

Malware INFO is not publicly released yet. When the Free installer is ready, this page will publish the official download, SHA-256 hash, release notes, and safe-use guidance. Professional and Enterprise customers will receive license-checked updates from inside Malware INFO.

2026-08-22 No public installer is available yet Need Professional or Enterprise?

Simple licensing

Choose the access your work requires.

Prices are shown in USD. First choose how the license will be used, then select the edition, device quantity, and one-, two-, or three-year term.

Purchase purpose

Who will use these licenses?

Personal purchases are for one person on one device, with a one-, two-, or three-year term.

Free

Core investigation

$0no license required

  • Lookup and layered local scanning
  • Quarantine, reports, news, and CVE alerts
  • Manual installer upgrades
2026-08-22
Enterprise

Private and deep analysis

$501 device / 1 year

  • Administration, policy, and private packages
  • Ransomware, payload, and API analysis tools
  • License-checked Enterprise updates

Quantity and pricing policy

Personal stays single-device; volume plans separate internal use from resale.

Personal · 1 deviceOne person, one device, and a one-, two-, or three-year term. Personal checkout never offers a volume quantity.
Organization · 3 to 200+Internal-use plans offer 3, 10, 50, 100, or above 200 devices. Above 200 uses a custom quote.
Reseller · 10 to 200+10 devices cost the same as Organization. Published 50- and 100-device totals are lower; only above 200 requires a lower custom Reseller quote.

Published volume policy: Organization 50/100 pricing uses 35%/40% savings from the single-device list total. Reseller 50/100 pricing uses 45%/50% savings. Reseller inventory remains restricted to separate end customers. A reseller must use a reseller-only email account; an account that already has customer entitlements, registered Machine Hash values, or device licenses cannot later be approved as a reseller.

Complete published pricing

All USD totals through 100 devices

These are final displayed totals for the current catalog. Only quantities above 200 devices require a custom quote.

EditionPurposeDevices1 year2 years3 years
ProfessionalPersonal1$30$53$72
ProfessionalOrganization3$78$137$187
ProfessionalOrganization10$225$394$540
ProfessionalOrganization50$975$1,723$2,340
ProfessionalOrganization100$1,800$3,180$4,320
ProfessionalReseller10$225$394$540
ProfessionalReseller50$825$1,458$1,980
ProfessionalReseller100$1,500$2,650$3,600
EnterprisePersonal1$50$88$120
EnterpriseOrganization3$130$228$312
EnterpriseOrganization10$375$656$900
EnterpriseOrganization50$1,625$2,860$3,900
EnterpriseOrganization100$3,000$5,280$7,200
EnterpriseReseller10$375$656$900
EnterpriseReseller50$1,375$2,420$3,300
EnterpriseReseller100$2,500$4,400$6,000
Above 200 devicesOrganization and Reseller plans use a custom sales quote. The matching Reseller quote remains lower than the Organization quote.Request quote

Current payment options

Purchase by USDT or PayPal while the payment gateway is being prepared.

  1. 1

    Confirm purposeChoose Personal, Organization, or Reseller, then confirm edition, quantity, and term.

  2. 2

    Choose paymentComplete the purchase using the confirmed USDT or PayPal payment instructions supplied by the Malware INFO team.

  3. 3

    Receive the correct keyDirect buyers receive their entitlement Temp Key. Resellers receive inventory that can issue a different customer Temp Key for each sale.

  4. 4

    Customer completes licensingOnly the final customer redeems the customer Temp Key, enters the Machine Hash, and receives the device license key.

Edition access

Complete current-build feature comparison.

A check means the feature is available in that edition. A dash means it is locked or unavailable. Help Center content is visible across editions so evaluators can understand paid capabilities without bypassing license controls.

Free

Core investigation

Threat Lookup, Rapid Scan, Deep Signature Scan, Quarantine Vault review, Reports & Evidence, Detection Library, Threat Briefing, Vulnerability Alerts, and Help Center.

Professional

Analyst workstation

Everything in Free plus Zero-Day Analysis, Threat Intelligence, licensed connectors, Dark Web Intelligence, custom feeds, Live Protection, and Ransomware Shield.

Enterprise

Private and deep analysis

Everything in Professional plus Administration, private packages, watchlists, App Lock, Security Connectors, Startup & Persistence Manager, selected-process Memory Payload Capture and Payload & Memory Analyzer, and API/DLL trace workflows.

FeatureFreeProfessionalEnterprise
Threat Lookup and reputation reviewYesYesYes
Rapid Scan — known-bad hash evidenceYesYesYes
Deep Signature Scan — HEX signaturesYesYesYes
YARA rule scanYesYesYes
Quarantine Vault review, restore, delete, exportYesYesYes
Reports & EvidenceYesYesYes
Detection LibraryYesYesYes
Tray-only startup and close-to-trayYesYesYes
Colored tray shield status iconYesYesYes
Custom VirusTotal API keyNoYesYes
Zero-Day AnalysisNoYesYes
Threat IntelligenceNoYesYes
Built-in Intelligence query templatesNoYesYes
Enterprise custom Intelligence query templatesNoNoYes
Malware download when account allows itNoYesYes
API ExplorerNoYesYes
Protection Matrix / Live Protection — File / Registry / Process / Network / Security TimelineNoYesYes
Threat Briefing reader and PDF exportYesYesYes
Vulnerability Alerts reader and PDF exportYesYesYes
Threat Briefing / Vulnerability Alerts Enterprise watchlistsNoNoYes
Custom Threat Briefing RSS/Atom feedsNoYesYes
Organization-owned licensed Threat/CVE API connectorsNoYesYes
Dark Web Intelligence through a licensed providerNoYesYes
Ransomware ShieldNoYesYes
Security Connectors — SIEM/XDR/SOAR/gateway eventsNoNoYes
Startup & Persistence Manager — Registry Run, Startup Folder, and Scheduled Task restore-ready cleanupNoNoYes
Payload & Memory Analyzer — static/correlated HTML reportNoNoYes
Payload & Memory Analyzer — strings and bounded HEX previewNoNoYes
Memory Payload Capture — bounded executable-memory recoveryNoNoYes
Guided / Deep API Trace — parameters and return valuesNoNoYes
DLL Behavior Trace — controlled native x86/x64 DLL observationNoNoYes
Guided / Deep API Trace — memory snapshots and behavior chainsNoNoYes
Guided / Deep API Trace — verified ZIP and offline HTML Final ReportNoNoYes
Final Report to CISONoNoYes
Enterprise App Lock password protectionNoNoYes
App Lock tray shield/exit protectionNoNoYes
Enterprise license App Lock recoveryNoNoYes
Administration workspace and organization-controlled policyNoNoYes
Update Center — program and public-signature update stagingYesYesYes
Local Update serverNoNoYes
Private encrypted hash/signature/YARA packagesNoNoYes
Enterprise private Guard engine override optionsNoNoYes
Offline Windows Memory Forensics — in-development advertisement / Developer preview onlyNot generally availableNot generally availableNot generally available

Recommended workflow

Escalate only as far as the evidence requires.

Start with non-invasive context, preserve identity and timing, and move to controlled live analysis only when authorization and an isolated lab are available.

  1. 01
    Preserve

    Record the original path, name, size, SHA-256, source, and case context.

  2. 02
    Look up

    Check reputation and relationships when policy permits sharing the indicator.

  3. 03
    Scan locally

    Use hash, HEX, YARA, memory, persistence, and custom-scope evidence.

  4. 04
    Correlate behavior

    Review Zero-Day Analysis signals and Live Protection file, registry, process, network, and memory history.

  5. 05
    Contain carefully

    Quarantine confirmed supported files; treat alert-only findings as review priorities.

  6. 06
    Escalate in a lab

    Use Payload/API workflows only for an authorized selected process in an isolated environment.

  7. 07
    Export and hand off

    Preserve reports, manifests, checksums, collection gaps, and analyst notes.

Security, privacy, and evidence limits

Readable evidence with explicit boundaries.

No automatic cloud-analysis upload

Evidence stays local unless the user deliberately exports or shares it. VirusTotal lookup sends the selected indicator; a complete file is sent only after the user explicitly chooses Upload to VirusTotal and confirms.

Verdict discipline

Observed and Allowed do not mean safe. AlertOnly means review is required. Detected means a configured confirmed source matched. Quarantined means supported file containment succeeded.

Not a sandbox boundary

Malware INFO does not make it safe to execute unknown code on a normal computer. It cannot guarantee interception of every exploit, driver, direct syscall, credential theft, destructive action, or evasion technique.

Guided before Deep

Guided API Trace is least invasive. Deep API Trace changes timing, may trigger anti-debug behavior, and has target limits. Use it only when exact supported API evidence is necessary and the lab accepts the impact.

Memory is evidence, not a verdict

An RX/RWX dump proves readable bytes existed at a recorded time. Correlate identity, protection changes, writer/thread origin, timeline, signer, network, file, and persistence context.

Current analyzer boundary

Payload & Memory Analyzer provides bounded static PE/raw-memory review, strings, bounded HEX preview, capability findings, and evidence correlation.

Enterprise private intelligence

Keep organization-owned detection content under organizational control.

Administration supports private hashes, signatures, YARA rules, encrypted private packages, local update strategy, and organization-controlled policy workflows. Normal rule import, validation, cleanup, and *_to_fix review remain in Detection Library.

Malware INFO Administration workspace for private intelligence and local update strategy

Complete local Help Center

Guidance is built into the product.

Help Center includes product doctrine, Threat Lookup, Scan Studio, Threat Intelligence, Threat Briefing, Vulnerability Alerts, Dark Web Intelligence, Update Center, Administration, Detection Library, Reports & Evidence, Protection Matrix and Live Protection, Ransomware Shield, Security Connectors, Startup & Persistence Manager, Quarantine Vault, memory and API Trace workflows, DLL Behavior Trace, Advanced Analysis, the in-development Memory Forensics preview guide, a security glossary, safe-lab guidance, and the full FAQ below.

Malware INFO Help Center showing the edition feature comparison

Complete FAQ

Frequently asked questions and safe-lab guidance.

These answers focus on what customers and analysts need to purchase, install, operate, troubleshoot, and use Malware INFO safely. Open a question to read the complete guidance.

FAQ progress: 0 of 49 read on this browser.

Can I read Malware INFO Help in my language?

Yes. Malware INFO Help is currently available in 22 languages:

  • - العربية Arabic
  • Deutsch - German
  • English - English
  • Español - Spanish
  • Français - French
  • हिन्दी - Hindi
  • Bahasa Indonesia - Indonesian
  • Italiano - Italian
  • 日本語 - Japanese
  • 한국어 - Korean
  • Bahasa Melayu - Malay
  • မြန်မာ - Myanmar (Burmese)
  • Nederlands - Dutch
  • Polski - Polish
  • Português - Portuguese
  • Русский - Russian
  • ไทย - Thai
  • Türkçe - Turkish
  • Українська - Ukrainian
  • Tiếng Việt - Vietnamese
  • 简体中文 - Chinese (Simplified)
  • 繁體中文 - Chinese (Traditional)
Does Malware INFO replace antivirus, Endpoint Security, EDR, or XDR?

No. Malware INFO is an investigation and incident-analysis companion, not a replacement for antivirus, Endpoint Security, EDR, XDR, SIEM, or their prevention and response controls. It is designed to examine artifacts and evidence that an existing endpoint platform did not expose clearly enough, helping the user investigate suspicious files, processes, persistence, memory, and related incident activity in greater detail. Its guided workflows are intended to help users with foundational cybersecurity knowledge make better-informed decisions, but results still depend on evidence quality and human judgment. The stronger the operator's cybersecurity knowledge and analytical discipline, the more effectively Malware INFO can be used. Keep existing endpoint protection enabled and follow your organization's response policy.

Why can Windows 11 Smart App Control alert on or block Malware INFO?

Smart App Control is a Windows 11 protection feature that uses Microsoft's cloud-powered app intelligence and code-integrity checks to decide whether an application is trusted to run. Malware INFO has not yet been signed with a trusted code-signing certificate, so Smart App Control may treat a new or reputation-unknown release as untrusted and display an alert or block it. This does not by itself prove that Malware INFO is malicious. Until signed releases are available, obtain Malware INFO only from its official release channel and verify the published version and SHA-256. Do not weaken an organization's security policy merely to run an unverified file. United Info-Sec is working toward trusted code signing for future Malware INFO releases.

Can Malware INFO run in a Windows 7 malware sandbox?

Yes. Malware INFO has been tested successfully on 64-bit Windows 7 and can be used in legacy malware-sandbox and isolated lab workflows. On tested Windows 7 systems, it may temporarily use more memory during startup and can consume approximately 2 GB more RAM than on newer Windows versions before memory usage gradually settles. Because Windows 7 has reached end of life and Microsoft does not officially support .NET 10 on it, Malware INFO provides Windows 7 compatibility on a best-effort basis rather than the same support guarantee available on current Windows versions. Keep the Windows 7 environment isolated, provide sufficient RAM, take a snapshot before analysis, and do not use an end-of-life system as an ordinary Internet-connected endpoint.

Can I use Malware INFO on an x86 computer or Windows Server?

The current Malware INFO application, updater, and Guard Service are distributed for x64 Windows; there is no x86 edition of the main application at this time. The packaged x86 API Trace worker exists only to inspect eligible 32-bit target processes and does not make the main product compatible with a 32-bit PC. Malware INFO is intended for incident investigation on both supported x64 Windows client systems and eligible x64 Windows Server versions. The interactive application requires a compatible graphical desktop environment, the required Windows components and services, administrative approval, and compliance with organizational policy; a Server Core installation without the required interactive desktop cannot host the current UI directly. Normal server workloads can be investigated, while Windows critical or protected processes remain intentionally unavailable for invasive tracing or dumping to protect system stability.

How can I purchase Malware INFO before an online payment gateway is available?

Automated online checkout is not connected yet. Professional and Enterprise purchases are currently handled through confirmed Crypto (USDT) or PayPal payment instructions. Select Personal, Organization, or Reseller before choosing the edition, device quantity, and term, then contact [email protected]. Send funds only using payment details confirmed through that official address; Malware INFO does not request a wallet seed phrase, private key, or account password.

Which device quantities are available for each purchase purpose?

Personal is limited to one device for one, two, or three years. Organization offers 3, 10, 50, 100, or above 200 devices. Reseller offers 10, 50, 100, or above 200 independent customer licenses. Above 200 is always handled as a custom quote.

How do Organization and Reseller prices compare?

The Organization and Reseller 10-device totals are intentionally identical. The published Reseller totals are lower than Organization at 50 and 100 devices for the same edition and term. For above-200 custom quotes, the matching Reseller quote must also remain lower.

Can I use the same Portal email as both a customer and a reseller?

No. A reseller must use a reseller-only Portal email account. If an email account has already redeemed a customer entitlement, registered a Machine Hash, or generated a device license, that account cannot later be approved as a reseller. This prevents customer device ownership and reseller inventory from mixing in one account. If you want to become a reseller, sign in to the Portal once with a separate reseller email address and ask Malware INFO Admin to approve that reseller-only account before reseller inventory is issued.

I purchased a license and received a Key (Temp Key). What should I do next?

A Temp Key represents the purchased entitlement; it is not yet the device-specific license used by Malware INFO.

  1. Open the Malware INFO User Portal.
  2. Sign in with the exact email address used to purchase the key or the customer email address assigned to the key by the approved reseller.
  3. Activate or redeem the purchased Temp Key. The Portal will display the license edition and the number of included devices. A different Portal email account cannot redeem that email-bound key.
  4. Install Malware INFO only from the official release channel approved for your account or organization.
  5. Open Malware INFO and select Register.
  6. Copy the Machine Hash shown by the application.
  7. Return to the Portal, add the Machine Hash to an available device slot, and generate the device license key.
  8. Enter that device license key in Malware INFO and activate the application.
  9. Malware INFO will restart automatically after successful activation.
  10. After restart, confirm that Live Protection is active. If the service is not active, open Protection Matrix from the sidebar and use Start protection service.

Keep the Temp Key, Machine Hash, and device license key private. Use only portal.malwareinfo.app and official Malware INFO installers.

If I buy a license in advance, does its one-year or multi-year term expire before I use it?

No. The purchased license term is not counted from the purchase date. It begins when you first register a Machine Hash in the Portal to generate the device license. You may therefore purchase the entitlement in advance, but add the Machine Hash and generate the device license only when you are ready to deploy Malware INFO on that computer. Once activation has begun, the applicable one-year, two-year, or other purchased term runs according to the entitlement shown in the Portal.

If someone obtains my activated Malware INFO device license key, will my license be revoked?

No. An activated device license is bound to the registered Machine Hash and cannot normally be reused to activate Malware INFO on another computer. The license will not be revoked solely because another person copied or viewed that device-bound key. Keep the key private, do not publish it, and contact Malware INFO support if the Portal shows an unknown device or other unauthorized account activity.

What happens if my license key and Malware INFO software are being shared publicly online?

A license confirmed to be distributed publicly with Malware INFO, used for unauthorized redistribution, or shared to bypass the licensed device and account rules will be added to the revocation list. The revoked key can no longer be used for continued licensed operation. A user who wants to continue using Malware INFO must purchase a new legitimate license. Accidental exposure of a device-bound key is reviewed separately from confirmed public software-and-license distribution.

Why does my Redeem Key show as invalid in the Portal?

A Redeem Key is bound to the email address recorded when the key is purchased or assigned by an approved reseller. Sign out of the Portal, then sign in with that exact purchase email address and redeem the key from that account. The Portal will show the key as invalid when it is entered from a different email account, even if the key text itself was copied correctly. If the key is still rejected from the correct purchase email, contact the seller or Malware INFO support from that same email address and provide the order or proof of purchase. Keep the key private and never send an account password.

I found a suspicious file. Where should I start?

Do not execute an unknown file on an everyday computer.

  1. Preserve its original path, name, size, and SHA-256.
  2. Use Threat Lookup when policy permits sharing the indicator.
  3. Run Rapid Scan and Deep Signature Scan for local hash, HEX, and YARA evidence.
  4. Use Zero-Day Analysis and Live Protection history for behavior context.
  5. Escalate to a controlled lab only when live execution is authorized and necessary.
Zero-Day Malware detected appeared. Should I quarantine or delete the file?

First read the detection source. A confirmed trusted hash, HEX signature, YARA/private rule, or user-confirmed malware-hash match is shown as a red Detected result and can send a supported file to Quarantine Vault according to the active policy. Prefer quarantine before permanent deletion because it preserves file identity, original path, detection reason, and a reversible evidence record. Delete only after incident evidence and retention decisions are complete.

A Zero-Day Analysis score by itself is heuristic AlertOnly evidence, even when the score is High or Critical. Do not call the file confirmed malware or permanently delete it from that score alone. Correlate it with Deep API Trace behavior, Payload & Memory Analyzer strings/memory evidence, signer and path context, and Rapid Scan / Deep Signature Scan results. If harmful activity is continuing, isolate the affected computer and follow the approved incident-response process while preserving evidence.

Does a red AlertOnly row mean Malware INFO confirmed malware?

No. AlertOnly means a rule found behavior or context that needs attention but did not meet a confirmed automatic-block boundary. Red is a review-priority color, not a malware-family verdict. Read the reason, process, signer, parent, path, related file/registry/network events, and any confirmed hash, HEX, or YARA evidence before deciding to quarantine.

What do Observed, Allowed, AlertOnly, Detected, and Quarantined mean?

Observed means activity was recorded without a malicious verdict. Allowed means the current policy did not block that event; it does not certify the program as safe. AlertOnly means review is required but automatic containment was not justified. Detected means a configured confirmed-detection source matched. Quarantined means a supported file was moved into protected containment. Always read Source, Engine, Reason, Action/Decision, path, and correlation together.

What is Protection Matrix, and what should I review first?

Protection Matrix is the Professional and Enterprise workspace for Live Protection status and current Guard evidence. First confirm that the protection service and required engines are active. Then review Detection Events and the Process, File, Registry, Network, and Security Timeline views around the incident time. Use the filters and correlation details to connect related activity, but do not treat one color, one event, or one executable-memory transition as an automatic malware verdict. Preserve the relevant report or evidence before containment changes.

Windows Defender or another AV detects Malware INFO. What should I do?

Treat the alert as unverified until the exact file is checked. Record the AV detection name, file path, product version, and SHA-256. Confirm that the package came from the approved Malware INFO distribution channel; compare a published hash when one is available; inspect the publisher signature when the release provides one; update the AV engine and security intelligence; and submit the exact file to the AV vendor as a suspected false positive. Microsoft Defender submissions can be made through Microsoft Security Intelligence file submission. If source, hash, or release identity cannot be verified, do not restore or exclude the file.

Should I exclude the Malware INFO app, the malware sample, or both?

On a normal production or personal endpoint, neither should be excluded by default. If a verified Malware INFO component is falsely detected and an immediate, policy-approved workaround is essential, allow only the exact verified product file reported by the AV. A malware sample or recovered payload should remain scanned on ordinary endpoints. Live-malware exclusions belong only inside a disposable, isolated research guest and only for the shortest necessary test window.

Defender detects payload_*.bin, *.memimg, or an exported case. Is that a Malware INFO false positive?

Not necessarily. A payload dump, memory image, quarantine object, or API evidence artifact can contain the real malicious bytes recovered from the target. An AV detection on that evidence may therefore be correct even when Malware INFO itself is clean. Record the exact detected path and hash, keep it inside controlled case storage, and do not classify it as a product false positive merely because Malware INFO created the file.

The AV deletes the sample while Malware INFO is analyzing it. How can I study the behavior responsibly?

Use two separate passes. Pass 1—protection-on: keep the AV enabled, record its detection and timing, preserve Guard/AV evidence, and complete all static analysis possible. Pass 2—controlled execution: only when authorized behavior evidence is still required, revert a disposable analysis VM to a clean snapshot, disconnect it from production networks, disable host integration, place the sample in a dedicated guest-only lab folder, and apply the narrowest temporary guest exclusion only if the AV still prevents the approved test. Start Malware INFO monitoring before launch, stop collection after the planned window, preserve checksums and reports, then revert or destroy the guest.

What is the minimum safe-lab checklist before running malware?
  1. Use a disposable full VM or an organization-approved sandbox; a full VM is preferable when Guard Service installation, restart, command-line replay, or longer observation is required.
  2. Take a clean snapshot before importing the sample.
  3. Remove corporate accounts, browser sessions, tokens, VPNs, SSH keys, password managers, and real documents.
  4. Disable shared clipboard, drag-and-drop, shared folders, host-drive mapping, USB passthrough, and unnecessary guest integrations.
  5. Use no network or a controlled malware-lab network with no route to production.
  6. Prepare monitoring and evidence storage before launch.
  7. Revert or destroy the guest after collection.
What if I do not have an isolated malware-analysis lab?

Do not execute the sample. Limit the case to static hash, signature, YARA, PE, strings, HEX, reputation, existing Guard history, and already-collected evidence. Preserve the artifact according to policy and transfer the case to an authorized team or lab. Lack of a lab is not a reason to disable AV or create sample exclusions on a production computer.

Should I turn off Defender or the AV completely during research?

Not on the host or an ordinary endpoint. Full AV disablement removes unrelated protection and makes operator mistakes harder to contain. In an approved disposable guest, a tightly controlled team may temporarily change protection only when the research objective cannot be met with a narrow path/file rule, but that is an exceptional laboratory decision requiring authorization, isolation, a fixed time window, and mandatory snapshot reversion—not normal Malware INFO setup guidance.

Can the malware-analysis VM use the Internet?

Default to no network. If network behavior must be observed, use a controlled lab segment or simulation service with no route to production, management interfaces, shared storage, printers, identity services, or the host. Capture DNS and connection evidence, apply egress limits, and obtain authorization before allowing any external communication. Do not let a sample contact real victims, scan third parties, send spam, or exfiltrate captured data.

What should I do after the live-analysis window?

Stop the API/Payload session, export the human-readable report and checksum inventory through the approved evidence workflow, record the sample and report hashes, and close the test. Do not return the guest to normal use. Revert to the clean snapshot or destroy the VM. Remove any temporary AV rule from the reusable base image and verify that no shared folder, clipboard, mounted image, or removable media still exposes sample bytes.

Does Malware INFO make it safe to run malware on my normal computer?

No. Malware INFO observes, scans, correlates, dumps, and helps contain supported activity, but it is not a virtualization boundary and cannot guarantee interception of every exploit, kernel driver, direct syscall, credential theft, network action, destructive operation, or anti-analysis technique. Unknown code must still be treated as hostile and executed only inside an authorized isolated environment.

What is the practical difference between Safe Trace and Deep Trace?

Safe Trace is the least-invasive selected-process timeline: it correlates available Guard, Event Log, ETW, runtime, and snapshot evidence without attaching a debugger or injecting into the target. Deep Trace is an explicit matching-bitness debugger workflow that can capture supported API entry/return evidence and bounded parameters, but it changes timing, may trigger anti-debug behavior, has target eligibility limits, and is never automatic. Use Safe first; choose Deep only when exact supported API calls are required and the lab accepts the added impact.

Does a dumped RWX/RX memory region prove it is malware?

No. A dump proves that bytes were readable from a selected memory region at a recorded time. JIT runtimes, browsers, compatibility layers, security tools, and packers can also create executable private memory. Correlate the region with its MZ/PE identity, entropy, strings, protection transitions, writer/thread origin, API timeline, process path, signer, network/file/persistence activity, and the Payload & Memory Analyzer report before assigning a malware conclusion.

Can Payload & Memory Analyzer name the exact malware family?

Not reliably from one memory chunk. The Enterprise analyzer performs bounded static PE/raw-memory inspection, strings and HEX preview, capability review, and matching session JSON/JSONL correlation. It can describe architecture, artifact shape, capabilities, and behavior leads, but those are analyst hypotheses rather than a guaranteed family attribution.

What do red, orange, and blue processes mean?

Red marks a critical or protected target for which invasive inspection, restart, or dumping is blocked. Orange means an inspectable high-privilege SYSTEM process that requires extra care and the least-invasive supported plan. Blue means a current-user process prioritized after executable private RX/RWX memory was observed or selected for payload review. Orange and blue are investigation priorities, not malware verdicts.

Should every NT AUTHORITY\SYSTEM or System32 process be ignored?

No. Location and account alone do not prove safety. Malware can inject into, imitate, or abuse trusted processes. Malware INFO blocks known critical/protected targets from invasive actions, displays eligible high-privilege SYSTEM processes as orange, and keeps target identity and access checks. Review path, signer, parent, command line, loaded modules, executable memory, and related activity; never force tracing against a red critical target.

Why does exact command line matter when using Restart & Record?

Some loaders, DLL hosts, services, and malware families act only with a particular argument, working directory, token, environment, or parent context. Restarting only the executable path can produce different behavior or no behavior. Use verified launch-context evidence, preserve the original command line, and treat unsupported fields honestly. Fileless or path-unavailable processes cannot be recreated safely from an invented command.

Where are payload and API trace results stored, and what should I read first?

Memory Payload Capture evidence is stored under C:\ProgramData\MalwareInfo\SecurityState\Guard\PayloadEvidence. API Trace sessions are stored under C:\ProgramData\MalwareInfo\SecurityState\Guard\ApiTraceEvidence with per-session access control. Use Open Evidence Folder or Export Verified ZIP instead of browsing protected parent folders. For an API Trace session, open index.html first; it summarizes collection state, exact/correlated evidence, memory artifacts, gaps, behavior chains, and next steps. JSON/JSONL remains the checksum-covered forensic source when deeper validation is required.

What should I do when Guard Service is stopped or Start Service fails?

Confirm the application was installed as one complete matching build under the expected program folder and that it is running with the required administrative approval. Use Repair Service to replace and re-register the service boundary, then run the service test and read the reported status. If it still fails, preserve Logs\StartupError.log and Guard/service diagnostic logs, record the Windows service error, and avoid repeatedly mixing Debug, Release, or older GuardService files.

Help or a report shows a WebView error. What is required?

Use one complete Fresh deployment instead of copying selected Debug/Release files. MalwareInfo.exe must retain its packaged WebView2Loader.dll and managed dependencies, and the computer must have a compatible Microsoft Edge WebView2 Runtime. If WebView cannot initialize, the fallback message identifies the missing runtime or loader. Reinstall the current Fresh package and WebView2 Runtime rather than copying one DLL from another build.

Does Malware INFO upload my files, dumps, or incident logs?

There is no automatic Malware INFO cloud-analysis upload pipeline in the current architecture. Evidence stays local unless the user deliberately exports or shares it. Network features remain explicit: public feeds and updates retrieve data; licensed connectors contact the configured provider; VirusTotal lookup sends the selected indicator; a complete file is sent only after the user explicitly chooses Upload to VirusTotal and confirms. Memory evidence can contain secrets, so local storage still requires access, retention, and sharing controls.

What do Security Connectors send, and do they give another platform control of my endpoint?

Security Connectors is an Enterprise-only outbound integration. It can send normalized, authorized Guard or Zero-Day security events to organization-approved HTTPS receivers such as a SIEM, XDR, SOAR, firewall, IDS/IPS, or managed gateway. Malware INFO does not open an inbound SIEM port or grant arbitrary remote control. Any containment request must use the configured approved gateway, policy checks, audit records, and a validated applied, rejected, or failed result; a delivered event or accepted receipt alone does not prove that an action was enforced. Enable file-path sharing and automated actions only when organizational policy permits them.

What can Startup & Persistence Manager change?

Startup & Persistence Manager is an Enterprise workflow that inventories supported Registry Run and RunOnce values, Startup Folder items, and executable Scheduled Tasks. An authorized analyst can disable or remove a selected supported item through a transaction-backed workflow that records a restore journal. Review the publisher, path, owner, purpose, creation time, and related process activity before changing anything. A persistence entry is not automatically malicious, and unsupported persistence mechanisms must be investigated with other evidence.

How should I use Update Center safely?

Use Update Center to keep three update jobs separate: Program Update for Malware INFO application files, Signature Update for public detection content, and Enterprise Local Update for organization-controlled detection packages. Use only the source configured by the application or your organization, review the offered version and channel, and verify the published hash or signature when supplied. Do not copy selected files from another build or mix old application, updater, Guard Service, and worker components; install one complete matching package.

Is offline Windows Memory Forensics generally available in Version 1.2.1?

No. Version 1.2.1 can display the Memory Forensics workspace and its Help guide as an in-development advertisement and Developer preview, but Free, Professional, and Enterprise licensing alone does not enable public analysis. No real Windows build or production memory-image format is currently claimed as supported. The existing Enterprise Memory Payload Capture and Payload & Memory Analyzer features work with selected-process evidence and are separate from offline physical-memory or crash-dump analysis. Do not purchase an edition on the assumption that the future offline Memory Forensics subsystem is already generally available.

What do (Pro/Ent Version) and (Ent Version) mean?

They are short access hints, not errors. A Free user sees Professional-capable features as (Pro/Ent Version) and Enterprise-only features as (Ent Version). A Professional user sees only Enterprise-only features marked (Ent Version). Enterprise users see no suffix. Help may describe a paid feature to explain the product, but documentation visibility never unlocks the control.

What should I check before restoring a quarantined file?

Confirm why it was quarantined, validate its hash and source, review the detection engine and related activity, determine whether it is a verified false positive or an accepted business risk, and choose a controlled destination. Do not restore directly into an active startup, service, Run key, scheduled-task, or production path. If an exception is genuinely required, scope and approve it separately; restoring a file does not automatically make it trusted.

How does Final Report to CISO turn technical evidence into a report leadership can act on?

Final Report to CISO is an Enterprise-only final reporting workspace, not another scanner. It validates supported structured packages from API Trace, Live Protection Guard evidence, and Payload & Memory Analyzer; preserves source identities, hashes, and evidence links; correlates independent observations; and exposes contradictions and collection gaps before producing a decision-focused 12-section narrative.

  1. Create one case folder and copy each complete supported evidence package into it without renaming or separating files from its manifest.
  2. Open Final Report to CISO, select the case folder, and validate the packages.
  3. Enter the case ID, incident title, and business context, then choose the appropriate redaction mode.
  4. Review source coverage, integrity, correlated findings, contradictions, known unknowns, collection gaps, and recommended actions.
  5. Explicitly confirm the human review and export a new verified ZIP containing the offline HTML report, executive PDF, normalized JSON, source inventory, and SHA-256 manifest.

The workflow runs locally and offline with deterministic rules. It does not require cloud AI, upload case evidence, execute recovered content, scan or quarantine files, change endpoint state, or make an automatic malware verdict. An Incident Handler must review and approve the report and remains responsible for containment, disclosure, and attribution decisions.

How should I preserve evidence for another analyst?

Stop active collection cleanly, use the product’s report/export action, retain the manifest and SHA-256 inventory, and work from a copy. Record case ID, source computer, target PID and creation time, collection mode, UTC start/stop, analyst, product version, and any source gaps or AV actions. Transfer only through an organization-approved evidence channel and remember that a report, dump, or archive may itself trigger AV because it contains malicious material.

Why does my copy show Lifetime Version or Unlimited Features?

Official Malware INFO licenses are issued only for fixed terms of up to three years. Malware INFO does not sell a Lifetime Version or an Unlimited Features license. If a copy displays either claim, treat it as an unauthorized modified, cracked, or pirated build rather than an official edition.

Stop using it, do not enter a real license key or organizational credentials, preserve its source and SHA-256 for review, scan the affected computer, and replace the software with an installer obtained through an official Malware INFO channel. Using unlicensed software may expose the user or organization to legal or contractual action, violate workplace security and acceptable-use policy, affect employment responsibilities, and introduce malicious code added by an unknown distributor.

Why is Malware INFO priced so affordably despite including uncommon security-analysis capabilities?

The developer of Malware INFO spent seven years serving on a national CERT team and handling numerous APT malware and ransomware incidents in an environment with limited staffing, budgets, and specialist skills. That experience showed how difficult it can be for resource-constrained CERT and CSIRT teams to investigate incidents quickly and to support a broader, collaborative response to malware affecting users across a country.

The product was created to carry that objective forward by making practical incident-analysis capability affordable to individual users and accessible to organizations of different sizes. Its price is an accessibility decision, not a claim that users should accept the product without evaluation. Malware INFO should be assessed by comparing its documented capabilities, reproducible evidence, safety boundaries, and real investigation results with other established security tools.

Official downloads

The official Free download is coming soon.

Public release

No public Free installer is available at this time. When release is ready, use only the official Malware INFO website or repository and verify the published SHA-256. Paid update packages are delivered only after the app verifies an active Professional or Enterprise license, edition, and registered device.

Websitewww.malwareinfo.app Public installer2026-08-22 License managementportal.malwareinfo.app Paid updatesAvailable only inside the activated application

Contact

Questions about Malware INFO?

For product, documentation, release, or organizational evaluation questions, contact:

Purchase notice

Purchase with USDT or PayPal.

The automated payment gateway is not connected yet. Purchases are currently completed using Crypto (USDT) or PayPal instructions confirmed by the Malware INFO team. No payment has been taken by this website.