A warning, K-Lite codec pack can install Infatica.

pc1

n3wb
May 7, 2018
20
16
I recently saw unusual entries in my Asus router's AI Protection logs. I ran a full scan of windows defender, found nothing. I then ran Malwarebytes, it flagged Infatica as a pup. Infatica is a proxy service, and while it can have legitimate uses, it has high potential for malicious use. When you first install K-Lite codec pack, it will also install Infatica unless you deselect it. ( K-Lite codec pack updates do not install Infatica, just a full install). Just a warning to be very careful to not install Infatica during a K-Lite codec pack install. Anyway, I'm now planning a full system wipe and install of windows LTSC.
 
  • Like
Reactions: TonyR
Good to know.

Yes, so many of my clients and friends will install a legit program but in their haste (I guess) fail to notice and uncheck boxes for McAfee Scan, Mindspring crap and so on ad nauseam then call me, I look at it and of course I hear "...but I didn't install that." :lmao:
 
  • Haha
Reactions: looney2ns
Have you asked the authors why it installs this if it has legitimate uses? It maybe for their update service or some other reason eg usage data. I have Klite on my system and malwarebytes and it doesn't detect infactia on my system albeit my klite is an older version.
 
I posted the question at codecs.forumotion.net , it was silently deleted soon after. The attached image is the step in the install process where you have to decline the Infatica installation, and does not suggest it has any legitimate use.
As for the threat actors, the system I had inadvertently installed Infatica on during K-Lite install, soon began lighting up my router's AI Protection logs with many entries for "Malicious Sites Blocking", "Two-Way IPS", and "Infected Device Prevention and Blocking".
I wiped the system and reinstalled to a prior backup, installed K-Lite without Infatica, and no more AI Protection entries were seen.

infatica.PNG