| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
694 results found for F
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| FRISK FP-Scheduler | U | F-Sched.exe | Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis | No |
| F-Secure Automatic Update | Y | F-Secure Automatic Update.exe | Automatically checks for updates for internet security software from F-Secure Corporation | No |
| F-StopW | Y | F-StopW.exe | F-Prot anti-virus background scanner by F-Risk Software | No |
| f01489ae591474641e456c050c1db1d7 | X | f01489ae591474641e456c050c1db1d7.exe | Detected by Dr.Web as Trojan.DownLoader7.29749 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Symantec Antivirus professional | X | f0dns.exe | Added by the FORBOT-GT WORM! | No |
| F0E84.exe | X | F0E84.exe | TrustDefender, IronDefender and IronProtector rogue security software - not recommended, removal instructions here, here and here | No |
| Start aThx Roll | X | f0mered.exe | Detected by Trend Micro as WORM_RBOT.AAV | No |
| SyZ | X | f1.exe | Added by the MSNDIABLO.A WORM! | No |
| f181b87b5e994ddc44f095ec70fd0f2c | X | f181b87b5e994ddc44f095ec70fd0f2c.exe | Detected by Dr.Web as Trojan.DownLoader7.32065 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| jzv9 | X | f1ku.exe | Detected by Kaspersky as Trojan-Downloader.Win32.Genome.cvhd and by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %Temp% | No |
| Systam13 | X | f1r5st83.exe | Added by the IRCBOT-YM WORM! | No |
| Mozilla Firefox | X | F1REF0X.EXE | Added by the SDBOT-UP BACKDOOR! Note that the filename has the numbers "1" and "0" in place of upper case "i" and "o" respectively | No |
| Compaq Drivers | X | F1rewalls.exe | Added by the SDBOT-WD WORM! | No |
| f1Tray.exe | U | F1TRAY.EXE | System Tray icon for FusionOne's MightyPhone software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer" | No |
| fgl23DoubleScreenHooks | ? | f23happ.exe | Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required? | No |
| f23mxins | ? | f23mxins | Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required? | No |
| F2Day | X | f2dupdater.exe | Detected by McAfee as Generic.dx!xlz | No |
| F2DayUpdate | X | f2dux.exe | Detected by McAfee as Generic.dx!xlz | No |
| f2install.exe | X | f2install.exe | Added by the IEFEAT-I TROJAN! | No |
| f607 | X | f607.exe | Added by the URAT.B TROJAN! | No |
| f7035170f3c0d7c8d377059820b859a0 | X | f7035170f3c0d7c8d377059820b859a0.exe | Detected by Dr.Web as Trojan.DownLoader7.26091 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| f78ab46e149d2ce1a6b721640ed25616 | X | f78ab46e149d2ce1a6b721640ed25616.exe | Detected by McAfee as RDN/Generic.dx!bcj and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| f99a910d3f4e230e93f6f52797fa3578 | X | f99a910d3f4e230e93f6f52797fa3578.exe | Detected by Dr.Web as Trojan.DownLoader8.37173 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| fa3c99036e85131dab81f132665aa15a | X | fa3c99036e85131dab81f132665aa15a.exe | Detected by Dr.Web as Trojan.DownLoader7.23039 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Fabrik Ultimate Backup Status | U | fabrikhomestat.exe | Status monitor for Fabrik Ultimate Backup from Fabrik Inc. "No matter what happens to the drive on your desk - a spilled drink, a curious toddler, a theft or a natural disaster - you know your files are still safe and secure on Fabrik Ultimate Backup's off-site servers" | No |
| Facbook | X | Facbook.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| FacbookUpdatdefender | X | FacbookUpdatdefender.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| FacbookUpdate | X | FacbookUpdate.exe | Detected by Dr.Web as Trojan.MulDrop4.1885 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| FacebookUpdate | X | faceb00kupdate.exe | Detected by Dr.Web as Trojan.Siggen4.24716 | No |
| runner1 | X | faceback.exe | Added by the DLOADR-BSX TROJAN! | No |
| Facebook güncellemee | X | Facebook inc.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\Facebook güncellemee | No |
| 082094b0627eab42aff3a5cb0627aaeb | X | Facebook.exe | Detected by McAfee as RDN/Generic.tfr!t and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| 8d0fa66a7f70d4b92f3da7199f7f9e8d | X | facebook.exe | Detected by Dr.Web as Trojan.DownLoader6.48102 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| 1987a5fe40ab41c51efd8ef7582fb9a5 | X | FacebookHack.exe | Detected by Dr.Web as Trojan.DownLoader8.24622 and by Malwarebytes Anti-Malware as Trojan.Clicker | No |
| Facebook Messenger | N | FacebookMessenger.exe | Facebook Messenger chat client for Windows | No |
| facebookmsg | X | facebookmsg.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%\system32 | No |
| FacebookSystems | X | FacebookSystems.vbs | Added by the AGENT-QLE TROJAN! | No |
| [random].exe | X | FacebookUpdate.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note - do not confuse with the legitimate update manager for software installed by the Facebook social networking site which is located in %LocalAppData%\Facebook\Update. This version is located in %AppData%\System | No |
| Facebook Update | N | FacebookUpdate.exe | Update manager for software installed by the Facebook social networking site - such as Video Calling. The file is located in %LocalAppData%\Facebook\Update | No |
| FacebookUpdate | X | FacebookUpdate.exe | Detected by Dr.Web as Trojan.MulDrop3.29468 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - do not confuse with the legitimate update manager for software installed by the Facebook social networking site which is located in %LocalAppData%\Facebook\Update. This version is located in %AppData% | No |
| FacebookUpdate | X | FacebookUpdate.exe | Detected by McAfee as RDN/Generic.dx!st and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - do not confuse with the legitimate update manager for software installed by the Facebook social networking site which is located in %LocalAppData%\Facebook\Update. This version is located in %AppData% | No |
| Facebookvideochat | X | facebookupdate.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT. Note - do not confuse with the legitimate update manager for software installed by the Facebook social networking site which is located in %LocalAppData%\Facebook\Update. This version is located in %LocalAppData%\Google | No |
| Facebookvideochat | X | FacebookVideoCall.exe | Detected by Sophos as Troj/Inject-ACI and by Malwarebytes Anti-Malware as Trojan.Agent.FB | No |
| KuzeKey | X | FacebookVideoCall.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located on %AppData% | No |
| notepad | X | FacebookVideoCall.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData% | No |
| svchost | X | FacebookVideoCall.exe | Detected by Dr.Web as Trojan.DownLoader6.32956 and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| SYSTEMENGINE | X | Facebook_dev.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
| (Default) | X | Facehack.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %ProgramFiles%\Facehack | No |
| facemoods | U | facemoodssrv.exe | Supports the free Facemoods add-on for Facebook Chat that "gives you a huge collection of smileys, winks, text effects and more!" and once loaded it exits. Note - if you install using the default options it will make facemoods.com the default home page, search provider and "new tab" page for your browser | Yes |
| facemoodssrv | U | facemoodssrv.exe | Supports the free Facemoods add-on for Facebook Chat that "gives you a huge collection of smileys, winks, text effects and more!" and once loaded it exits. Note - if you install using the default options it will make facemoods.com the default home page, search provider and "new tab" page for your browser | Yes |
| HKCU | X | FaceUp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\passUp | No |
| HKLM | X | FaceUp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\passUp | No |
| Policies | X | FaceUp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\passUp | No |
| (Default) | X | fada.exe | Added by the VB.HEI TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run, HKLM\RunServices and HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| Microsoft Driver | X | faet.exe | Added by a variant of Win32/Rbot | No |
| boowudo | X | fafegoubu.exe | Added by the LINEAG-FX TROJAN! | No |
| FS Agent | X | fagent.exe | Added by the VOLVER-B TROJAN! | No |
| fagyqcoqleme | X | fagyqcoqleme.exe | Detected by McAfee as RDN/Downloader.a!fd and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| FairPointServicepoint.exe | Y | FairPointServicepoint.exe | FairPoint Servicepoint Agent tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| faiwek | X | faiwek.exe | Added by the VBKRYPT.ABFH TROJAN! | No |
| fajenignyrra | X | fajenignyrra.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| fakelookfakelook.exe | X | fakelook.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserProfile%\[numbers] | No |
| fakocan | X | fakocan.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Root% | No |
| Windows Sistem Updater | X | fakocan.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Root% | No |
| Load32 | X | Falckon.exe | Detected by Symantec as W32.HLLW.Vicety and by Malwarebytes Anti-Malware as Worm.Vicety | No |
| windll | X | Falcon.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData% | No |
| blah service | X | FaLeH.exe | Added by the RBOT-AES WORM! | No |
| UCmd | X | fallfour.exe | Added by the SDBOT-AZA WORM! | No |
| Toshiba Fan | Y | fan.exe | Toshiba untilty to keep the fan on a laptop running if they fail to detect there is too much heat | No |
| fapmon | ? | fapmon.exe | Fair Access Policy monitor for DirecPC/DirecWay internet access | No |
| Far2 | X | Far2.exe | Detected by Dr.Web as BackDoor.Armagedon.22 | No |
| farkrish | X | farkrish.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
| farmmext | X | farmmext.exe | VX2.Transponder parasite updater/installer related | No |
| Fash | X | Fash.exe | IBIS Toolbar hijacker | No |
| fast | N | fast.exe | Optional install from an early release of the Windows XP PowerToys to provide an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system) | No |
| FastUser | N | fast.exe | Optional install from an early release of the Windows XP PowerToys to provide an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system) | No |
| FastUsr | N | fast.exe | Optional install from an early release of the Windows XP PowerToys to provide an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system) | No |
| FAST Defrag | N | FAST2.EXE | FastDefrag defragmenting software | No |
| Fast Antivirus 2009 | X | FastAV.exe | Fast Antivirus rogue security software - not recommended, removal instructions here | No |
| Microsoft Office Fast Cache | N | Fastboot.exe | Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled | No |
| FBSearch | X | FastBrowserSearchProtection.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information | No |
| fastcurestart.exe | X | fastcurestart.exe | FastCure rogue security software - not recommended, removal instructions here | No |
| acocash | X | fastdown.exe | Adult content dialler | No |
| acocash | X | FASTFOWN.EXE | Adult content dialler | No |
| FastLinkAgent | X | FastLinkAgent.exe | Detected by McAfee as RDN/Generic.bfr!cc | No |
| fastcs | X | fastns32.exe | Detected by Sophos as Mal/Inject-CY | No |
| FastScanMain | X | FastScan.exe | FastScan rogue security software - not recommended, removal instructions here | No |
| fastsmell | X | fastsmell.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
| FastTVSync | U | FastTVSync.exe | Part of InterVideo (now Corel) DVD Copy - "fast DVD copying and file conversion software. In just three steps, you can copy videos to most DVD formats, or convert them for smooth, flawless viewing on your PSP® or iPod®. With broad format support and unique CopyLater technology, DVD Copy saves you time and ensures high-quality output like no other copying software" | No |
| Buttons & OSDs control application gen2 | U | FastUserSwitching.exe | Allows for fast user switching between user accounts without logging off via a hotkey on some HP/Compaq machines - see here | No |
| Buttons & OSDs control application gen3 | U | FastUserSwitching.exe | Allows for fast user switching between user accounts without logging off via a hotkey on some HP/Compaq machines - see here | No |
| DellOSD | U | FastUserSwitching.exe | Allows for fast user switching between user accounts without logging off via a hotkey on some Dell machines | No |
| Hotkey | U | FastUserSwitching.exe | Allows for fast user switching between user accounts without logging off via a hotkey on some Pegatron machines. Pegatron is an ASUS OEM - see here | No |
| UserSwitch | U | FastUserSwitching.exe | Allows for fast user switching between user accounts without logging off via a hotkey on some Dell machines (and maybe others?) | No |
| fastvaccinestart.exe | X | fastvaccinestart.exe | Detected by McAfee as Generic.tfr | No |
| fastvaccine main | X | fastvaccineu.exe | Detected by McAfee as Generic.tfr | No |
| faT | X | faT.exe | Added by the BANKER-DFP TROJAN! | No |
| fat.exe | X | fat.exe | Part of the WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 rogue security programs - not recommended, removal instructions here and here | No |
| Fat32 Microsoft | X | fat32.exe | Added by the RBOT-EL WORM! | No |
| FATrayAlert | Y | FATrayMon.exe | Part of the FastAccess facial recognition utility by Sensible Vision | No |
| fatrecov | U | fatrecov.exe | SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| dago | X | fault.exe | Detected by Sophos as W32/Punya-A | No |
| favoclip | X | favoclips.exe | Detected by McAfee as Generic Downloader.x!fyo and by Malwarebytes Anti-Malware as Adware.Agent | No |
| FavoriteSync | U | FavoriteSync.exe | FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync | No |
| Windows Guardian | U | Fawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes | No |
| 11 | X | faxcomdos.exe | Added by the DLOADER-KF TROJAN! | No |
| RightFAX Print-to-Fax Driver | U | FaxCtrl.exe | Part of RightFAX from Captaris - "the proven market leader in fax server and document delivery software" | No |
| WinFax PRO | N | FAXMNG32.EXE | WinFax PRO from Symantec - fax management software | No |
| L0aders | X | faxneti.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| CstlFaxTray | U | FaxTray.Exe | System Tray access to OpenText Fax Appliance, FaxPress (formerly Castelle FaxPress) - which "offers a combined hardware and software faxing solution, providing every possible computer-based, network fax option" | No |
| Gestionnaire de lancement d'application fax | U | faxtray.exe | System Tray access to Internet Fax software by Alliance MCA | No |
| Lancement Application Fax | U | faxtray.exe | System Tray access to Fax-Internet (by Axmapresse) and SafeFax (by Alliance MCA) internet fax software | No |
| systray for fax applications | U | faxtray.exe | System Tray access to Fax-Internet software by AXMA | No |
| FBDirect | U | FBDirect.exe | Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop! | No |
| PP****usb | N | FBDirect.exe | Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start → Programs | No |
| SpeedDownload | X | FBDManager.exe | Detected by McAfee as Generic PUP.x and by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %AppData%\SpeedDownload | No |
| FBI | ? | FBISM.exe | Compaq related but what does it do? | No |
| Mount Safe & Sound | U | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start | No |
| dvsfss | X | fbsfsdrs.exe | Added by the SDBOT-QA WORM! | No |
| FacebookUpdate | X | fbupdate.exe | Detected by Sophos as Troj/Sisron-G and by Malwarebytes Anti-Malware as Trojan.QHosts | No |
| InstallMon | X | fbx.exe | Added by the MDROP-CZK TROJAN! | No |
| BlazeChanger | N | FBZPaper.exe | Ember graphic file viewer, manager, and touch-up system | No |
| System33 | X | FB_PNU.EXE | Added by the NICHELLO-A WORM! | No |
| FastCache | U | fc.exe | FastCache from AnalogX - speeds up browsing by resolving DNS requests locally | No |
| fcabafaaddeafad | X | fcabafaaddeafad.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\{GUID} | No |
| FCACheck | U | FCACheck.exe | Family Cyber Alert surveillance software. Uninstall this software unless you put it there yourself | No |
| FCEngine | X | FCEngine.exe | CASClient adware | No |
| FCHelp | X | FCHelp.exe | Added by either FCHelp adware or a variant of it | No |
| NTSF MICROSOFT SYSTEM | X | fck.exe.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| FCleaner | U | FCleaner.exe | FCleaner by FTweak Inc - "is a freeware all-in-one Windows disk and registry cleaning and optimization tool. It removes unused files and invalid registry entries that are eating up your disk space and slowing your system down, tweaks your system and allows your Windows to run faster." Features include removing unused files, cleaning internet history, managing startup programs and a fully featured registry cleaner | Yes |
| FTweakFCleaner | U | FCleaner.exe | FCleaner by FTweak Inc - "is a freeware all-in-one Windows disk and registry cleaning and optimization tool. It removes unused files and invalid registry entries that are eating up your disk space and slowing your system down, tweaks your system and allows your Windows to run faster." Features include removing unused files, cleaning internet history, managing startup programs and a fully featured registry cleaner | Yes |
| User Manager | X | fcllls.exe | Added by the ZAGABAN-B TROJAN! | No |
| FCMan | X | FCMan.exe | FCHelp adware | No |
| FD_SAP | U | FD.exe | Reported to be the autopassword program from the Sony Microvault thumb drive | No |
| FreshDownload | N | FD.EXE | Fresh Download from Freshdevices.com - "is a download manager for Internet Explorer that helps you downloading files from the Internet, such as your favorite freeware/shareware, mp3 files, movie files, picture collections, etc" | Yes |
| Diomacd | X | fdafbfd.exe | Added by the MULDROP.F TROJAN! | No |
| Free Downloads Monitor | ? | fdcmon.exe | ?? | No |
| FDD SYSTEM | X | Fdd.exe | Added by the MYTOB-FO WORM! | No |
| Tji771 | X | fddg.exe | Added by the PALEVO.AVJI WORM! | No |
| msjdqs | X | fddwqt.exe | Added by the SDBOT-PO WORM! | No |
| wzxzxds | X | fdfddad.exe | Added by the RANKY.AB TROJAN! | No |
| Free Download Manager | N | fdm.exe | Free Download Manager - "a powerful, easy-to-use and absolutely free download accelerator and manager" | No |
| Windows Update | X | fdos.exe | Detected by Sophos as W32/Rbot-COG and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| FdDir | X | FdPrg.exe | Detected by Dr.Web as Trojan.DownLoader6.59063 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %CommonAppData%\FdDir | No |
| FdDir | X | FdPrg.exe | Detected by Dr.Web as Trojan.Siggen4.35733 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\FdDir | No |
| WMGIL | X | fdRUP.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| msgsmrsgs | X | fdxit.exe | Added by the SDBOT-QY WORM! | No |
| ODBC BackUp | U | fdxxl.exe | G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! | No |
| SysPilot | U | fdxxl.exe | G Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here. Disable/remove if you didn't install it yourself! | No |
| fe32e6b321a15a20570ae15a1efc1f36 | X | fe32e6b321a15a20570ae15a1efc1f36.exe | Detected by Dr.Web as Trojan.DownLoader7.21667 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| MSys32 | U | fe33c1ae.exe | Webentrance adware | No |
| FeCPY | X | fecpy.exe | FlashEnhancer adware | No |
| Monitor SynManager | X | fecwvncd.exe | Added by the SDBOT-IW WORM! | No |
| WAB | X | feda200219.exe | Detected by Dr.Web as Trojan.Siggen5.10954 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| FlySky | X | feeba1.exe | Detected by Microsoft as TrojanDownloader:Win32/Dofoil.R | No |
| Agnitum Outpost | Y | feedback.exe | Part of the error reporting mechanism for the Outpost range of security products from Agnitum Ltd - including Outpost Firewall Pro, Outpost Antivirus Pro and Outpost Security Suite Pro. Dumps the system information to a log at startup in case it's needed and exits. Located in an "Agnitum" sub-directory of %ProgramFiles% | Yes |
| feedback | Y | feedback.exe | Part of the error reporting mechanism for the Outpost range of security products from Agnitum Ltd - including Outpost Firewall Pro, Outpost Antivirus Pro and Outpost Security Suite Pro. Dumps the system information to a log at startup in case it's needed and exits. Also used by Lavasoft Personal Firewall and located in either "Agnitum" or "Lavasoft" sub-directories of %ProgramFiles% | No |
| Lavasoft Personal Firewall | Y | feedback.exe | Part of the error reporting mechanism for Lavasoft Personal Firewall. Dumps the system information to a log at startup in case it's needed and exits. Located in %ProgramFiles%\Lavasoft\Personal Firewall. Based upon the Outpost Firewall by Agnitum Ltd | Yes |
| lavasoftFeedBack | Y | feedback.exe | Part of the error reporting mechanism for Lavasoft Personal Firewall. Dumps the system information to a log at startup in case it's needed and exits. Located in %ProgramFiles%\Lavasoft\Personal Firewall. Based upon the Outpost Firewall by Agnitum Ltd | Yes |
| OutpostFeedBack | Y | feedback.exe | Part of the error reporting mechanism for the Outpost range of security products from Agnitum Ltd - including Outpost Firewall Pro, Outpost Antivirus Pro and Outpost Security Suite Pro. Dumps the system information to a log at startup in case it's needed and exits. Located in an "Agnitum" sub-directory of %ProgramFiles% | Yes |
| feedreader.exe | U | feedreader.exe | "Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML" | No |
| FEELitDeviceManager | U | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals) | No |
| FELUMMAWAKSU | X | felummawaksu.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% | No |
| femokybhawam | X | femokybhawam.exe | Detected by Trend Micro as TROJ_DLOAD.BTN | No |
| Microsoftf DDEs Control | X | FEnR.exe | Added by the RBOT-AIM WORM! | No |
| Fen Startups | X | fensvc32.exe | Added by the RANDEX.CCF WORM! | No |
| FerrariWallPaper | U | FerrariWP.exe | Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com | No |
| NowwwfaaaName-Crypt | X | Feuerzewfaawug.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %Temp% | No |
| NowwwName-Crypt | X | Feuerzewwug.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %Temp% | No |
| fewapinybeax | X | fewapinybeax.exe | Detected by McAfee as PWS-Zbot.gen.amv and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| Savasddwq | X | ffasd.exe | Added by the SDBOT-SI WORM! | No |
| Norton Auto-Protect | X | ffbaqe.exe | Added by the SLINBOT.RF BACKDOOR! Note - this is not a valid Norton product | No |
| ffis | X | ffisearch.exe | Detected by McAfee as Adware-ISearch | No |
| ffprsrv | Y | ffprsrv.exe | File and Folder Privacy - is a "system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program | Yes |
| ffprsrv.exe | Y | ffprsrv.exe | File and Folder Privacy - is a "system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program | Yes |
| ffpsrv | Y | ffpsrv.exe | File & Folder Protector - "great easy-to-use password-protected security utility lets you password-protect certain files and folders, or to hide them securely from viewing and searching just with a click of mouse". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program | Yes |
| ffpsrv.exe | Y | ffpsrv.exe | File & Folder Protector - "great easy-to-use password-protected security utility lets you password-protect certain files and folders, or to hide them securely from viewing and searching just with a click of mouse". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program | Yes |
| dS35DLL | X | ffqca.exe | Added by the SDBOT-KV WORM! | No |
| MS32DLL | X | ffqca.exe | Added by the SDBOT-YD WORM! | No |
| Windows Reg Services | X | ffservice.exe | Added by the DLOADER-PL or DLOADER-XM TROJANS! | No |
| DfqwSfS | X | ffsqsd.exe | Added by the SDBOT-SH WORM! | No |
| fftJvuYYiwI | X | fftJvuYYiwI.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| FreeFallProtection | Y | FF_Protection.exe | Found on some Dell laptops (any maybe others which include an STMicroelectronics accelerometer) - provides protection for supported hard disks when a fall or sudden movement is detected by "parking" the drive reading heads to avoid damage | No |
| MSMSGNER | X | fgozmox.exe | Added by the AGENT-EBJ BACKDOOR! | No |
| FheSrv | X | FheSrv32.exe | Added by the DELF.AFH BACKDOOR! | No |
| Windows MS Update 32 | X | fhm.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Fhtisxk | U | fhtisxk.exe | XtraKeys keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| fiangedrv | X | fiangedr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %System% | No |
| akjhskh8hn | X | Fifa.exe | Detected by Malwarebytes Anti-Malware as Trojan.Delf. The file is located in %AppData% | No |
| Windows Service Pack Auto Update | X | figgaz.exe | Detected by Kaspersky as the AGENT.BT TROJAN! | No |
| 1052b8e9071d5b658c32c84c463014f5 | X | file.exe | Detected by Dr.Web as Trojan.DownLoader8.11031 and by Malwarebytes Anti-Malware as Spyware.Banker | No |
| Adobe Updates | X | file.exe | Detected by McAfee as Generic PWS.y!dr3. Note - this is not a legitimate Adobe entry | No |
| DLL | X | file.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp% | No |
| GoogleUpdate | X | file.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %UserTemp% | No |
| hfghgf | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| hhff | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.ZB. The file is located in %UserTemp% | No |
| hsdfghgsss | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Zbot. The file is located in %UserTemp% | No |
| Java Runtime | X | file.exe | Detected by Dr.Web as Trojan.DownLoader6.51392 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Messenger | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| Microsoft DLL Verifier | X | file.exe | Added by the RBOT-AED WORM! | No |
| MSN | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp% | No |
| NEW | X | file.exe | Detected by Malwarebytes Anti-Malware as Spyware.Zeus. The file is located in %UserTemp% | No |
| Notepad.exe | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %UserTemp% | No |
| rundll32 | X | file.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Temp% | No |
| StartupHelp | X | file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| StartupName | X | File.exe | Detected by Dr.Web as Trojan.DownLoader7.16318 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
| StartupName | X | File.exe | Detected by Dr.Web as Trojan.DownLoader7.16318 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Temp% | No |
| system | X | file.exe | Detected by Dr.Web as Trojan.DownLoader8.32017 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| USB Controller | X | file.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Temp% | No |
| SHOWSTRUCK | X | Fileadhesive.exe | Detected by McAfee as RDN/Generic FakeAlert!bg and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| FDoumiStart | X | filedoumiupgrade.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\filedoumi | No |
| FDoumiup2Start | X | filedoumiuphp.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\filedoumi | No |
| NTFSS Microsoft System | X | filees.exe | Detected by Trend Micro as WORM_RBOT.GAB | No |
| BSserver | X | FileKan.exe | Added by the VB.CBW WORM! | No |
| File Protection Monitor | X | filemon.exe | Added by a variant of Win32/Rbot | No |
| filen | X | filen.exe | Added by the VBNAM-A WORM! | No |
| Service Cleaner | X | filen.exe | Added by the RBOT.BRH WORM! | No |
| Service Monitor | X | filen.exe | Added by a variant of Win32/Rbot | No |
| ADOBEDLL | X | FileName.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Chrome | X | FileName.exe | Detected by Kaspersky as Trojan.Win32.VBKrypt.cghr. Note - this is not a legitimate Google Chrome browser file | No |
| Configuration Loader | X | FILENAME.EXE | Added by the AGOBOT-DQ WORM! | No |
| filename | X | filename.exe | Added by the VB.FSY TROJAN! | No |
| HOT FIX | X | filename.exe | Added by the SDBOT-DKM WORM! | No |
| Key Name | X | FileName.exe | Detected by Dr.Web as Trojan.DownLoader3.22897 and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\Directory | No |
| Key Name | X | FileName.exe | Detected by Dr.Web as Trojan.DownLoader6.9518 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\FolerName | No |
| KeyName | X | Filename.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| Windows Services | X | filename.exe | Detected by Kaspersky as Backdoor.Win32.SdBot.fsk and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| ActiveX File Registration Service | X | filereg.exe | Added by the RBOT-DVD WORM! | No |
| NTFSS MICROSOFT SYSTEM | X | filess.exe | Added by the RBOT.AXZ WORM! | No |
| FileTap_UDControl | X | Filetap_UDControl.exe | Detected by Dr.Web as Trojan.DownLoader6.29826 and by Malwarebytes Anti-Malware as Adware.Korad | No |
| HKCU | X | filewin.exe | Detected by McAfee as Generic.bfr!gw and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| HKLM | X | filewin.exe | Detected by McAfee as Generic.bfr!gw and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| Policies | X | filewin.exe | Detected by McAfee as Generic.bfr!gw and by Malwarebytes Anti-Malware as Backdoor.Agent.Pgen | No |
| SystemTasks | X | filez.exe | Adult content dialler | No |
| FileZilla Server Interface | N | FileZilla Server Interface.exe | Frontend for the free FileZilla FTP server | No |
| FILE_77186 | X | FILE_77186.exe | Added by the AUTWRM-E MALWARE! | No |
| FilmLoop | U | FilmLoopService.exe | Related to FilmLoop - a photocasting network. Share your pictures with your family and friends | No |
| FilterGate | U | filtergate.exe | Filtergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items | No |
| Filterguard | U | Filtrgrd.exe | An icon located in the lower left of the screen and looks like a lifesaver. This icon is a "short-cut" to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by "right-clicking" on the icon | No |
| xVgIL | X | FIMVD.exe | Detected by Malwarebytes Anti-Malware as Trojan.LVBP. The file is located in %AppData% | No |
| Find | X | find.exe | Added by the OPANKI WORM! | No |
| First | X | Finddir.exe | Added by the DELF-EZD TROJAN! | No |
| Find Fast | N | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines | No |
| findfast | X | findfast.exe | Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office | No |
| findfast.exe | X | findfast.exe | Identified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office | No |
| Microsoft Find Fast | N | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines | Yes |
| BrowseProxy | X | FindService.exe | AdvSearch adware | No |
| win32Kernel | X | findx.exe | Added by the BANLOA-EY TROJAN! | No |
| FineTop | X | FineTop.exe | Detected by Microsoft as Adware:Win32/FineTop | No |
| FineTopUDF | X | FineTopUDF.exe | Detected by Microsoft as Adware:Win32/FineTop | No |
| ASDPLUGIN | X | Finland.exe | AsdPlug premium rate adult content dialer | No |
| FIREBOX | U | FIREBOX Control.exe | Control panel for the PreSonus FireBox Firewire based personal recording studio | No |
| FireBox Control Panel | U | FireBox.exe | Control panel for the PreSonus FireBox Firewire based personal recording studio | No |
| Mozila Firefox | X | firebox.exe | Added by the RBOT-AIP WORM! | No |
| FireExplore Update | X | FireExplore.exe | Added by a variant of Win32/Rbot | No |
| firefox udate.exe | X | firefox udate.exe | Detected by McAfee as PWS-Zbot.gen.aru and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| saodsae1 | X | firefox..exe | Detected by McAfee as RDN/Generic BackDoor!k and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| 36d7a02fbca41f608c4baf27f6374668 | X | firefox.exe | Detected by Dr.Web as Trojan.DownLoader7.6718 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %AppData% | No |
| firefox | X | firefox.exe | Detected by Kaspersky as Backdoor.Win32.mIRC-based.p and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %WinTemp%\history | No |
| firefox | X | firefox.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %AppData%\Mozilla | No |
| FireFox | X | firefox.exe | Detected by Sophos as W32/Rbot-ATP and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %System% | No |
| Firefox helper | X | firefox.exe | Detected by Microsoft as Trojan:Win32/Ransom.EJ. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %AppData%\mozilla\firefox | No |
| firefox.exe | X | firefox.exe | Detected by Sophos as Troj/Banker-EBO and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %System% | No |
| Microsoft | X | firefox.exe | Detected by Sophos as W32/Rbot-GVJ and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %System% | No |
| Mozilla Firefox | X | firefox.exe | Detected by Kaspersky as Worm.Win32.AutoRun.pom and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %System% | No |
| Windows Internet Explorer 6 | X | firefox.exe | Detected by Trend Micro as WORM_SPYBOT.ANA and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the Mozilla Firefox web browser which is normally located in %ProgramFiles%\Mozilla Firefox. This one is located in %System% | No |
| Firefox Plugin Manager | X | firefoxpgm.exe | Added by the MSNPHOTO.E WORM! | No |
| Firefox Preloader | U | FirefoxPreloader.exe | Firefox Preloader - "a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time". Even on fast machines Firefox can take a while to load | Yes |
| hadespeter | X | firefx_.exe | Added by the AGENT-QVT TROJAN! | No |
| EleFunAnimatedWallpaper | U | Fireplace.exe | Fireplace animated wallpaper from | No |
| FirePod | Y | FIREPOD.EXE | Driver for the PreSonus FP10 (formerly FirePod) Firewire recording system | No |
| McAfee Desktop Firewall Tray | Y | FireTray.exe | McAfee Desktop Firewall | No |
| McAfeeFireTray | Y | Firetray.exe | McAfee Desktop Firewall | No |
| firewal | X | firewal.exe | Added by the BANCBAN-QY TROJAN! | No |
| Life FireWall Update1 | X | FireWall-Update1.exe | Added by the RBOT-ARS WORM! | No |
| Personal Firewall V9 | X | Firewall-UpdateV9.exe | Added by the RBOT-BJR WORM! | No |
| Firewall | X | Firewall.bat | Added by the YPSAN.G WORM! | No |
| Ashampoo FireWall | Y | FireWall.exe | Ashampoo® Firewall FREE | Yes |
| Ashampoo FireWall PRO | Y | FireWall.exe | Ashampoo® Firewall PRO | Yes |
| dwStart | N | FireWall.exe | The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall | No |
| firewall | X | firewall.exe | Added by the SURO-A TROJAN! | No |
| FireWall.exe | Y | FireWall.exe | Ashampoo® Firewall FREE and PRO. Located in an Ashampoo related sub-directory of %ProgramFiles% | Yes |
| Firewall.exe | X | Firewall.exe | Added by the AGENT.AGL BACKDOOR! Located in %System% | No |
| HKCU | X | firewall.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\system32 | No |
| HKLM | X | firewall.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\system32 | No |
| Microsoft Internet Firewall | X | firewall.exe | Added by the IRCBOT.MD BACKDOOR! Located in %System% | No |
| Microsoft Security Monitor Process | X | firewall.exe | Added by a variant of the IRCBOT BACKDOOR! Located in %System% | No |
| Microsoft Service firewall Manager | X | firewall.exe | Added by a variant of W32/Sdbot.worm. The file is located in %System% | No |
| Policies | X | firewall.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\system32 | No |
| Protection | X | Firewall.exe | Added by the ELIPTER.A or ELIPTER.B WORMS! Located in %ProgramFiles%\Internet Explorer | No |
| Windows Network Firewall | X | firewall.exe | Added by the POEBOT-J WORM! Located in %System% | No |
| WindowsDefender | X | firewall.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %MyDocuments%\Windows | No |
| 00PCTFW | Y | FirewallGUI.exe | System Tray access to PC Tools Firewall Plus from PC Tools - which "is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC" | Yes |
| FirewallGUI | Y | FirewallGUI.exe | System Tray access to PC Tools Firewall Plus from PC Tools - which "is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC" | Yes |
| PC Tools Firewall Plus | Y | FirewallGUI.exe | System Tray access to PC Tools Firewall Plus from PC Tools - which "is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC" | Yes |
| Life Personal Firewall | X | FirewallingV10.exe | Added by the RBOT-BKF WORM! | No |
| Microsoft Firewall | X | firewallsp2.exe | Added by the RBOT-MC WORM! | No |
| FirewallStartup | U | Firewallstartup.exe | Innovative Startup Firewall - "designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean, fast and in it's best shape" | No |
| FirewallSvr | X | FirewallSvr.exe | Added by the NETSKY.X or NETSKY.Y WORMS! | No |
| firewall_anti | X | firewall_anti.exe | Added by the NETDENY-B TROJAN! | No |
| Microsoft Synchronization Manager | X | firewire.exe | Added by the SDBOT-AFC WORM! | No |
| weboqacuc | X | firitirol.exe | Added by the SDBOT-UC WORM! | No |
| Systam13 | X | first.exe | Added by the RBOT.GND BACKDOOR! | No |
| HGTXPEI | N | FirstReboot.exe | Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start → Settings → Control Panel | No |
| OM_Monitor | N | FirstStart.exe | Olympus Master management tool for their range of digital cameras | No |
| OM2_Monitor | N | FirstStart.exe | Olympus Master management tool for their range of digital cameras | No |
| DesktopX Widget | U | Fishy.exe | Fishy widget included with the DesktopX desktop utility from Stardock Corporation. Displays a fish swimming on the desktop. Once started, Fishy.exe loads a file called "DXWidget.exe" and exits | Yes |
| Fishy | U | Fishy.exe | Fishy widget included with the DesktopX desktop utility from Stardock Corporation. Displays a fish swimming on the desktop. Once started, Fishy.exe loads a file called "DXWidget.exe" and exits | Yes |
| nnmb4w | X | fisnmn.exe | Added by the VB-FDF TROJAN! | No |
| Fix Tool | X | Fix-Tool.exe | Fix Tool rogue system error and cleaning utility - not recommended | No |
| SyncMon | X | fixcomdos.exe | Added by the CLUNKY-B TROJAN! | No |
| MSN | X | Fixdriver.exe | Added by the SILLYFDC.BBY WORM! | No |
| ARCHIVE CONTROL | X | fixupdattr.exe | Added by the MYTOB.GU WORM! | No |
| Windows has Layer | X | fixweb.exe | Added by the SPYBOT.AWS WORM! | No |
| fiztumgofuzb | X | fiztumgofuzb.exe | Detected by McAfee as RDN/Downloader.a!bb and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| FJUPDNV_Chitose | N | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop | No |
| FjMenu | U | FjMenu.exe | From the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable | No |
| Fujitsu Menu | U | FjMnuIco.exe | From the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable | No |
| fjqim4 | X | fjqim4.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bifrose. The file is located in %ProgramFiles%\BackgroundCMD | No |
| FJTWAIN Setup | U | FjtwSetup.exe | Fujitsu scanner utility | No |
| fkSysMon | N | fksysmon.exe | fkWrae SysMon - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more" | No |
| FlaCPY | X | flacpy.exe | FlashEnhancer adware | No |
| ad4d45303f2237f7bec35a28f3352dd7 | X | flash player.exe | Detected by McAfee as RDN/Generic.tfr!a and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Macromedia 8 | X | Flash Player.exe | Added by the JAMBU-A WORM! | No |
| Flash Updater | X | Flash Updater.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Flash | X | Flash.exe | Added by the BANKER.ETK TROJAN! | No |
| flash.exe | X | flash.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Temp%\.. | No |
| Microsoft Security Monitor Process | X | flash.exe | Added by the EGGDROP.EE BACKDOOR! | No |
| microsoftflash | X | flash.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.FLA. The file is located in %System% - see here | No |
| RegistryKey | X | flash.exe | Added by the LOGONINVADER.A TROJAN! | No |
| Flash32 | X | FLASH32.COM | Added by the STARTER-F TROJAN! | No |
| FlashEnc | U | FlashEnc.exe | Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission, which is a pain. No need for it if you do not want these features | No |
| .Flash | X | Flasher.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\.Flash | No |
| Flashget | N | FlashGet.exe | FlashGet download manager. Located in %ProgramFiles%\FlashGet | No |
| Flashget Download Manager | X | Flashget.exe | Added by the RBOT-AGZ WORM! Located in %System% | No |
| FlashGuard | X | FlashGuard.exe | Added by the AUTOIT.AL WORM! | No |
| DataCaching | N | FlashKsk.exe | SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon | No |
| FlashMute | U | FlashMute.exe | "FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively, or alternatively all sounds produced by the browser" | No |
| flashplayer | X | flashplayer.exe | Detected by McAfee as Generic Dropper!fd3 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Java(TM) Updater | X | FlashPlayer.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %Windir%\Documents and Settings | No |
| Shockwave Support | X | FlashPlayer.exe | Added by the DELF-DRA WORM! | No |
| flashplayerapp | X | flashplayerapp.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeAdobe. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| FlashPlayerPlug_31014353 | X | FlashPlayerPlug_31014353.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\FlashPlayerEdition | No |
| Macromedia Flash Player Addon | X | FlashSDK.exe | Detected by ESET as Win32/VB.NYT | No |
| MicrosoftCorp | X | flashsplayer.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| MicrosoftNAPC | X | flashsplayer.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| FlashUpdate | X | FlashUpdate.exe | Detected by Dr.Web as Trojan.Click2.42764 and by Malwarebytes Anti-Malware as Trojan.FakeFlash | No |
| Windows | X | FlashUtil59k.exe | Detected by Malwarebytes Anti-Malware as Backdoor.PWin.Gen. The file is located in %AppData%\Adobe Flash Folder | No |
| me | X | flashutill.exe | Detected by Dr.Web as Trojan.SMSSend.2969 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Flashy Bot | X | Flashy.exe | Added by the GLUPZY.A WORM! | No |
| Adobe Flash Player | X | flash_player.exe | Detected by Dr.Web as Trojan.DownLoader5.3979 and by Malwarebytes Anti-Malware as Trojan.Scar. The file is located in %Root%\5fab54f222460aa69cf4d6b8b96e58fb | No |
| Adobe Flash Player | X | flash_player.exe | Detected by Dr.Web as BackDoor.IRC.Sdbot.17537 and by Malwarebytes Anti-Malware as Trojan.Fakesig. The file is located in %LocalAppData%\Adobe | No |
| PP3100b | N | flatbed.exe | Twain driver for the Visioneer PaperPort 3100b scanner that allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop | No |
| KL AntiFunLove | X | flcss.exe | Added by the FUNLOVE.4099 VIRUS! | No |
| mule_st_key | X | flec006.exe | Added by the BAGLE.AV TROJAN! | No |
| FlenCPY | X | flencpy.exe | FlashEnhancer adware | No |
| Flex2K.exe | U | Flex2K.exe | FlexType 2k from Datecs - a program used to read and write in symbolic writing systems such as Cyrillic, Greek and Russian | Yes |
| FlexType 2K | U | Flex2K.exe | FlexType 2k from Datecs - a program used to read and write in symbolic writing systems such as Cyrillic, Greek and Russian | Yes |
| Flexicd | U | Flexicd.exe | CD player - part of the Win95 Power Toys | No |
| FlingRun | U | fling.exe | Fling - free FTP software from NCH Software | No |
| jvdnlssn | X | fljzsshc.exe | Flingstone.com adware - and its Golden Palace Casino program | No |
| [various names] | X | FLKPT.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| TrendSecure Remote File Lock | Y | FLMain.exe | TrendSecure Remote File Lock 'protects your most valuable computer files from theft and loss by enabling you to "lock" them remotely from another computer' | No |
| FlnCPY | X | flncpy.exe | FlashEnhancer adware | No |
| Flow Go TV | ? | flogotv.exe | ?? | No |
| Microsoft Update Device | X | flolo.exe | Added by a variant of the SPYBOT WORM! See here | No |
| flooder @extreme | X | flooder @extreme.exe | Detected by Malwarebytes Anti-Malware as Backdoor.XTreme. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| FLooDNeT | X | FLooDeR.exe | Added by the ENDOOL TROJAN! | No |
| Microsoft Memory Flow Cycle | X | flowcycle.exe | Added by the IRCBOT.WAD BACKDOOR! | No |
| Microsoft Memory Flow Cycle | X | flowcycles.exe | Added by the WAREZOV.AAK WORM! | No |
| flps | X | flps.vbs | Added by the BYRON WORM! | No |
| Flpycntl | X | flpycntl.exe | Added by the GEMA TROJAN! | No |
| FlashPath Monitor | N | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start → Programs | No |
| FlashPath Status | N | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start → Programs | No |
| FLSVCI | ? | FLSVCI.exe | ?? | No |
| Symantec Antivirus professional | X | flushdns.exe | Added by a variant of the FORBOT WORM! | No |
| F.lux | U | flux.exe | f.lux "makes the color of your computer's display adapt to the time of day, warm at night and like sunlight during the day" | No |
| 1ac3148900aa938c1c20844809bbde8a | X | flv.exe | Detected by Dr.Web as Trojan.DownLoader7.2563 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Ask and Record FLV Service | U | FLVSrvc.exe | Part of Applian Technologies Replay Media Catcher (streaming video and audio/MP3 downloader) and Freecoder (save video and audio from the web and convert to many popular formats - formally known as Ask & Record Toolbar). "Allows the video history tool to save videos you've played from your computer's cache" - see here. As it's based upon the Ask.com tooblar it sets your default search engine to Ask if not unchecked | No |
| Freecorder FLV Service | U | FLVSrvc.exe | Part of Applian Technologies Freecoder (save video and audio from the web and convert to many popular formats - formally known as ak & Record Toolbar). "Allows the video history tool to save videos you've played from your computer's cache" - see here. As it's based upon the Ask.com toolbar it sets your default search engine to Ask if not unchecked | No |
| NotFaut | X | flxper.exe | Added by the SDBOT-AGZ WORM! | No |
| FlyswatDesktop | X | flydesk.exe | Advertising spyware | No |
| Dell 968 AIO Printer | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell 968 AIO printer | No |
| Dell 968 AIO Printer Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell 968 AIO printer | No |
| Dell AIO Printer 948 | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell AIO Printer 948 | No |
| Dell AIO Printer 948 Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell AIO Printer 948 | No |
| Dell V310-V510 Series | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell V310-V510 Series AIO printers | No |
| Dell V310-V510 Series FaxServer | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell V310-V510 Series AIO printers | No |
| Dell V505 | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell V505 AIO printer | No |
| Dell V505 Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell V505 AIO printer | No |
| Dell V715w Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Dell V715W AIO printer | No |
| FaxCenterServer | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others | No |
| FaxCenterServer4_in_1 | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others | No |
| Lexmark 4200 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 4200 Series AIO printer | No |
| Lexmark 5000 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 5000 Series AIO printer | No |
| Lexmark 5300 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 5300 Series AIO printer | No |
| Lexmark 5400 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 5400 Series AIO printer | No |
| Lexmark 5600-6600 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 5600-6600 Series AIO printers | No |
| Lexmark 6500 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 6500 Series AIO printer | No |
| Lexmark 7500 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 7500 Series AIO printer | No |
| Lexmark 7600 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 5400 Series AIO printer | No |
| Lexmark 9300 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 9300 Series AIO printer | No |
| Lexmark 9500 Series | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 9500 Series AIO printer | No |
| Lexmark 9500 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark 9500 Series AIO printer | No |
| Lexmark Pro200-S500 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark Pro200-S500 Series Fax Server AIO printer | No |
| Lexmark Pro700 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark Pro700 Series AIO printer | No |
| Lexmark Pro800-Pro900 Series | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark X5400 Series AIO printer | No |
| Lexmark S300-S400 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark S300-S400 Series AIO printer | No |
| Lexmark S800 Series | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark S800 Series AIO printer | No |
| Lexmark X5400 Series Fax Server | U | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Bundled version for the Lexmark X5400 Series AIO printer | No |
| fmbiost | X | fmbiost.exe | Added by the ONLINEGAMES.AJTI TROJAN! | No |
| FmctrlTray | U | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used) | No |
| run= | N | fmedia.exe | FMedia FaxWorks related - can be run manually | No |
| FreeMem Pro | U | fmempro.exe | FreeMem Professional - "is the world's most popular memory manager and system optimizer on the market with millions of satisfied users" | No |
| Intel Audio Studio V2.0 | X | fmideploy.exe | Added by the DELF.AZY TROJAN! | No |
| fmnwebassist | X | fmnwebassist.exe | Adware popup generator | No |
| fms440 | X | fms440.exe | Detected by McAfee as PWS-Zbot.gen.aru and byMalwarebytes Anti-Malware as Backdoor.Agent | No |
| fmsbbqi | X | fmsbbqi.exe | Added by the ONLINEG.IGG TROJAN! | No |
| fmsiocps | X | fmsiocps.exe | Detected by Trend Micro as TSPY_ONLINEG.CYU | No |
| fmsjhif | X | fmsjhif.exe | Added by the ONLINEG.OZN TROJAN! | No |
| FMStart | U | Fmstart.exe | GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop | No |
| FMSZ | X | fmsz.exe | Added by the FMSZ TROJAN! | No |
| Alcom PCL Capture | ? | FMW_PCAP.EXE | ?? | No |
| fndfst32 | X | fndfst32.exe | Detected by McAfee as Comame and by Malwarebytes Anti-Malware as Trojan.Comame | No |
| Fenio Startups | X | fnesvc32.exe | Added by the AGOBOT-OS BACKDOOR! | No |
| TOSHIBA Accessibility | U | FnKeyHook.exe | "Allows you to use the Fn key to create a hot key combination with one of the function keys without pressing the two keys simultaneously as is usually required. Using Accessibility lets you make the Fn key a sticky key, meaning you can press it once, release it, and then press a function key to activate the hot key function" | No |
| fnmwebassist | X | fnmwebassist.exe | WinPL adware | No |
| run= | X | fntldr.exe | CoolWebSearch Tapicfg parasite variant | No |
| Focus | ? | Focus.exe | ISDN configuration wizard? | No |
| fOEqVGtijLGLKa | X | fOEqVGtijLGLKa.exe | Added by the FAKEAV-DTH TROJAN! | No |
| RealP1ayer | X | folder.bat | Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L" | No |
| RealP1ayer | X | folder.exe | Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L" | No |
| FolderClone v*.*.* | U | folderclone.exe | Folderclone backup and synchronization software | No |
| FolderShare | U | FolderShare.exe | "FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends" | No |
| fspr | Y | FolderShield.exe | Folder Shield - hide personal files and folders | No |
| Folder View | U | folderview.exe | Folder View enhances the Windows file Explorer by making all folders you need available in a single click | No |
| FoneSyncSystemTray | N | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required | No |
| FontFix | X | fontfix.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| fontnav | N | FontNav.exe | Font Navigator from Bitstream Inc. - a font management utility | No |
| sys | X | Fonts.exe | Added by the AUTORUN.BUK WORM! | No |
| AdobeFonts | X | fonts.hta | Browser hijacker - redirecting to Hugesearch.net | No |
| TrueFonts | X | fonts.hta | Browser hijacker - redirecting to Hugesearch.net | No |
| FONTVIEW | X | FONTVIEW.EXE | Added by the OPASERV.T WORM! | No |
| Fontview32. | X | Fontview32..exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Fontview32 | X | Fontview32.exe | Detected by Dr.Web as Trojan.StartPage.49351 and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Font Viewer | X | fontviewer.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| FooBar 1.0 | U | FooBar.exe | FooBar - "combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar" | No |
| foobin lptt01 | X | foobin.exe | RapidBlaster variant (in a "foo1" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| foobin ml097e | X | foobin.exe | RapidBlaster variant (in a "foo1" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| Tiny AV | X | fooding.exe | Added by the NETSKY.I WORM! | No |
| fool | X | fool.exe | Added by the SILLYFDC.BCV WORM! | No |
| Symantec Antivirus professional | X | for.exe | Added by a variant of the FORBOT WORM! | No |
| Forbes | N | ForbesAlerts.exe | Forbes Business News Alerts - displays business news headlines in a little window on the screen | No |
| deejay | X | forboo.exe | Added by the FORBOT-AY WORM! | No |
| ForceField | Y | ForceField.exe | ZoneAlarm ForceField is designed specifically to protect users while they bank, shop or surf dangerous areas of the Internet by creating a virtual "bubble" around their surfing session, protecting their PCs from fraudulent websites, phishing scams, spyware websites and dangerous downloads. Previously available as a stand-alone product, it's now included in all of the ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall | Yes |
| ISW | Y | ForceField.exe | ZoneAlarm ForceField is designed specifically to protect users while they bank, shop or surf dangerous areas of the Internet by creating a virtual "bubble" around their surfing session, protecting their PCs from fraudulent websites, phishing scams, spyware websites and dangerous downloads. Previously available as a stand-alone product, it's now included in all of the ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall | Yes |
| ZoneAlarm Browser Security | Y | ForceField.exe | ZoneAlarm ForceField is designed specifically to protect users while they bank, shop or surf dangerous areas of the Internet by creating a virtual "bubble" around their surfing session, protecting their PCs from fraudulent websites, phishing scams, spyware websites and dangerous downloads. Previously available as a stand-alone product, it's now included in all of the ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall | Yes |
| ZoneAlarm ForceField | Y | ForceField.exe | ZoneAlarm ForceField is designed specifically to protect users while they bank, shop or surf dangerous areas of the Internet by creating a virtual "bubble" around their surfing session, protecting their PCs from fraudulent websites, phishing scams, spyware websites and dangerous downloads. Previously available as a stand-alone product, it's now included in all of the ZoneAlarm security products - including Extreme Security, Internet Security Suite and Firewall | Yes |
| Intel Graphics | X | ForceOPV5.9.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| [various names] | X | forces_elite.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Form1 | X | Form1.exe | Detected by Malwarebytes Anti-Malware as Password.Stealer.LMIR. The file is located in %Windir% | No |
| avnort | X | formatsys.exe | Added by the SERFLOG.A WORM! | No |
| ltwob | X | formatsys.exe | Added by the SERFLOG.A WORM! | No |
| serpe | X | formatsys.exe | Added by the SERFLOG.A WORM! | No |
| FortiClient | Y | FortiClient.exe | Fortinet security systems are the new generation of real time network protection systems | No |
| ViewpointPhotosDeviceConnect | U | FotomatDeviceConnect.exe | Related to Viewpoint which is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 according to this article. You can remove it via Start → Settings → Control Panel → Add/Remove Programs list... | No |
| fotos | X | fotos.exe | Added by the BANKER-FP TROJAN! | No |
| Fotos.exe | X | Fotos.exe | Added by the VB-FNB TROJAN! | No |
| FotoStation Easy AutoLaunch | N | FotoStation Easy AutoLaunch.exe | Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either | No |
| Klass | X | Fouad.exe | Detected by Kaspersky as Trojan.Win32.Scar.cnok and by Malwarebytes Anti-Malware as Trojan.VBAgent | No |
| Foul PX | U | FoulPX.exe | Foul PX, Optusnet usage stat checker | No |
| FourthDay | U | FourthDay.exe | The Fourth Day - "astronomical clock and almanac for your system tray" | No |
| FoWilCo | X | fowilco.exe | Added by the WOOTBOT.CR WORM! | No |
| JQ8F3MYA | X | fox.exe | Detected by McAfee as PWS-Zbot.gen.zy and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| V224618KR60U | X | fox.exe | Detected by McAfee as PWS-Zbot.gen.zy and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| W68D00HY5Q20 | X | fox.exe | Detected by McAfee as PWS-Zbot.gen.zy and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| foxdh | X | foxdh.exe | Added by the GWGHOST-Q TROJAN! | No |
| foxdh | X | foxdhend.exe | Added by the MENGHUAN TROJAN! | No |
| foxrxjh | X | foxrxjh.exe | Added by the GWGHOST-T TROJAN! | No |
| scroller | X | fpapli.exe | CoolWebSearch parasite variant | No |
| FingerPrintSoftware | U | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks | No |
| fpassist | N | fpassist.exe | Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer | Yes |
| FreePDF Assistant | N | fpassist.exe | Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer | Yes |
| FreePDF_Assistant | N | fpassist.exe | Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer | Yes |
| Fatpipe Dialer | U | fpdialer.exe | Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users | No |
| FinePrint Dispatcher v4 | U | fpdisp4.exe | FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output" | No |
| FinePrint Dispatcher v4 | U | fpdisp4a.exe | FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output" | No |
| FinePrint Dispatcher v5 | U | fpdisp5a.exe | FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output" | No |
| First Principle Group | ? | fpg.exe | Related to the E-Players Card from First Principle Group | No |
| Form Pilot Home virtual printer agent | U | fphoagent.exe | Virtual printer for Form Pilot Home from Two Pilots - a lite version "for filling out one-page electronic and paper forms" | No |
| Extension | X | FPlay.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %CommonAppData%\Vextension - see here | No |
| Form Pilot Office virtual printer agent | U | fpoagent.exe | Virtual printer for Form Pilot Office from Two Pilots - form filling utility for filling out paper and electronic forms on your computer instead of using a typewriter. With the Office version "you can create special forms for filling in by your customers and partners" | No |
| Form Pilot Office (demo) printing agent | U | fpoagenttsd.exe | Virtual printer for Form Pilot Office from Two Pilots - form filling utility for filling out paper and electronic forms on your computer instead of using a typewriter. With the Office version "you can create special forms for filling in by your customers and partners." Demo version | No |
| Form Pilot Pro Trial virtual printer agent | U | fppagentd.exe | Virtual printer for Form Pilot Pro from Two Pilots - which "is basic Form Pilot software for filling out paper and electronic forms on your computer instead of using a typewriter." Trial version | No |
| pdfFactory Pro Dispatcher v1 | U | fppdis1.exe | FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory PRO printer. Version 1.x of the software. "pdfFactory products offer a unique approach to PDF creation that is simpler, more effective and less expensive than that offered by other programs" | No |
| pdfFactory Dispatcher v1 | U | fppdis1a.exe | FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 1.x of the software. "pdfFactory products offer a unique approach to PDF creation that is simpler, more effective and less expensive than that offered by other programs" | No |
| pdfFactory Dispatcher v2 | U | fppdis2a.exe | FinePrint pdfFactory Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory printer. Version 2.x of the software. "pdfFactory products offer a unique approach to PDF creation that is simpler, more effective and less expensive than that offered by other programs" | No |
| pdfFactory Pro Dispatcher v3 | U | fppdis3a.exe | FinePrint pdfFactory Pro Dispatcher - background task which handles the creation of PDF files when you print to the FinePrint pdfFactory Pro printer. Version 3.x of the software. "pdfFactory products offer a unique approach to PDF creation that is simpler, more effective and less expensive than that offered by other programs" | No |
| Warning: do not remove it! | U | fpplock.exe | Part of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data" | No |
| Form Pilot Pro virtual printer agent | U | fppragent.exe | Virtual printer for Form Pilot Pro from Two Pilots - which "is basic Form Pilot software for filling out paper and electronic forms on your computer instead of using a typewriter" | No |
| F-PROT Antivirus Tray application | U | FProtTray.exe | System Tray access to F-PROT Antivirus | No |
| Terminate Popup | X | fpuk.exe | Popup killer - foistware proven to install the Regsvc32 homepage hijacker | No |
| FPWGMWZD | ? | FPWGMWZD.exe | ?? | No |
| FoolProof | Y | fpwinldr.exe | "FoolProof Security" PC security software from SmartStuff - no longer available | No |
| Quick Startup | Y | Fquick32.exe | For a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone | No |
| GoOutside | X | fqwfeq.exe | Added by the RBOT.CRD WORM! | No |
| Winloader microsoft | X | fqwsnn.exe | Detected by Dr.Web as Trojan.DownLoader6.57884 | No |
| FrameWork 2.5 | X | FrameWork.exe | Added by the RBOT-FMW WORM! Note - can terminate AV related processes | No |
| MSFramework | X | Framework.exe | Detected by Malwarebytes Anti-Malware as Backdoor.DarkKomet. The file is located in %Temp%\ServiceFramework | No |
| Syswin32 | X | framework.exe | Detected by Dr.Web as Trojan.DownLoader8.15632 and by Malwarebytes Anti-Malware as Trojan.Agent.AI | No |
| EmpoweringTechnology | ? | Framework.Launcher.exe | Part of Acer Empowering Technology. What does it do and is it required? | No |
| ASDPLUGIN | X | france.exe | AsdPlug premium rate adult content dialer | No |
| HELPER | X | france.exe | AsdPlug premium rate adult content dialer variant | No |
| Fraps | N | FRAPS.EXE | Fraps® by Beepa Pty Ltd - is "a universal Windows application that can be used with games using DirectX or OpenGL graphic technology". It can show how many Frames Per Second (FPS) you are getting, allow you to take a screenshot with a single keypress or record a video | Yes |
| APPLEMOBILEDEVICE | X | frddd.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.APMGen. The file is located in %AppData% | No |
| sysfbtray | X | freddy70.exe | Added by the KOOBFACE.BVM WORM! | No |
| SAFE2008 File Redirection Starter | ? | fredirstarter.exe | Older (2008) version of the Steganos Safe encryption utility | No |
| ead7018df7644215400c46501984d528 | X | Free Book Maker.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| FreeAC | U | FreeAlarmClock.exe | Free Alarm Clock by Comfort Software Group - "allows you to set as many alarms as you want. You can set one-time alarms or repeating alarms - activate only from Monday through Friday and give you a chance to sleep on the weekends" | No |
| Freebie Notes | N | FreebieNotes.exe | Freebie Notes by Power Soft - create electronic notes (stickers) | No |
| FreeCall | N | FreeCall.exe | FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| l44sys** | X | freecell | Added by the VBS.LIDO WORM - where ** is a number between 1 and 12 | No |
| Monstersoundtray | N | Freectrl.exe | Diamond Multimedia sound card control panel | No |
| BellSouth Internet Security | Y | Freedom.exe | BellSouth Internet Security - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available | No |
| Freedom | Y | Freedom.exe | Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available | No |
| Internet Security Suite | Y | Freedom.exe | Verizon Internet Security Suite - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available | No |
| Safeworld | Y | Freedom.exe | Safeworld - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available | No |
| TELUS Security service | Y | freedom.exe | TELUS Security service - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available | No |
| Zero Knowledge Freedom | Y | Freedom.exe | Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available | No |
| Free DVD Direct | N | FreeDVDDirect.exe | Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here) | No |
| FreeGo | ? | FreeGo.exe | FreeGo by Julien Palier. Translation: "FreeGo offers Free subscribers the ultimate tool to better manage their account" | No |
| FreeGo | ? | FreeGo3.exe | FreeGo by Julien Palier. Translation: "FreeGo offers Free subscribers the ultimate tool to better manage their account" | No |
| Free Hide IP | U | FreeHideIP.exe | Free Hide IP - "hide your real IP address for free, anonymize your web surfing, keep your computer safe from hacker attacks and other risks, all with a single click" | No |
| Free Key Logger | U | freekeylogger.exe | Free Key Logger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| FreeListen | N | FreeListenUpdate.exe | Updates for the Korean "Free Listen" music player. Detected by Malwarebytes Anti-Malware as PUP.KorAd - remove it unless you installed it yourself | No |
| Memory Service | X | freememory.exe | Added by the RBOT.GEN WORM! | No |
| freemi | X | freemiUp.exe | Detected by Malwarebytes Anti-Malware as Adware.Nieguide. The file is located in %ProgramFiles%\freemi | No |
| FreeRAM XP | U | FreeRAM XP Pro *.exe | FreeRAM XP Pro - memory optimizer where * represents the version | No |
| FreeRAM XP | U | FreeRAM XP Pro.exe | FreeRAM XP Pro - memory optimizer | No |
| BySoft FreeRAM | U | FreeRAM.exe | "Bysoft FreeRAM is a program that frees up ram manually or automatically. It shows current memory status, memory load and CPU usage graphically" | No |
| MicroSoft OneCare | X | FreeS3x.exe | Added by the SDBOT-DJT WORM! | No |
| Spyware Begone | U | freescan.exe | Spyware BeGone - spyware remover. Previously not recommended, see here | No |
| Spyware Vanisher | U | FreeScanner.exe | Spyware Vanisher - spyware remover. Previously not recommended, see here | No |
| Winsystem | X | Freevideo5.EXE | Added by the AGENT.FZS WORM! | No |
| freizer | X | freizer.exe | Detected by McAfee as RDN/Generic.bfr!cc and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Test321 | X | fresdg.exe | Added by the HAMWEQ.DD WORM! See here | No |
| freshclam | N | freshclam.exe | Auto update agent of the open source Clamwin virus scanner | No |
| Fresh Desktop | U | freshdesktop.exe | Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals | No |
| freshUI | U | freshui.exe | Part of Fresh UI from Freshdevices.com - "a fresh solution for configuring and optimizing Windows." This entry is added if you select any of the "on logon" options under "Covering Your Track" for "Clear Explorer History" and "Clear Internet Explorer History" and will have one or more numbers between 0 and 17 appended to the filename depending upon the option(s) selected. Once run it will exit | Yes |
| FUIClearHis | U | freshui.exe | Part of Fresh UI from Freshdevices.com - "a fresh solution for configuring and optimizing Windows." This entry is added if you select any of the "on logon" options under "Covering Your Track" for "Clear Explorer History" and "Clear Internet Explorer History" and will have one or more numbers between 0 and 17 appended to the filename depending upon the option(s) selected. Once run it will exit | Yes |
| FridaysInHellInstaller | ? | FridaysInHellInstaller.exe | ?? | No |
| What Frenz | X | FriendEQUALsuX.exe | Added by the BHARAT.A WORM! | No |
| Raymond present | X | friska_w32.exe | Added by the RUBBLE-C WORM! | No |
| Windows Framework | X | frmwrk.exe | Added by the DWNLDR-GWV TROJAN! | No |
| Framework Windows | X | frmwrk32.exe | Added by the FAKEAV-KS TROJAN! | No |
| Windows Frame Works | X | frmwrks32.exe | Added by the AGOBOT.ACM WORM! | No |
| FG1_00 | U | frntgate.exe | FrontGate MX - e-mail spam blocker | No |
| Free Ram Optimizer | U | fro.exe | Ram Optimizer "monitors your memory and frees up memory if it falls below a certain minimum level" | No |
| HP_runner | X | front.exe | Added by the SILLYFDC WORM! | No |
| FrostWire On Startup | N | FrostWire.exe | FrostWire peer-to-peer (P2P) file-sharing client. As all peer-to-peer file-sharing clients are used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads. Note that by default FrostWire installs the Ask.com toolbar which can be avoided (see here) | No |
| Frsk | X | frsk.exe | Unidentified adware downloader trojan | No |
| FRW_EXE | Y | FRW.EXE | ConSeal Signal9 firewall - now McAfee Personal firewall | No |
| frxmxins | Y | frxmxins.exe | ATI 3D Studio MAX/VIZ driver | No |
| DepFrez | U | frzstate.exe | Deep Freeze from Faronics Coporation. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example | No |
| freesurfer | U | fs20.exe | EMS Free Surfer - pop-up stopper | No |
| FS6519 | X | FS6519.dll.vbs | Added by the SOLOW.B WORM! | No |
| fsaa | Y | fsaa.exe | F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers | No |
| gadkgak12 | X | fsafsakx12.exe | Added by the ONLINEG-N TROJAN! | No |
| akgkagaksad9 | X | fsakfask9.exe | Added by the ONLINEG-M TROJAN! | No |
| FSCBoss | N | FSCBoss.exe | Free Store Club shop online software | No |
| FSDPSRV | ? | FSDPSRV.exe | ?? | No |
| dasxdads | X | fsdqd.exe | Added by the GAOBOT.BIQ WORM! | No |
| Fdaemon security | X | fsecur.exe | Added by the SDBOT.KXO WORM! | No |
| fsserv | U | fserv.exe | Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time | No |
| DirectX for Microsoft Windows | X | Fservice.exe | Added by the PRORAT TROJAN! | No |
| DirectX For Microsoft® Windows | X | fservice.exe | Detected by Sophos as Troj/Prorat-L and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| DirectX For Microsoft® Windows | X | fservice.exe | Added by the PRORAT-P TROJAN! | No |
| Windows Reg Services | X | fservice.exe | Added by the PRORAT-D TROJAN! | No |
| afskfask8 | X | fsfjasj8.exe | Added by the ONLINEG-L TROJAN! | No |
| F-Secure Manager | Y | FSM32.EXE | F-Secure antivirus - carry out scheduled virus scans automatically | No |
| F-Secure Management Agent | U | FSMA32.EXE | F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products | No |
| fsp | U | fsp.exe | Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents | No |
| Charter High-Speed Security Suite | Y | fspex.exe | Charter High-Speed Security Suite - security software in collaboration with F-Secure | No |
| F-Secure 2006 | Y | fspex.exe | F-Secure Anti-Virus automatic updater | No |
| fspuip | U | fspuip.exe | Supports the Sentelic Finger Sensing Pad (FSP) pointing device used in notebook touchpads, for example | No |
| serjfsd | X | fsrjsdks.exe | Added by the VBCHEMAN-A MALWARE! | No |
| wificompressor | X | fsrun.exe | Added by the BANKER-FHY TROJAN! | No |
| Windows Live | X | fsrun.exe | Detected by Sophos as W32/Stratork-A | No |
| FSScrCtl | N | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit", SolidWorks and Hubble Space Telescope screen savers (and possibly others). Lets you control your installed screensavers from a System Tray icon | No |
| Screen Saver Control | N | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit", SolidWorks and Hubble Space Telescope screen savers (and possibly others). Lets you control your installed screensavers from a System Tray icon | No |
| Family Safety | X | fsssvc.exe | Detected by McAfee as Ransom and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitmate Windows Live Family Safety Service (fsssvc.exe) which runs a service and is located in %ProgramFiles%\Windows Live\Family Safety. This one is located in %LocalAppData%\Google | No |
| fssui | U | fssui.exe | System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches, monitoring and blocking/allowing websites and deciding who your kids can communicate with in Messenger or Hotmail. Note - disabling this entry does not disable Family Safety and prevent it monitoring a users activity or restricting access | Yes |
| Windows Live OneCare Family Safety | U | fssui.exe | System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches, monitoring and blocking/allowing websites and deciding who your kids can communicate with in Messenger or Hotmail. Note - disabling this entry does not disable Family Safety and prevent it monitoring a users activity or restricting access | Yes |
| F-Secure Startup Wizard | Y | FSSW.EXE | F-Secure antivirus | No |
| fssui | U | fsui.exe | System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. "With Family Safety, you decide how your kids experience the Internet. Limit searches, monitor and block or allow websites, and decide who your kids can communicate with in Windows Live Spaces, Messenger, or Hotmail". Note - disabling this entry does not disable Family Safety and prevent it monitoring a user's activity or restricting access | Yes |
| fsui | U | fsui.exe | System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. "With Family Safety, you decide how your kids experience the Internet. Limit searches, monitor and block or allow websites, and decide who your kids can communicate with in Windows Live Spaces, Messenger, or Hotmail". Note - disabling this entry does not disable Family Safety and prevent it monitoring a user's activity or restricting access | Yes |
| Windows Live Family Safety Filter | U | fsui.exe | System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. "With Family Safety, you decide how your kids experience the Internet. Limit searches, monitor and block or allow websites, and decide who your kids can communicate with in Windows Live Spaces, Messenger, or Hotmail". Note - disabling this entry does not disable Family Safety and prevent it monitoring a user's activity or restricting access | Yes |
| FSW | X | FSW.exe | FreeScratchAndWin parasite | No |
| SysDesktop | X | fswanQQ.exe | Added by the QQSEND-A TROJAN! | No |
| FSWebServer | U | fsws.exe | Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services | No |
| [various names] | X | ftbar.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Family Tree Builder Update | N | FTBCheckUpdates.exe | Automatic updates for the Family Tree Builder genealogy application from MyHeritage | No |
| GilatFTC | Y | ftc.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system | No |
| FaxTalk CallControl 6.0 | N | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually | No |
| CallControl | N | ftctrl32.exe | FaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows | No |
| anycom bluetooth | ? | ftflauncher.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? | No |
| f | X | ftkclean.exe | FlashEnhancer adware | No |
| ftk | X | ftkclean.exe | FlashEnhancer adware | No |
| FtkCPY | X | ftkcpy.exe | FlashEnhancer adware | No |
| FtLnSOP_setup | U | FtLnSOP.exe | Fujitsu scanner utility | No |
| FTMSFLT(USB) | U | FTMSFLTU.EXE | Fujitsu's Touch Panel Message Notifier | No |
| NetOnHold | U | FTNOHMgr.EXE | "FaxTalk NetOnHold 1.5 works with the Modem-On-Hold capabilities found in V.92 modems to provide the ability to place an Internet connection "on hold" and receive incoming calls or place outgoing calls" | No |
| MSFWAVTSM | X | FTPDev.exe | Added by the RBOT-ACF WORM! | No |
| FTPManager | N | FTPDM.exe | "Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another, remote computer system connected via a modem and telephone lines or by a local-area network (with upload transfer resume and download transfer resume)". Can be started manually | No |
| ATI Video Driver Control | X | ftpex.exe | Added by the BZUB.FAS TROJAN! | No |
| FTPGraber | X | FTPGraber.exe | Added by the DLOADER-DT TROJAN! | No |
| Kernel Faults | X | ftphost.exe | Detected by Trend Micro as WORM_RBOT.BHU | No |
| irwftp | X | ftpmon.exe | Added by the BANCBAN-BO TROJAN! | No |
| ftpqueue | U | ftpqueue.exe | System Tray access for managing FTP transfers via an older version of WS_FTP Pro from Ipswitch | No |
| Ftpqueue | U | Ftpsched.exe | Scheduling service for FTP transfers via an older version of WS_FTP Pro from Ipswitch. Runs as a service in Vista/XP/2K and loads via the "RunServices" registry key in WinMe/98 | No |
| FtpServer.exe | ? | FtpServer.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". What does it do and is it required? | No |
| FTP FOR WINDOWS | X | ftpwin32.exe | Added by a variant of Win32/Rbot | No |
| BMail Installation | N | FTP_back.exe | Part of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not | No |
| %FP%012-L2TP fts.exe | N | fts.exe | 012.Net.il Israeli ISP software front-end | No |
| %FP%1776 Internet fts.exe | N | fts.exe | 1776 Internet US ISP software ISP software front-end | No |
| %FP%AIRTEL fts.exe | N | fts.exe | Bharti Airtel Broadband - Indian ISP software front-end | No |
| %FP%Barak013 fts.exe | N | fts.exe | Barak013 Israeli ISP software front-end | No |
| %FP%Friendly fts.exe | N | fts.exe | Friendly ISP software front-end | No |
| FlexType 2K | U | FType2K.exe | FlexType 2k from Datecs - a program used to read and write in symbolic writing systems such as Cyrillic, Greek and Russian | No |
| WINDOWS FUCK BY CLASIC | X | fuck.exe | Added by the ZOTOB.H or ZOTOB.J WORMS! | No |
| fuck | X | Fuck.scr | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\fuck | No |
| super | X | fuckbx.exe | Added by the LINEAGE-H TROJAN! | No |
| FuckD3w4 | X | FuckD3w4.exe | Added by the BRONTOK-DI WORM! | No |
| system32x | X | fuckeando.exe | Detected by Symantec as W32.HLLW.Vicety and by Malwarebytes Anti-Malware as Worm.Vicety | No |
| Fucker | X | fucker.vbs | Added by the CATCHER-A WORM! | No |
| .NET. | X | FUD.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.DF. The file is located in %System% | No |
| Microsoft Windows XP (Versão 5.1) | X | fudencio.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\linziop | No |
| halit | X | fuduj.exe | Added by the SDBOT.ATR WORM! | No |
| FUFAXRCV | U | FUFAXRCV.exe | Epson fax utility for some of their AIO printers | No |
| FUFAXSTM | N | FUFAXSTM.exe | Epson fax utility for some of their AIO printers | No |
| NTSF MICROSOFT SYSTEM | X | fufffy.exe | Detected by Sophos as W32/Rbot-AEL and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| TPM Cryptographic Thread Update | X | fuikthalaccp\qpgjiqi.exe | Detected by McAfee as RDN/Generic.grp!bg and by Malwarebytes Anti-Malware as Trojan.Agent.FFN | No |
| fukerservice | X | fukerz.exe | Added by the SPYBOT.GD WORM! | No |
| reg_key | X | FUKULAMER.exe | Added by the BEAGLE.AH WORM! | No |
| ASDPLUGIN | X | fullgames.exe | AsdPlug premium rate adult content dialer | No |
| JavaSunKit | X | fullkit.exe | Detected by Dr.Web as Trojan.Proxy.24016 and by Malwarebytes Anti-Malware as Trojan.Agent.JV | No |
| x64pro | X | fullsx.exe | Added by the SMARPIYASA.B TROJAN! | No |
| Microsoft DLL | X | fumeta.exe | Added by the RBOT-AUG WORM! | No |
| Fun | X | Fun.exe | Detected by Sophos as W32/VB-DZE | No |
| FunyMall | X | FunyMallUpdate.exe | FunyMall adware | No |
| ID-CHANGER | X | Furv.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.DI. The file is located in %ProgramFiles%\Kpte | No |
| startkey | X | furzi.exe | Added by the BIFROSE-OK TROJAN! | No |
| FusionHdtvTray | N | FusionHdtvTray.exe | FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software | No |
| FusionTrayAgent | N | FusionHdtvTray.exe | FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software | No |
| FusionRC | U | FusionRC.exe | Remote control manager for DVICO FusionHDTV | No |
| FusionRemote | U | FusionRc.exe | Remote control manager for DVICO FusionHDTV | No |
| Userinterface Reporter | X | fuuuucktttttt.exe | Added by the MYTOB-DK WORM! | No |
| FU | X | FUvirus.exe | Added by the VB-EJC TROJAN! | No |
| (Default) | X | fvdfb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %LocalAppData% | No |
| fvek | X | fvek.exe | Added by the DRIVOL-A TROJAN! | No |
| FveNotify | Y | fveNotify.exe | Windows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista, "BitLocker prevents a thief who boots another operating system or runs a software hacking tool from breaking Windows Vista file and system protections or performing offline viewing of the files stored on the protected drive" - see here | No |
| Find Virus Launch Program | Y | fvlaunch.exe | Part of Dr. Solomon's Antivirus | No |
| Norton Antivirus AV | X | FVProtect.exe | Detected by Symantec as W32.Netsky.P@mm. Note - this is not the popular Norton anti-virus software | No |
| Microsoft Driver Setup | X | fvrgmt.exe | Detected by McAfee as PWS-Spyeye.aj and by Malwarebytes Anti-Malware as Worm.Palevo | No |
| Microsoft Firewall 2.9 | X | FW-[9 random digits].exe | Added by variants of the AGENT-QWP TROJAN! Example filenames include FW-926056545.exe, FW-241043244.exe, FW-516217385.exe and FW-888349494.exe | No |
| FW Manager | X | fwcheck.exe | Added by the DELBOT-H WORM! | No |
| hp 1000 firmware | ? | fwdl.exe | HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)? | No |
| UpdateFW | ? | fwdload.exe | Appears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module? | No |
| FWDMON.EXE | X | fwdmon.exe | Added by the PROXY-S TROJAN! | No |
| FRITZ!webProtect | U | FwebProt.exe | Firewall included in FRITZ! ISP DSL software | No |
| fwenc.exe | Y | fwenc.exe | Check Point SecuRemote VPN client - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers" | No |
| All Sea web link | X | FWLink.exe | Free screensaver, installs lots of foistware - remove it | No |
| Dilberttest3 web link | X | FWLink.exe | Free screensaver, installs lots of foistware - remove it | No |
| msfirewall32 | X | FWMs32.exe | Added by the PROXY-AA TROJAN! | No |
| %FP%012-L2TP FWPortal.exe | U | FWPortal.exe | 012.Net.il Israeli ISP dial-up software | No |
| %FP%1776 Internet FWPortal.exe | U | FWPortal.exe | 1776 Internet US ISP dial-up software | No |
| %FP%Barak013 FWPortal.exe | U | FWPortal.exe | Barak013 Israeli ISP dial-up software | No |
| Fwr Command Module | X | fwr.exe | Added by the SDBOT-PP WORM! | No |
| fwrastrc | N | fwrastrc.exe | Dial-up software for Friendly Technologies/1NationOnLine free ISP | No |
| fwservice | U | fwservice.exe | Firewall function of eAcceleration Stop-Sign security software - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation | No |
| LGODDFU | U | fwupdate.exe | Auto firmware update program for LG Electronics CD-ROM/DVD writer | No |
| firewall | X | fw_304.exe | Added by the BDOOR-JQ BACKDOOR! | No |
| fxredir | U | fxredir.exe | Canon MultiPASS fax redirector | No |
| Microsoft Security Controlers | X | fxsecues.exe | Added by a variant of W32/Sdbot.worm | No |
| Windows UDP Control Center | X | fxstaller.exe | Detected by Sophos as Troj/Agent-IEE | No |
| Windows UDP Control Center | X | fxsteller.exe | Added by the IRCBOT-J BACKDOOR! | No |
| testest | X | fxxxh.exe | Added by the SDBOT-MK WORM! | No |
| NTSF Microsoft System | X | fylez.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System% | No |
| fyncaqigpicq | X | fyncaqigpicq.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| Nasiso | X | fyowewd.exe | Detected by Malwarebytes Anti-Malware as Trojan.FlyStudio. The file is located in %Windir% | No |
| fyruretpubri | X | fyruretpubri.exe | Detected by McAfee as PWS-Zbot.gen.ari and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| fzee7szk | X | fzee7szk.exe | Detected by McAfee as Generic PWS.y and by Malwarebytes Anti-Malware as PasswordStealer.Tibia. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| qfqqza | X | fzqw.exe | Added by the SDBOT-EL WORM! | No |
| 3feb1dd2ad865b6c315e43e33049579e | X | fzzh.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |