| Status | Autorun name | Command | Description |
| X | ff | svhost32.exe | Added by the LINEAG-AFF TROJAN! |
| X | ffeqfqs | dqddss.exe | Added by the SDBOT-SG WORM! |
| X | ffeqOME | vcvsav.exe | Added by the RANKY.AB TROJAN! |
| X | ffis | ffisearch.exe | iSearch adware |
| Y | ffprsrv | ffprsrv.exe | File and Folder Privacy - is a "system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program |
| Y | ffprsrv.exe | ffprsrv.exe | File and Folder Privacy - is a "system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program |
| Y | ffpsrv | ffpsrv.exe | File & Folder Protector - "great easy-to-use password-protected security utility lets you password-protect certain files and folders, or to hide them securely from viewing and searching just with a click of mouse". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program |
| Y | ffpsrv.exe | ffpsrv.exe | File & Folder Protector - "great easy-to-use password-protected security utility lets you password-protect certain files and folders, or to hide them securely from viewing and searching just with a click of mouse". If this entry is disabled, any files/folders that are protected/hidden will no longer be accessible without first accessing the main program |
| U | FG1_00 | frntgate.exe | FrontGate MX - e-mail spam blocker |
| ? | fgl23DoubleScreenHooks | f23happ.exe | Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required? |
| X | fGQEGqHOME | gwwgtp.exe | Added by the RANKY.J TROJAN! |
| X | FheSrv | FheSrv32.exe | Added by the DELF.AFH BACKDOOR! |
| X | FHPage | shdochp.exe | Added by the WINHOUND TROJAN! |
| X | FHStart | shdocsvc.exe | Added by the WINHOUND TROJAN! |
| U | Fhtisxk | fhtisxk.exe | XtraKeys keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Fhzepgyi | HELLRAIDER.EXE | Added by the MINDCTRL.A BACKDOOR! |
| U | FieldForms Sync | SyncService.exe | Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well |
| X | FiendlyType | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup! |
| X | FILE | abcdefg.exe | Added by the KELVIR.DD WORM! |
| ? | file indexing service | msfindfile.exe | New version of MS FindFast and still a resource hog? |
| X | file laoder configuration | rnd32.exe | Added by the RBOT.BQJ WORM! |
| X | File Mapping Services | hp-1003.exe | Added by the RBOT.FAN WORM! |
| X | File Protection Monitor | filemon.exe | Added by a variant of the RBOT WORM! |
| X | File System | taskmqrs.exe | Added by a variant of the TOXBOT/CODBOT WORM! |
| X | File System | taskmqr.exe | Added by the RBOT.BWQ WORM! |
| X | File System Service | wmiprvsc.exe | Added by the AGOBOT-HZ TROJAN! |
| X | File Updater | SPY_NET_RAT.exe | Added by the AGENT-LRO TROJAN! |
| X | File-Sharing Wizard | shwizard.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | File0_0 | MD1.exe | Added by the DLOADER-OR TROJAN! |
| X | File1 | Dia Claro.htm | Added by the DLOADER-OR TROJAN! |
| X | FileFreedom_Plugin | wtm.exe | FileFreedom peer-to-peer sharing program |
| N | filehippo.com | UpdateChecker.exe | Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required |
| N | FileHippo.com Update Checker | UpdateChecker.exe | Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required |
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ChkMgr32.vbs" file is located in %System% |
| X | filen | filen.exe | Added by the VBNAM-A WORM! |
| X | filename | filename.exe | Added by the VB.FSY TROJAN! |
| X | filename process | kerneldll.exe | Added by the AGOBOT-PO WORM! |
| X | filename process | explore.exe | Added by the AGOBOT-QN WORM! |
| X | filename process | Rundil16.exe | Added by the GAOBOT.ZX WORM! |
| X | Files Driver | sdphost.exe | Added by the SDBOT-DKZ WORM! |
| X | Files Driver | sfdhost.exe | Added by the AGOBOT-AJC BACKDOOR! |
| X | FileSoft | Wscript.exe UpdataFiles.vbs | Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "UpdataFiles.vbs" file is located in %Windir% |
| X | FileSystem | [random].exe | Added by the ROHIMAFO BACKDOOR! |
| X | filit | [path to trojan] | Added by the PERDA-G BACKDOOR! |
| U | FilmLoop | FilmLoopService.exe | Related to FilmLoop - a photocasting network. Share your pictures with your family and friends |
| U | FilterGate | filtergate.exe | Filtergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items |
| U | Filterguard | Filtrgrd.exe | An icon located in the lower left of the screen and looks like a lifesaver. This icon is a "short-cut" to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by "right-clicking" on the icon |
| X | FilterProgram | GDC.exe | FilterProgram rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool family |
| X | Find | find.exe | Added by the OPANKI WORM! |
| N | Find Fast | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines |
| Y | Find Virus Launch Program | fvlaunch.exe | Part of Dr. Solomon's Antivirus |
| X | findfast | findfast.exe | Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office |
| X | findfast.exe | findfast.exe | Identified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office |
| X | FindHack | [path to worm] | Added by the KELVIR-BA WORM! |
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output" |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output" |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. "FinePrint saves ink, paper, time and money by controlling and enhancing printed output" |
| N | FineReader7NewsReaderPro | AbbyyNewsReader.exe | ABBYY FineReader OCR software - version 7 |
| U | FingerPrintSoftware | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks |
| X | Fire Wall services | [random filename] | Added by the IRCBOT-QY WORM! |
| X | Fire Wall services | wnlmzsfhobi.exe | Added by the IRCBOT-QY WORM! |
| X | Fire Well service | [random].exe | Added by the RBOT-FJU WORM! |
| ? | FireBox Control Panel | FireBox.exe | Control panel for the Presonus FireBox firewire based music recording system. Is it required? |
| X | FireExplore Update | FireExplore.exe | Added by a variant of the RBOT WORM! |
| X | FireFox | firefox.exe | Added by the RBOT-ATP WORM! Note - this is not the popular FireFox web browser and is located in %System% |
| X | Firefox Plugin Manager | firefoxpgm.exe | Added by the MSNPHOTO.E WORM! |
| U | Firefox Preloader | FirefoxPreloader.exe | Firefox Preloader - "a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time". Even on fast machines Firefox can take a while to load |
| X | FireFox Service Drivers | ssmss.exe | Added by a variant of the SDBOT WORM! |
| X | FireFox Startup Drivers | wuaclt.exe | Added by the RBOT.BYX WORM! |
| X | firefox.exe | firefox.exe | Added by the BANKER-EBO TROJAN! Note - this is not the popular FireFox web browser and is located in %System% |
| Y | FirePod | FIREPOD.EXE | Driver for the PreSonus FP10 (formerly FirePod) Firewire recording system |
| X | FiresWallservices | [random].exe | Added by the RBOT-FJT WORM! |
| Y | Firetrust Benign | B9.exe | FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run" |
| X | Firevall Administrating | rndll.exe | Added by the PUSHBOT-B WORM! |
| X | firewal | firewal.exe | Added by the BANCBAN-QY TROJAN! |
| X | Firewall | wmlaunch .exe | Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename |
| X | Firewall | wmlaunch .exe | Added by the ELIPTER.D WORM! |
| X | Firewall | SP2 UPDATE.exe | Added by the ELITPER.E WORM! |
| X | Firewall | Firewall.bat | Added by the YPSAN.G WORM! |
| X | firewall | fw_304.exe | Added by the BDOOR-JQ BACKDOOR! |
| X | Firewall | ctfmon.exe | Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir% |
| X | firewall | spoolsv.exe | Added by the DIZAN.F VIRUS! |
| X | firewall | firewall.exe | Added by the SURO-A TROJAN! |
| X | firewall 2008 | logoneui.exe | Added by the SILLYFDC WORM! |
| X | Firewall Admin | infocard.exe | Added by the VBPIT-A MALWARE! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft which is normally found in %Windir%\Microsoft.NET%\Framework%\v3.0%\Windows Communication Foundation. This one is located in %Windir% |
| X | Firewall Administrating | infocard.exe | Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename |
| X | Firewall auto setup | winlogon.exe | Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% |
| X | Firewall auto setup | [path to trojan] | Added by the AGENT-GLY TROJAN! |
| X | Firewall config | ReadMe.exe | Added by the SILLYFDC.BBT WORM! |
| X | Firewall Controls | sys32.exe | Added by the SDBOT-DGI WORM! |
| X | Firewall Policy | MidiDef32.exe | Added by the PIEBOT-A TROJAN! |
| X | Firewall Sp2 system | sys32Conf.exe | Added by the RBOT-ABT WORM! |
| X | Firewall Update System1 | WinedowsUpdater1.exe | Added by the RBOT-ARU WORM! |
| X | Firewall Updater | msnupdateit.exe | Added by the RBOT-AAQ WORM! |
| X | Firewall.exe | Firewall.exe | Added by the AGENT.AGL BACKDOOR! Located in %System% |
| Y | FireWall.exe | FireWall.exe | Ashampoo® Firewall PRO and Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG. Located in an Ashampoo related sub-directory of %ProgramFiles% |
| X | firewall_anti | firewall_anti.exe | Added by the NETDENY-B TROJAN! |
| X | FirewallActivies | csrss.exe | Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "3041" subfolder |
| Y | FirewallGUI | FirewallGUI.exe | System Tray access to PC Tools Firewall Plus from PC Tools - which "is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC" |
| U | FirewallStartup | Firewallstartup.exe | Innovative Startup Firewall - "designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean, fast and in it's best shape" |