| Status | Autorun name | Command | Description |
| Y | F-Secure 2006 | fspex.exe | F-Secure Anti-Virus automatic updater |
| Y | F-Secure Automatic Update | F-Secure Automatic Update.exe | Automatically checks for updates for internet security software from F-Secure Corporation |
| X | F-Secure Gatekeeper | [malware name].exe | Added by the NUWAR.AXQ WORM! |
| U | F-Secure Management Agent | FSMA32.EXE | F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products |
| Y | F-Secure Manager | FSM32.EXE | F-Secure antivirus - carry out scheduled virus scans automatically |
| Y | F-Secure Startup Wizard | FSSW.EXE | F-Secure antivirus |
| Y | F-Secure TNB | TNBUtil.exe | F-Secure antivirus |
| Y | F-StopW | F-StopW.exe | F-Prot anti-virus background scanner by F-Risk Software |
| X | f~a | ra32.exe | Added by the CAY TROJAN! |
| X | F0E84.exe | F0E84.exe | TrustDefender, IronDefender and IronProtector rogue security software - not recommended, removal instructions here, here and here |
| U | f1Tray.exe | F1TRAY.EXE | System Tray icon for FusionOne's MightyPhone software. "MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer" |
| ? | f23mxins | f23mxins | Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required? |
| X | f2install.exe | f2install.exe | Added by the IEFEAT-I TROJAN! |
| U | F5D7050v3 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter |
| U | F5D8001 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card |
| U | F5D8011 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card |
| U | F5D8055v1 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter |
| U | F5D8071 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard |
| U | F5D9010 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter |
| U | F5D9050 | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter |
| X | f607 | f607.exe | Added by the URAT.B TROJAN! |
| X | f73cdc8ee94e | btsendto.exe | Associated with mysearchnow.com/searchbar.html |
| X | f94mggfhfghodftdf | [path to trojan] | Added by the SMALL.JHZ TROJAN! |
| U | Fabrik Ultimate Backup Status | fabrikhomestat.exe | Status monitor for Fabrik Ultimate Backup from Fabrik Inc. "No matter what happens to the drive on your desk - a spilled drink, a curious toddler, a theft or a natural disaster - you know your files are still safe and secure on Fabrik Ultimate Backup's off-site servers" |
| X | FacebookSystems | FacebookSystems.vbs | Added by the AGENT-QLE TROJAN! |
| X | Facegame | [path to trojan] | Added by the AGENT-ICM TROJAN! The most common filename is "Facegame.exe" located in %AppData%\Facegame |
| U | facemoods | facemoodssrv.exe | Supports the free Facemoods add-on for Facebook Chat that "gives you a huge collection of smileys, winks, text effects and more!" and once loaded it exits. Note - if you install using the default options it will make facemoods.com the default home page, search provider and "new tab" page for your browser |
| U | facemoodssrv | facemoodssrv.exe | Supports the free Facemoods add-on for Facebook Chat that "gives you a huge collection of smileys, winks, text effects and more!" and once loaded it exits. Note - if you install using the default options it will make facemoods.com the default home page, search provider and "new tab" page for your browser |
| Y | FairPointServicepoint.exe | FairPointServicepoint.exe | FairPoint Servicepoint Agent tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled |
| X | FaltCheck | allps.exe | Added by the AGENT.RAP TROJAN! |
| U | FamilyKeyLogger | cisvc.exe | Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger |
| X | Fantasia injector | wincfg.exe | Added by the AGOBOT.US WORM! |
| ? | fapmon | fapmon.exe | Fair Access Policy monitor for DirecPC/DirecWay internet access |
| X | farkrish | farkrish.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example |
| X | farmmext | farmmext.exe | VX2.Transponder parasite updater/installer related |
| X | Fash | Fash.exe | IBIS Toolbar hijacker |
| X | faslkakj11 | kjgagklj11.exe | Added by the LEGMIE-ARE TROJAN! |
| N | fast | fast.exe | Optional install from an early release of the Windows XP PowerToys to provide an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system) |
| X | fast | A-fast.exe | A-fast Antivirus rogue security software - not recommended, removal instructions here |
| X | Fast Antivirus 2009 | FastAV.exe | Fast Antivirus rogue security software - not recommended, removal instructions here |
| N | FAST Defrag | FAST2.EXE | FastDefrag defragmenting software |
| X | Fast Home | svcnvt.exe | Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines, however as of this writing it has only been seen in the System32 folder |
| X | Fast Search | svcnv.exe | Homepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf |
| X | Fast start | Ntut.exe | Adware - deteced by Kaspersky as the FAVADD.I TROJAN! |
| X | Fast start | svcnt.exe | Adware - detected by Kaspersky as a variant of the FAVADD TROJAN! |
| U | FastCache | fc.exe | FastCache from AnalogX - speeds up browsing by resolving DNS requests locally |
| X | FastDownloads | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | fastsmell | fastsmell.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example |
| X | FastStart | ntnut32.exe | Added by the STARTPAGE.L TROJAN! |
| X | FastStart | svcnut.exe | Browser hijacker - a variant of the STARTPAGE.L TROJAN! |
| X | FastStart | svcnut32.exe | Browser hijacker - a variant of the STARTPAGE.L TROJAN! |
| N | FastTrack Accelerator | SPEED UP.EXE | FastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus |
| X | FASTTRACKNETVISION | NETVISION.exe | DialCar-Z premium rate dialer |
| U | FastTVSync | FastTVSync.exe | Part of InterVideo (now Corel) DVD Copy - "fast DVD copying and file conversion software. In just three steps, you can copy videos to most DVD formats, or convert them for smooth, flawless viewing on your PSP® or iPod®. With broad format support and unique CopyLater™ technology, DVD Copy saves you time and ensures high-quality output like no other copying software" |
| N | FastUser | fast.exe | Optional install from an early release of the Windows XP PowerToys to provide an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system) |
| N | FastUsr | fast.exe | Optional install from an early release of the Windows XP PowerToys to provide an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system) |
| X | faT | faT.exe | Added by the BANKER-DFP TROJAN! |
| X | fat.exe | fat.exe | Part of the WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 rogue security programs - not recommended, removal instructions here and here |
| X | Fat32 Microsoft | fat32.exe | Added by the RBOT-EL WORM! |
| U | FatPipe | DHCP | Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users |
| U | Fatpipe Dialer | fpdialer.exe | Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users |
| U | fatrecov | fatrecov.exe | SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | FavoriteSync | FavoriteSync.exe | FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync |
| U | FaxCenterServer | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others |
| U | FaxCenterServer4_in_1 | fm3032.exe | FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others |
| U | FaxCtrl.exe | ASMediaProxyServer.exe | Part of Avaya's Contact Center Express - "a multi-channel, high-volume software solution from Avaya designed specifically for the intelligent routing and computer telephony integration (CTI) needs of medium-sized contact centers" |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually |
| U | FBDirect | FBDirect.exe | Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop! |
| ? | FBI | FBISM.exe | Compaq related but what does it do? |
| X | FBSearch | FastBrowserSearchProtection.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information |
| X | FBSearch | SearchGuardPlus.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information |
| X | FBSSA | ie3sh.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information |
| X | fc | runfc.exe | Added by the CAMPURF WORM! |
| U | FCACheck | FCACheck.exe | Family Cyber Alert surveillance software. Uninstall this software unless you put it there yourself |
| X | FCEngine | FCEngine.exe | CASClient adware |
| X | FCHelp | FCHelp.exe | Added by either FCHelp adware or a variant of it |
| U | FCleaner | FCleaner.exe | FCleaner by FTweak Inc - "is a freeware all-in-one Windows disk and registry cleaning and optimization tool. It removes unused files and invalid registry entries that are eating up your disk space and slowing your system down, tweaks your system and allows your Windows to run faster." Features include removing unused files, cleaning internet history, managing startup programs and a fully featured registry cleaner |
| X | FCMan | FCMan.exe | FCHelp adware |
| U | FD_SAP | FD.exe | Reported to be the autopassword program from the Sony Microvault thumb drive |
| X | Fdaemon security | fsecur.exe | Added by the SDBOT.KXO WORM! |
| X | FDD SYSTEM | Fdd.exe | Added by the MYTOB-FO WORM! |
| X | fddddHOME | dxxatp.exe | Added by the RANKY.AA TROJAN! |
| X | Fdr Command Module | sp2.exe | Added by the SDBOT.WP WORM! |
| X | FDriver | windrv.exe | Added by the DELF.WG TROJAN! |
| X | FeCPY | fecpy.exe | FlashEnhancer adware |
| Y | feedback | feedback.exe | Part of the error reporting mechanism for the Outpost range of security products from Agnitum Ltd - including Outpost Firewall Pro, Outpost Antivirus Pro and Outpost Security Suite Pro. Dumps the system information to a log at startup in case it's needed and exits. Also used by Lavasoft Personal Firewall and located in either "Agnitum" or "Lavasoft" sub-directories of %ProgramFiles% |
| U | feedreader.exe | feedreader.exe | "Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML" |
| X | feelalright | mirc.exe | Added by the IRCFLOOD-M WORM! |
| U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals) |
| X | fegoze | SVCH0ST.EXE | Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase "o" |
| U | Fellowes Proxy | R3proxy.exe | Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice |
| X | Fen Startups | fensvc32.exe | Added by the RANDEX.CCF WORM! |
| X | Fenio Startups | fnesvc32.exe | Added by the AGOBOT-OS BACKDOOR! |
| U | FerrariWallPaper | FerrariWP.exe | Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com |
| X | FestPlattenCleaner | SysRep.exe | FestPlattenCleaner, German rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| X | FestplattenReiniger | GDC.exe | FestplattenReiniger, German rogue privacy tool - not recommended. A member of the PCPrivacyTool family |
| X | ff | [path to worm] | Added by the RBOT-XL WORM! |
| X | ff | svhost32.exe | Added by the LINEAG-AFF TROJAN! |
| X | ffeqfqs | dqddss.exe | Added by the SDBOT-SG WORM! |
| X | ffeqOME | vcvsav.exe | Added by the RANKY.AB TROJAN! |