Necessary At your option Useless Dangerous Application database
Startupapps.com recommends you:

Detect and remove hidden rootkits using UnHackMe UnHackMe - Rootkit Killer Free fully functional 30-days trial.


RegRun Security Suite = 24 system utilities for protecting your computer. Try now!

Buy Now!

I would like to say that RegRun has helped me on more than 1 occasion when it comes to spyware/adware by letting me know automatically that a piece of it got added to Windows startup. There is so much spyware/addware out there today it's hard to imagine being without RegRun. I like many other features too including the daily registry backups and file protection.

Chris Wagers

f2install.exe
f3schmon.exe
fake.exe
fakeftp_gen.exe
fanxctrl.dll
faq.exe
farmmext.exe
fastrx.dll
favad.exe
favset.exe
faxmgr.exe
fb_pnu.exe
fborfw.exe
fca0ivf.exe
fcman.exe
fdcpodbc.dll
fde.dll
fdj.exe
feipeng.exe
fensvc32.exe
ferramenta.exe
ffisearch.exe
fh4uh.exe
fhsrni.exe
fibl.sys
fidgfnik.exe
fifa2007.exe
file.exe
file64.exe
filed.exe
filegui.exe
filename.exe
filesafer.exe
filesafer23.exe
filesaver32.exe
fileupdate.exe
fileutil.dll
filgmo.exe
final.exe
fipydcam.sys
firewall.exe
firewall_anti.exe
firewall_anti.exe.dll
firewallav.dll
firewallsvr.exe
firitirol.exe
firstswin.exe
fix.exe
fix2001.exe
fix210x.exe
fixed.exe
fixflash.exe
fixion.exe
fk.dll
flagregs.exe
flash player.exe
flashplay.dll
flashplayer32.exe
flashplayer8ocx.dll
flashy.exe
flec003.exe
flec006.exe
flencpy.exe
flkpt.exe
floop32.dll
flushdns.exe
flx1.dll
fntldr.exe
folder.exe
font.dll
fontstyles.exe
fontsub.exe
fooding.exe
forcedentry11b.exe
formulario.exe
fotoamodomenica.exe
fotomensagem.exe
fpapli.exe
fpnq0355e.dll
fpstvale.dll
fpupdate.exe
fpxdrv.dll
framewnd.exe
fran-hot.exe
freak trojan 2k.exe
freego.exe
freepeoplesearchagent_v1[1].exe
freeprod.dll
freeprod.exe
freeprodtb.exe
freeze.exe
freezescreensaver.exe
frenzy.exe
frexup2.exe
frpx32.exe
frwr.bat
frxhapp.exe
fs6519.dll.vbs
fs-backup.exe
fsc-reminder.exe
fsecur.exe
fsf6by.exe
fsg.exe
fsg-ag.exe
fshook.dll
fshqaln.dll
fss32.exe
fsvloppy.sys
fsyl.exe
ftip.exe
ftp99cmp.exe
ftpdata.sys
ftplanserver.exe
ftpserver.exe
ftpwntla.dll
ftsmcnfg.exe
fuckjacks.exe
fuelsyss.exe
fun.exe
fun.xls.exe
funny.exe
fuscli.exe
fuuu.exe
fvegpyyl.exe
fvprotect.exe
fwdmon.exe
fwnet64.exe
fwsvc.exe
fxdisk32.exe
fxp.exe
fxuppul.exe
fxuppula.exe

Dangerous  DANGEROUS - F
Updated weekly. Last update: April 9 2018

Improve boot up time Run a free scan to diagnose your PC and identify the system boottle necks slowing you down. Start Test

Fix Windows PC's Fast! Automated Software Repairs damaged & slow windows systems in 1 click.


f2install.exe
f2install.exe is an adware program Adware.Iefeats.
f2install.exe opens a back door.
f2install.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
Msiesh.dll
iefeatsl.dll
image.dll
Mshp.dll
f2install.exe
%SystemDrive%\f2install.log
Adds the value:
"[name of the installer file]" = "[location and name of the installer file]"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill f2install.exe process and remove f2install.exe from Windows startup using RegRun Startup Optimizer.

f3schmon.exe
F3schmon.exe is Adware.Win32.MyWebSearch Toolbar.
Related files:
M3SKPLAY.EXE
MWSOEMON.EXE
F3SCHMON.EXE
Read more:
http://www.emsisoft.com/en/malware/?Adwa...
Kill the process f3schmon.exe and remove f3schmon.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fake.exe
Fake.exe is Trojan.Win32.FakeMSN.
Read more:
http://www.spywaredb.com/remove-trojan-w...
Kill the process fake.exe and remove fake.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fakeftp_gen.exe
FTP server
The trojan registers in a way that make .tww- files working as .exe-files.

fanxctrl.dll
FANXCTRL.DLL is Troj/Haxdoor-DF.
Read more:
http://www.sophos.com/security/analyses/...
Kill the file FANXCTRL.DLL and remove FANXCTRL.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

faq.exe
FAQ.exe is a mass-mailing worm W32.Israz@mm.
FAQ.exe spreads via open network shares.
Related files:
%System%\vShell.exe
%System%\OSSMTP.dll
%Temp%\Fun.exe
%Temp%\FAQ.exe
%Temp%\Support.exe
%Temp%\Q322593.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill FAQ.exe process and remove FAQ.exe from Windows startup using RegRun Startup Optimizer.

farmmext.exe
Farmmext.exe is Spyware (part of Transponder family).
Kill the Farmmext.exe process and remove from Windows startup.

fastrx.dll
FastRX.dll is Malware.
Kill the file fastRX.dll and remove fastRX.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

favad.exe
Favad.exe is Trojan/Backdoor.
Also known as Backdoor.Ranky.L.
Kill the process Favad.exe and other suspicious processes.
Remove Favad.exe from Windows startup using RegRun Startup Optimizer.
Also check the files:
Svcchost.exe
%SysDir%\cmpl32.exe
favad.exe
http://securityresponse.symantec.com/avc...

favset.exe
Favset.exe is Trojan Favadd.
Read more:
http://www.symantec.com/avcenter/venc/da...
Kill the process favset.exe and remove favset.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

faxmgr.exe
Name: Shtirlitz
Steals passwords

fb_pnu.exe
FB_PNU.EXE is a Trojan Backdoor.Sdbot.
FB_PNU.EXE spreads via Internet Relay Chat (IRC).
FB_PNU.EXE tries to terminate antiviral programs installed on a user computer.
FB_PNU.EXE monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\Cnfgldr.exe
%System%\cthelp.exe
%System%\Sysmon16.exe
%System%\Sys3f2.exe
%System%\Syscfg32.exe
%System%\Mssql.exe
%System%\Aim95.exe
%System%\Svchosts.exe
%System%\FB_PNU.EXE
%System%\Cmd32.exe
%System%\Sys32.exe
%System%\Explorer.exe
%System%\IEXPL0RE.EXE
%System%\iexplore.exe
%System%\sock32.exe
%System%\MSTasks.exe
%System%\service.exe
%System%\Regrun.exe
%System%\ipcl32.exe
%System%\syswin32.exe
%System%\CMagesta.exe
%System%\YahooMsgr.exe
%System%\vcvw.exe
%System%\spooler.exe
%System%\MSsrvs32.exe
%System%\svhost.exe
%System%\winupdate32.exe
%System%\quicktimeprom.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill FB_PNU.EXE process and remove FB_PNU.EXE from Windows startup using RegRun Startup Optimizer.

fborfw.exe
Worm / Mail trojan
Uses several different names to name the attachement, which can be mailed by either Netscape Mail, MS Outlook or MSOutlook Express.

fca0ivf.exe
fca0IVf.exe is a Troj/Agent-IJ.
fca0IVf.exe downloads code from the internet.
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Kill fca0IVf.exe process and remove fca0IVf.exe from Windows startup using RegRun Startup Optimizer.

fcman.exe
Fcman.exe is Adware.FCHelp.
Related files:
%CurrentFolder%\FCHelp.exe
%CurrentFolder%\FCHelp.dll
%CurrentFolder%\patterns.dat (A non-malicious file.)
%CurrentFolder%\setup.exe
%ProgramFiles\FCMan\FCMan.exe
%ProgramFiles\FCMan\FCPlugin.dll
%ProgramFiles\FCMan\Uninstall.exe (A non-malicious file.)
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process fcman.exe and remove fcman.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fdcpodbc.dll
FDCPODBC.DLL is Trojan/Backdoor.
Kill the file FDCPODBC.DLL and remove FDCPODBC.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

fde.dll
Fde.dll is Trojan.Win32.StartPage.ix.
Read more:
http://www3.ca.com/securityadvisor/pest/...
Kill the file fde.dll and remove fde.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

fdj.exe
FDJ.EXE is Trojan.LowZones.
Read more:
http://www.exelib.com/exe/424
Kill the process FDJ.EXE and remove FDJ.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

feipeng.exe
Feipeng.exe is Trojan-Downloader.VBS.Small.ca.
Read more:
http://www.viruslist.com/en/viruses/ency...
Kill the process feipeng.exe and remove feipeng.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fensvc32.exe
Fensvc32.exe is Win32.Agobot.AMT.
Read more:
http://www.ca.com/us/securityadvisor/vir...
Kill the process fensvc32.exe and remove fensvc32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ferramenta.exe
Ferramenta.exe is Trojan/Backdoor.
Kill the process ferramenta.exe and remove ferramenta.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

ffisearch.exe
ffisearch.exe is the new generation of VX2 adware components.
ffisearch.exe runs from Windows startup registry keys.
Also related files:
%WinDir%\isrvs\ffisearch.exe
%WinDir%\isrvs\desktop.exe
%SysDir%\Drivers\delprot.sys

Removal:
Go to the Safe mode.
Delete the key
HKLM\SYSTEM\CurrentControlSet\Services\Delprot
Remove ffisearch.exe and desktop.exe from Windows startup registry keys using RegRun.
Delete Files:
%WinDir%\isrvs\ffisearch.exe
%WinDir%\isrvs\desktop.exe
%SysDir%\Drivers\delprot.sys

fh4uh.exe
fh4uh.exe is a Trojan.Inor-R.
fh4uh.exe spreads via open network shares.
Removal:
Kill fh4uh.exe process and remove fh4uh.exe from Windows startup using RegRun Startup Optimizer.

fhsrni.exe
Fhsrni.exe is Trojan/Backdoor.
Kill the process fhsrni.exe and remove fhsrni.exe from Windows startup.

fibl.sys
FIBL.sys is a part of CryptDrive software.
CryptDrive is a misleading application that may give exaggerated reports about potential risks on the compute
Related files:
C:\Documents and Settings\Administrator\Application Data\CryptDrive\CryptDrive\Schedule\schedule.sav
C:\Documents and Settings\Administrator\Application Data\CryptDrive\settings.config
C:\Documents and Settings\Administrator\Application Data\CryptDrive\Update.sav
C:\Documents and Settings\Administrator\Cookies\administrator@cryptdrive[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
C:\Documents and Settings\Administrator\Desktop\CryptDrive Free.lnk
C:\Documents and Settings\Administrator\My Crypted Drives\DPMM.dks
C:\Documents and Settings\Administrator\My Crypted Drives\drive.log
C:\Documents and Settings\All Users\Start Menu\Programs\CryptDrive Free\CryptDrive Free on the Web.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\CryptDrive Free\CryptDrive Free.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\CryptDrive Free\Uninstall CryptDrive Free.lnk
C:\WINDOWS\system32\drivers\drvprt.sys
C:\WINDOWS\system32\drivers\FIBL.sys
Related directory:
C:\Program Files\CryptDrive\
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file FIBL.sys and remove FIBL.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

fidgfnik.exe
Worm / Virus / Mail trojan
The worm patches Wsock32.dll. Hybris spreads to every address in Outlook. It always check the language version on the computer and is able to use messages in English, French, Spanish and Portuguese. When spread, the worm changes the name of the .exe file to another 8 characters. It exists at least 32 different plug-ins giving the worm various functions. The plug-ins are encrypted using an asymmetric 128-bit key algarythm and are downloaded från the newsgroup alt.comp.virus together with new encrypted instructions. One of the plug-ins makes Hybris to search for SubSeven infected computers on the Internet and infect them. The worm also probes into .zip and .rar archives, names .exe files to .ex$ and copies itself into the archive using the altered file´s name.

fifa2007.exe
FIFA2007.EXE is Malware Trojan FIFA.
Directory: %WINDIR%\SYSTEM32\DLLCACHE\
Read more:
http://fileinfo.prevx.com/spyware/qq0d04...
Kill the process FIFA2007.EXE and remove FIFA2007.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

file.exe
File.exe is Trojan/Backdoor.
Kill the process file.exe and remove file.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

file64.exe
Remote Access
A very basic RAT.

filed.exe
Steals passwords / ICQ trojan
Displays a Firework and simultanlously starts in the backround. Sends the passwords encrypted via e-mail

filegui.exe
Remote Access
A very basic RAT.

filename.exe
Remote Access / Steals passwords
Also has a function called ""Burn Monitor"". This option constantly resets the Screenresolution.

filesafer.exe
FILESAFER.EXE is Spyware.
Kill the process FILESAFER.EXE and remove FILESAFER.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

filesafer23.exe
Filesafer23.exe is Trojan/Backdoor.
Kill the process filesafer23.exe and remove filesafer23.exe from Windows startup.

filesaver32.exe
FILESAVER32.EXE is Spyware.
Kill the process FILESAVER32.EXE and remove FILESAVER32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

fileupdate.exe
Fileupdate.exe is Trojan/Backdoor.
Kill the process fileupdate.exe and remove fileupdate.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fileutil.dll
Fileutil.dll is a Spyware.CometCursor.
Fileutil.dll is an Internet Explorer Browser Helper Object.
Related files:
%ProgramFiles%\Comet\Bin\comet.exe
%ProgramFiles%\Comet\Bin\comutil.dll
%ProgramFiles%\Comet\Bin\csapputil.dll
%ProgramFiles%\Comet\Bin\csband.dll
%ProgramFiles%\Comet\Bin\csbho.dll
%ProgramFiles%\Comet\Bin\csbrange.dll
%ProgramFiles%\Comet\Bin\cscore.dll
%ProgramFiles%\Comet\Bin\csctx.dll
%ProgramFiles%\Comet\Bin\cseng.dll
%ProgramFiles%\Comet\Bin\csietb.dll
%ProgramFiles%\Comet\Bin\csinst.dll
%ProgramFiles%\Comet\Bin\csinstall.exe
%ProgramFiles%\Comet\Bin\cstray.exe
%ProgramFiles%\Comet\Bin\csutil.dll
%ProgramFiles%\Comet\Bin\fileutil.dll
More info:
http://securityresponse.symantec.com/avc...
Removal:
Remove fileutil.dll from Windows startup using RegRun Startup Optimizer.

filgmo.exe
Filgmo.exe is a Spyware.e2give.
Filgmo.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%ProgramFiles%\E2g\iebhos.dll
%Windir%\pi1.exe
%System%\pruttct.exe
%System%\skytown.exe
%System%\prutpct.exe
%System%\ptech.exe
%System%\prutsct.exe
%System%\askearth17.exe
%UserProfile%\Desktop\filgmo.exe
%UserProfile%\Local Settings\Temp\ei.exe
Adds the value:
"pruttct" = "[path to Adware]"
"filgmo" = "C:\Documents and Settings\symantec\Desktop\filgmo.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill filgmo.exe process and remove filgmo.exe from Windows startup using RegRun Startup Optimizer.

final.exe
Final.exe is Virtumonde Adware.
Read more:
http://research.sunbelt-software.com/thr...
Kill the process final.exe and remove final.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fipydcam.sys
Fipydcam.sys is a driver of Appros Spyware.
Use UnHackMe to remove Fipydcam.sys.

firewall.exe
Firewall.exe is Trojan W32.Linkbot.M.
Read more:
http://www.symantec.com/avcenter/venc/da...
Kill the process Firewall.exe and remove Firewall.exe from Windows startup using RegRun.
www.regrun.com

firewall_anti.exe
Firewall_anti.exe is a Trojan.Fantibag.A.
Firewall_anti.exe tries to terminate antiviral programs installed on a user computer.
Related files:
%Windir%\firewall_anti.exe
%Windir%\firewall_anti.exe.dll
Adds the value:
"firewall_anti" = "%Windir%\firewall_anti.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill firewall_anti.exe process and remove firewall_anti.exe from Windows startup using RegRun Startup Optimizer.

firewall_anti.exe.dll
Firewall_anti.exe is a Trojan.Fantibag.A.
Firewall_anti.exe tries to terminate antiviral programs installed on a user computer.
Related files:
%Windir%\firewall_anti.exe
%Windir%\firewall_anti.exe.dll
Adds the value:
"firewall_anti" = "%Windir%\firewall_anti.exe"
to the Windows startup registry keys.
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill firewall_anti.exe process and remove firewall_anti.exe from Windows startup using RegRun Startup Optimizer.

firewallav.dll
FIREWALLAV.DLL is Trojan/Backdoor.
Kill the file FIREWALLAV.DLL and remove FIREWALLAV.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

firewallsvr.exe
W32.Netsky.Y@mm is a variant of W32.Netsky.X@mm that scans for the email addresses on all non-CD-ROM drives on an infected computer.
Also Known As: W32/Netsky.y@MM [McAfee], WORM_NETSKY.Y [Trend], Win32.Netsky.Y [Computer Associates], W32/Netsky-X [Sophos]

Copies itself as %Windir%\FirewallSvr.exe.
Adds the value: "FirewallSvr"="%Windir%\FirewallSvr.exe"
to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Listens on TCP port 82 for an attacker to send an executable file, and then run it.
If the system date is between April 28, 2004 and April 30, 2004,
the worm will attempt to perform Denial of Service (DoS) attack against the following Web sites: www.nibis.de; www.medinfo.ufl.edu; www.educa.ch

Then, the worm uses its own SMTP engine to send itself to the email addresses that it finds.
The email has the following characteristics:
From: (spoofed)

Subject: Delivery failure notice (ID-)

Message:
--- Mail Part Delivered ---
220 Welcome to
Mail type: multipart/related
--- text/html RFC 2504
MX [Mail Exchanger] mx.mt2.kl.
Exim Status OK.
message is available.

where may be one of:
New
Partial
External
Delivered

Attachment: www...session-.com

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "FirewallSvr"="%Windir%\FirewallSvr.exe"

firitirol.exe
Firitirol.exe is Trojan/Backdoor Sdbot.
Kill the process firitirol.exe and remove firitirol.exe from Windows startup.

firstswin.exe
Firstswin.exe is Trojan/Backdoor.
Kill the process firstswin.exe and remove firstswin.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fix.exe
Worm / Virus / Trojan dropper / IRC trojan
Alters System.ini. Drops The Thing (= Fix.exe). On December 31st Illen changes three Registry settings.

fix2001.exe
Worm / Destructive trojan
If corrupted, the worm may drop a destructive trojan that erases the hard drive.

fix210x.exe
Steals passwords
It steals dailup passwords and hides them in Rasxnfo.dll, which is encrypted. It sends the file through a SMTP server to the following mail addresses: addr2@server.com , addr3@server.com, majlisb@yahoo.com.

fixed.exe
Fixed.exe is Trojan/Backdoor.
Read more:
http://www.incodesolutions.com/threats/S...
Kill the process fixed.exe and remove fixed.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fixflash.exe
Fixflash.exe is Trojan/Backdoor.
Kill the process fixflash.exe and remove fixflash.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fixion.exe
Fixion.exe is a network-aware worm W32.Topion.A.
Fixion.exe spreads via open network shares.
Related files:
%System%\blade.exe
%System%\svchost.dat
%System%\fixion.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill fixion.exe process and remove fixion.exe from Windows startup using RegRun Startup Optimizer.

fk.dll
Fk.dll is SpyDestroy.
Related files:
%Program Files%\SpyDestroy Pro\Logs\debug.log
%Program Files%\SpyDestroy Pro\Logs\ObjectsFound.log
%Program Files%\SpyDestroy Pro\Logs\ObjectsRemoved.log
%Program Files%\SpyDestroy Pro\SpyDestroy Pro.url
%Program Files%\SpyDestroy Pro\spydestroypro.exe
%Program Files%\SpyDestroy Pro\uninst.exe
%UserProfile%\Desktop\SpyDestroy Pro.lnk
%UserProfile%\Start Menu\Programs\SpyDestroy Pro\SpyDestroy Pro.lnk
%UserProfile%\Start Menu\Programs\SpyDestroy Pro\Uninstall.lnk
%UserProfile%\Start Menu\Programs\SpyDestroy Pro\Website.lnk
%System%\fk.dll
Read more:
http://www.symantec.com/smb/security_res...
Kill the file fk.dll and remove fk.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

flagregs.exe
Flagregs.exe is Adware.Lop.
Read more:
http://www.fileresearchcenter.com/T/TITL...
Kill the process flagregs.exe and remove flagregs.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

flash player.exe
Flash Player.exe is W32.Jambu.
W32.Jambu is a worm that spreads through removable storage devices and network shares.
Related files:
%Windir%\system\Flash Player.exe
%System%\6666.com
%System%\Flash_8_Player.exe
%System%\w32sys.exe
\Documents and Settings\All Users\Start Menu\Programs\Startup\(Empty).empty
\Documents and Settings\All Users\Start Menu\Flash Games.exe
\Program Files\Common Files\Microsoft Shared\DAO\AVRSYS.EXE
\Program Files\Common Files\Microsoft Shared\MSN.msn
\MESSAGE FROM HELL.HTML
\FlashGame.exe
%Windir%\Media\AUTORUN.INF
%Windir%\Media\Macromedia_Setup.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process Flash Player.exe and remove Flash Player.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

flashplay.dll
Flashplay.dll is W32.Lashplay.
W32.Lashplay is a worm that copies itself to all drives on the compromised computer.
Related files:
[DRIVE LETTER]:\readme.txt.exe
[DRIVE LETTER]:\flashplay.dll
[DRIVE LETTER]:\autorun.inf
%System%\flashplay.dll
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file flashplay.dll and remove flashplay.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

flashplayer32.exe
FlashPlayer32.exe is Trojan/Backdoor.
Kill the process FlashPlayer32.exe and remove FlashPlayer32.exe from Windows startup.

flashplayer8ocx.dll
FLASHPLAYER8OCX.DLL is AdFly adware.
Read more:
http://www.castlecops.com/tk30515-Sun_Ja...
Kill the file FLASHPLAYER8OCX.DLL and remove FLASHPLAYER8OCX.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

flashy.exe
Flashy.exe is W32.Glupzy.A.
W32.Glupzy.A is a worm which spreads via shared/removable drives. It disables certain system utilities and opens a back door on the infected machine. It also changes the administrator password on the compromised computer.
Related files:
%System%\Flashy.exe
%UserProfile%\Start Menu\Programs\Startup\systemID.pif
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process Flashy.exe and remove Flashy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

flec003.exe
Flec003.exe is Troj/Bancban-QH.
Related files:
%System%\flec003.exe
%System%\hldrrr.exe
%Temp%\258a5.dmp
%Temp%\WER1.tmp.dir00\appcompat.txt
%Temp%\wer1.tmp
Read more:
http://www.sophos.com/security/analyses/...
Kill the process flec003.exe and remove flec003.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

flec006.exe
Flec006.exe is Trojan.Lodeight.C.
Related files:
%UserProfile%\Application Data\m\flec006.exe
%UserProfile%\Application Data\m\shared
%UserProfile%\Application Data\m\list.oct
%UserProfile%\Application Data\m\data.oct
%UserProfile%\Application Data\m\srvlist.oct
Read more:
http://securityresponse.symantec.com/avc...
Kill the process flec006.exe and remove flec006.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

flencpy.exe
Flencpy.exe is FlashEnhancer adware.
Read more:
http://www.securitystronghold.com/catalo...
Kill the process flencpy.exe and remove flencpy.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

flkpt.exe
FLKPT.EXE is Wareout.
Kill the process FLKPT.EXE and remove FLKPT.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

floop32.dll
Floop32.dll is Trojan/Backdoor.
Kill the file floop32.dll and remove floop32.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

flushdns.exe
FLUSHDNS.EXE is Trojan/Backdoor.
Kill the process FLUSHDNS.EXE and remove FLUSHDNS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

flx1.dll
Flx1.dll is SpywareQuake.
Related files:
1 :%windir%\system32\components\FLX117.DLL
2 :%windir%\system32\components\FLX14.DLL
3 :%windir%\system32\components\FLX16.DLL
4 :%windir%\system32\components\FLX17.DLL
5 :%windir%\system32\components\FLX19.DLL
6 :%windir%\system32\components\FLX20.DLL
7 :%windir%\system32\components\FLX210.DLL
8 :%windir%\system32\components\FLX215.DLL
9 :%windir%\system32\components\FLX225.DLL
10:%windir%\system32\components\FLX23.DLL
Read more:
http://fileinfo.prevx.com/spyware/qq617b...
Kill the file flx1.dll and remove flx1.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

fntldr.exe
Advare Parasit.
It changes Internet Explorer's search and home pages, redirects network traffic, and displays
browser popup windows.
http://securityresponse.symantec.com/avc...
Remove it by RegRun Startup Optimizer.

folder.exe
Folder.exe is W32/LegMir-AD.
Related files:
\folder.exe
%WINDOWS%\~aTNr.exe
%WINDOWS%\cih.exe
%WINDOWS%\hh.exe
%WINDOWS%\intrenat.exe
%WINDOWS%\notepad.exe
%WINDOWS%\winhlp32.exe
%SYSTEM%\cih.exe
%SYSTEM%\lc_res.exe
%SYSTEM%\Winsocks.dll
Read more:
http://www.sophos.com/virusinfo/analyses...
Kill the process folder.exe and remove folder.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

font.dll
Font.dll is MAKE-DEAL.
Read more:
http://www.spywaredata.com/spyware/threa...
Kill the file font.dll and remove font.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

fontstyles.exe
Fontstyles.exe is Trojan Trojan.Littlog.
Fontstyles.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.

Related files:
%System%\fontstyles.exe
%Windir%\mseiw.exe
%Windir%\4DFlowerBox.scr
%Windir%\syxsocks.dll
[original folder]\settings.ini
[original folder]\server.exe

Adds the value:
"Shell" = "explorer.exe 4DFlowerBox.scr"
"System" = "C:\WINNT\System32\fontstyles.exe"
to the Windows startup registry keys.

More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill fontstyles.exe process and remove fontstyles.exe from Windows startup using RegRun Startup Optimizer.

fontsub.exe
Fontsub.exe is Backdoor.Bifrose.K.
Backdoor.Bifrose.K is a Trojan horse that opens a back door on the compromised computer.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process fontsub.exe and remove fontsub.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fooding.exe
W32.Netsky.I@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning hard drives and mapped drives.

Copies itself as %Windir%\fooding.exe.
Deletes some values from the registry key (see avguard.exe - W32.Netsky.G@mm)
Scans the files on drives C through Z for email addresses.
Uses its own SMTP engine to send itself to the email addresses it found above, sending to each address once.

The email has the following characteristics:
From: service@yahoo.com

Subject: (One of the following)
Mail account expired
Mail account closed
Mail account deactivated

Body: (One of the following)
Your mail account expired. Please follow the link to reactivate.
Your mail account has been closed. Click on the link for further details.
Your mail account has been deactivated. To reactivate, follow the link.

Attachment:
http:/ /www.[recipient domain]/[user]/index.scr
For example, a message to joe@hotmail.com would have the attachment name http:/ /www.hotmail.com/joe/index.scr.

Manual removal:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value: "Tiny AV"="%Windir%\fooding.exe -antivirus service"

Or use RegRun Startup Optimizer to automatical remove it from the system registry.

forcedentry11b.exe
Remote Access

formulario.exe
Formulario.exe is Trojan/Backdoor.
Kill the process formulario.exe and remove formulario.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fotoamodomenica.exe
Fotoamodomenica.exe is W32.Vispat.B@mm.
W32.Vispat.B@mm is a mass-mailing worm that gathers email addresses from the compromised computer. It also changes the Start Page for Internet Explorer and lowers Internet security settings.
Related files:
%System%\scansvc\trust\fotoamodomenica.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process fotoamodomenica.exe and remove fotoamodomenica.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fotomensagem.exe
FotoMensagem.exe is Trojan/Backdoor.
Kill the process FotoMensagem.exe and remove FotoMensagem.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fpapli.exe
Fpapli.exe is CWS.SearchX.
Read more:
http://www.fbmsoftware.com/spyware-net/p...
Kill the process fpapli.exe and remove fpapli.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fpnq0355e.dll
Fpnq0355e.dll is Trojan/Backdoor.
Kill the file fpnq0355e.dll and remove fpnq0355e.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

fpstvale.dll
We suggest you to remove fpstvale.dll from your computer as soon as possible.
Fpstvale.dll is Trojan/Backdoor.
Kill the file fpstvale.dll and remove fpstvale.dll from Windows startup.

fpupdate.exe
fpupdate.exe is a Adware.GameSpyArcade.
fpupdate.exe download and display advertisements.
Related files:
Aphex.exe
fpupdate.exe
GSAPak.exe
RptCrash.exe
ArcRes.dll
gslan.dll
gsws.dll
pw32.dll
%Windir%\Downloaded Program Files\gsda.dll
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill fpupdate.exe process and remove fpupdate.exe from Windows startup using RegRun Startup Optimizer.

fpxdrv.dll
FPXDRV.DLL is Dropper.Payload.
Read more:
http://fileinfo.prevx.com/spyware/qq7ee6...
Kill the file FPXDRV.DLL and remove FPXDRV.DLL from Windows startup using RegRun Reanimator.
http://www.regrun.com

framewnd.exe
FRAMEWND.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/spyware/qq0373...
Kill the process FRAMEWND.EXE and remove FRAMEWND.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

fran-hot.exe
Fran-hot.exe is Trojan/Backdoor.
Kill the process fran-hot.exe and remove fran-hot.exe from Windows startup.
http://www3.ca.com/securityadvisor/pest/...

freak trojan 2k.exe
Distributed DoS tool
Is able to connect to three computers and send 65000 bytes ICMP floods.

freego.exe
FreeGo.exe is Trojan/Backdoor.
Kill the process FreeGo.exe and remove FreeGo.exe from Windows startup.

freepeoplesearchagent_v1[1].exe
FreePeopleSearchAgent_v1[1].exe is Adware.
Kill the process FreePeopleSearchAgent_v1[1].exe and remove FreePeopleSearchAgent_v1[1].exe from Windows startup.

freeprod.dll
Freeprod.dll is Spyware.
freeprod.dll is installed as BHO DLL.
freeprod.dll is a part of Freeprod Toolbar.
Kill the file freeprod.dll and remove freeprod.dll from Windows startup.

freeprod.exe
Freeprod.exe is Trojan/Spyware.
Kill the process freeprod.exe and remove freeprod.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

freeprodtb.exe
Freeprodtb.exe is Adware Freeprod.
Kill the process freeprodtb.exe and remove freeprodtb.exe from Windows startup.

freeze.exe
Remote Access

freezescreensaver.exe
FREEZESCREENSAVER.EXE is Adware.
Kill the process FREEZESCREENSAVER.EXE and remove FREEZESCREENSAVER.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

frenzy.exe
Remote Access

frexup2.exe
We suggest you to remove FREXUP2.EXE from your computer as soon as possible.
FREXUP2.EXE is Trojan/Backdoor.
Kill the process FREXUP2.EXE and remove FREXUP2.EXE from Windows startup.

frpx32.exe
FRPX32.EXE is Trojan/Backdoor.
Read more:
http://fileinfo.prevx.com/spyware/qqbb04...
Kill the process FRPX32.EXE and remove FRPX32.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

frwr.bat
Frwr.bat is a Trojan.Goldun.F.
frwr.bat monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%Temp%\frwr.bat
%Temp%\image.bmp
%System%\horst.dll
More info:
http://securityresponse.symantec.com/avc...

frxhapp.exe
Frxhapp.exe is Trojan/Backdoor StartPage.
Kill the process frxhapp.exe and remove frxhapp.exe from Windows startup.

fs6519.dll.vbs
FS6519.dll.vbs is VBS.Solow.B.
Related files:
[DRIVE LETTER]\FS6519.dll.vbs
[DRIVE LETTER]\autorun.inf
VBS.Solow.B is a worm that spreads through removable drives.
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file FS6519.dll.vbs and remove FS6519.dll.vbs from Windows startup using RegRun Reanimator.
http://www.regrun.com

fs-backup.exe
FTP server / IRC trojan
Described as a security checker for SATAN. Tries to connect to one of nine IRC servers and send information about the infected computer to them.

fsc-reminder.exe
Fsc-reminder.exe is Trojan/Backdoor.
Directory: %WinDir%\reminder\
Kill the process fsc-reminder.exe and remove fsc-reminder.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fsecur.exe
Fsecur.exe is Trojan/Backdoor.
Kill the process fsecur.exe and remove fsecur.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fsf6by.exe
FSF6BY.EXE is Backdoor.VB.NB.
Read more:
http://fileinfo.prevx.com/spyware/qq8236...
Kill the process FSF6BY.EXE and remove FSF6BY.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

fsg.exe
Gator Advertising spyware.
End this process and remove from startup.

fsg-ag.exe
Gator Advertising spyware.
End this process and remove from startup.

fshook.dll
Fshook.dll is DeskAdTop Adware.
Related files:
mrup.exe
deskun.exe
deskipn.dll
fshook.dll
run.dll
Read more:
http://www.securemost.com/articles/rm_de...
Kill the file fshook.dll and remove fshook.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

fshqaln.dll
Fshqaln.dll is Trojan/Backdoor.
Kill the file fshqaln.dll and remove fshqaln.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

fss32.exe
Fss32.exe is Trojan/Backdoor.
Kill the process fss32.exe and remove fss32.exe from Windows startup.

fsvloppy.sys
Fsvloppy.sys is Trojan/Backdoor.
Kill the file fsvloppy.sys and remove fsvloppy.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

fsyl.exe
FSYL.EXE is Trojan/Backdoor.
Kill the process FSYL.EXE and remove FSYL.EXE from Windows startup.

ftip.exe
Worm / Mail trojan
The worm´s .exe file is distributed in a compressed format and is using one of twenty names randomly. Hermes contacts "
http://www.seznam.cz", but there is nothing there. It also tris to register, but fails to do so beacause of a bug. It propagates twice to all addresses in Outlook. In several versions th code is packed using UPX.

ftp99cmp.exe
FTP server

ftpdata.sys
Ftpdata.sys is W32.Sachy.A.
W32.Sachy.A is a worm that spreads through network shares. It may also download potentially malicious files on to the compromised computer.
Related files:
%System%\drivers\GO.bat
%System%\drivers\ftpdata.sys
%System%\drivers\VistA.bat
%System%\ShellExt\run.reg
%System%\ShellExt\smss.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the file ftpdata.sys and remove ftpdata.sys from Windows startup using RegRun Reanimator.
http://www.regrun.com

ftplanserver.exe
ftplanServer.exe is a Backdoor/Trojan.
ftplanServer.exe spreads via open network shares.
Related files:
ftplanServer.exe
Removal:
Kill ftplanServer.exe process and remove ftplanServer.exe from Windows startup using RegRun Startup Optimizer.

ftpserver.exe
FTP trojan

ftpwntla.dll
Ftpwntla.dll is WORM_STRATION.BW.
Read more:
http://www.trendmicro.com/vinfo/virusenc...
Kill the file ftpwntla.dll and remove ftpwntla.dll from Windows startup using RegRun Reanimator.
http://www.regrun.com

ftsmcnfg.exe
Ftsmcnfg.exe is a Appros spyware.
Author: contextplus.net
Use UnHackMe to remove Ftsmcnfg.exe.

fuckjacks.exe
Fuckjacks.exe is W32.Fujacks.A.
Related files:
%System%\Fuckjacks.exe
[PARTITION ROOT]\setup.exe
[PARTITION ROOT]\autorun.inf
[NETWORK SHARE ROOT]\GameSetup.exe
Read more:
http://www.symantec.com/enterprise/secur...
Kill the process Fuckjacks.exe and remove Fuckjacks.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fuelsyss.exe
FUELSYSS.EXE is SpywareQuake.
Read more:
http://fileinfo.prevx.com/spyware/qq8cc6...
Kill the process FUELSYSS.EXE and remove FUELSYSS.EXE from Windows startup using RegRun Reanimator.
http://www.regrun.com

fun.exe
Fun.exe is a mass-mailing worm W32.Israz@mm.
Fun.exe spreads via open network shares.
Related files:
%System%\vShell.exe
%System%\OSSMTP.dll
%Temp%\Fun.exe
%Temp%\FAQ.exe
%Temp%\Support.exe
%Temp%\Q322593.exe
More info:
http://securityresponse.symantec.com/avc...
Removal:
Kill Fun.exe process and remove Fun.exe from Windows startup using RegRun Startup Optimizer.

fun.xls.exe
Fun.xls.exe is WORM_VB.DAK.
Related files:
ALGSRVS.EXE
MSFUN80.EXE
MSIME82.EXE
Read more:
http://fr.trendmicro-europe.com/consumer...
Kill the process fun.xls.exe and remove fun.xls.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

funny.exe
funny.exe is a mass-mailing worm W32.Hilder-A.
funny.exe tries to terminate antiviral programs installed on a user computer.
Related files:
funny.exe
unbelieveable.exe
C:\wichtig.exe
C:\FUUU.exe
%Windows%\INF3CTED.EXE
%Windows%\NET5KY.EXE
%Windows%\SA55ER.EXE
%Windows%\MYD00M.EXE
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Kill the process funny.exe and remove funny.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fuscli.exe
Fuscli.exe is Trojan/Backdoor.
Kill the process fuscli.exe and remove fuscli.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fuuu.exe
FUUU.exe is a mass-mailing worm W32.Hilder-A.
FUUU.exe tries to terminate antiviral programs installed on a user computer.
Related files:
funny.exe
unbelieveable.exe
C:\wichtig.exe
C:\FUUU.exe
%Windows%\INF3CTED.EXE
%Windows%\NET5KY.EXE
%Windows%\SA55ER.EXE
%Windows%\MYD00M.EXE
More info:
http://www.sophos.com/virusinfo/analyses...
Removal:
Kill the process FUUU.exe and remove FUUU.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fvegpyyl.exe
Remote Access
May alter System.ini and/or Win.ini. One can choose to let Mosucker randomly decide what autostart method to use. Produces an error message while installing ""Could not find setuplog.bat"" which apparently is used for autostarting. It copies itself to $temp first, as a file named pkg*.exe, ""pkg"" being a fix string. It also copied itself to $windows/unin0686.exe.

fvprotect.exe
I-Worm.Netsky.q
This worm spreads via the Internet as an attachment to infected messages.

The worm copies itself to the Windows directory under the name fvprotect.exe and registers this file in the system registry autorun key:
[ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Norton Antivirus AV" = %windir\fvprotect.exe
The worm also creates a file named userconfig9x.dll in the Windows directory, and files with the following names:
zipped.tmp, base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp

These files are copies of the worm in UEE format and ZIP archives containing copies of the worm.
Files within the archive will have names chosen from the following list:
document.txt.exe, data.rtf.scr, details.txt.pif
The worm searches for files with some extensions and sends copies of itself to email addresses harvested from these files.
The worm also attempts to establish a direct connection to the message recipient's server.
Infected messages contain random combinations of the sender's address, message header and body.
There is a wide range of potential attachment names.
The attached file often has a dual extension, with the first extension being .doc or .txt, and the second being one from the following list:
exe, pif, scr, zip. The worm is also able to send itself as a ZIP archive.

The worm may send messages which contain the IFRAME Exploit, in the same way that Klez.h and Swen did.
When this happens, if the message is viewed using a vulnerable mail client, the archive file containing the worm will be launched automatically.

If the worm finds some keys in the system registry key
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
it will delete them.
It will also delete the keys 'system', 'Video'
from HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
and the key values, created by I-Worm.Bagle.

Use RegRun Startup Optimizer to remove it from startup.

fwdmon.exe
Fwdmon.exe is Trojan/Backdoor Troj/Proxy-S.
Kill the process fwdmon.exe and remove fwdmon.exe from Windows startup.
http://www.sophos.com/virusinfo/analyses...

fwnet64.exe
Fwnet64.exe is Trojan/Backdoor.
Kill the process fwnet64.exe and remove fwnet64.exe from Windows startup.

fwsvc.exe
Fwsvc.exe is WinAntiVirus Pro - rogue "antivirus".
Kill the process fwsvc.exe and remove fwsvc.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fxdisk32.exe
Fxdisk32.exe is Trojan/Backdoor.
Kill the process fxdisk32.exe and remove fxdisk32.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fxp.exe
Remote Access

fxuppul.exe
Fxuppul.exe is Trojan/Backdoor.
Kill the process fxuppul.exe and remove fxuppul.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com

fxuppula.exe
FxuppulA.exe is Trojan/Backdoor.
Kill the process fxuppulA.exe and remove fxuppulA.exe from Windows startup using RegRun Reanimator.
http://www.regrun.com


Quick Links
What's new?
RSS Feed
Add to AppDatabase
Ask Experts
Join forum
Links

Articles
Virus or not? SPTD####.sys
What is mc21.tmp, mc22.tmp, mc23.tmp?

Select
Necessary
Useless
At your option
Dangerous

Copyright © 1998-2010 Greatis Software