| Status | Autorun name | Aufruf | Beschreibung |
| X | FireWire Services | nvcsv32.exe | Added by a variant of the SPYBOT WORM! |
| X | First | Finddir.exe | Added by the DELF-EZD TROJAN! |
| X | First Home Page | http://find.naupoint.com | Naupoint browser hijacker |
| ? | First Principle Group | fpg.exe | Related to the E-Players Card from First Principle Group |
| U | Fishy | Fishy.exe | Fishy widget included with the DesktopX desktop utility from Stardock Corporation. Displays a fish swimming on the desktop. Once started, Fishy.exe loads a file called "DXWidget.exe" and exits |
| X | FIX | WinFIX1.0.vbs | Added by the GORMLEZ-A WORM! |
| X | Fix Tool | Fix-Tool.exe | Fix Tool rogue system error and cleaning utility - not recommended |
| Y | Fix-it | mxtask.exe | Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required |
| Y | Fix-it AV | memcheck.exe | Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources |
| X | Fixnice | vcvw.exe | Added by the SDBOT TROJAN! |
| X | fjdslssdfd | mat2.exe | Added by the SLAPEW.C TROJAN! |
| U | FjMenu | FjMenu.exe | From the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable |
| U | FJTWAIN Setup | FjtwSetup.exe | Fujitsu scanner utility |
| N | FJUPDNV_Chitose | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop |
| X | FKS v2.0 | msngr.exe | Added by an unidentified WORM or TROJAN! |
| N | fkSysMon | fksysmon.exe | fkWrae SysMon - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more" |
| X | FlaCPY | flacpy.exe | FlashEnhancer adware |
| X | Flash | Flash.exe | Added by the BANKER.ETK TROJAN! |
| X | Flash Driver | [path to trojan] | Added by the AGENT.CWVT TROJAN! |
| X | Flash Media | %%%%%.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Flash Media | %%%.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Flash Media | [path to trojan] | Added by the IRCBOT.AUR TROJAN! |
| X | Flash Media | ^ ^^^ %% % ^% ^%%^ %^ .exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | ^^% ^ %%% %^%%%^%%^%^% % ^^%% % %^^^^ ^%%^%% .exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | ^^^^^.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Flash Media | ^^^^^^.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Flash Media | services.exe | Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% |
| X | Flash Media | zrpk��'�'%''msn'�%'fix''.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | % ^% ^^^ %^% %% ^ ^ %%% ^% %^ % %^^.exe | Added by a variant of the IRCBOT BACKDOOR! Note the space at the beginning of the filename |
| X | Flash Media | ^%%^%%%^% %^ ^ .exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | %^^%^^% %^^^^ .exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | ^%^^^%% ^ ^ %^^^^^ %^ ^%^^ ^%^^^^^ %^ ^^^%^%%.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | %^% ^ %^%% ^ % ^%%^^ %^^%^%^ ^%% %^.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | %%%%%%^^ ^ .exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | Flash Media | skxs��'�'%''msn'�%'fix''.exe | Added by the AGENT.ZOY TROJAN! |
| X | Flash Media | ^ %%^%^%.exe | Added by the FLUSH.A TROJAN! Note the space at the beginning of the filename |
| X | Flash Media | %% % ^^ % %% ^%^^ ^^^ % ^%% ^ ^.exe | Added by a variant of the IRCBOT BACKDOOR! See here. Note the space at the beginning of the filename |
| X | Flash Media | ^ ^ % ^ % % ^ ^ ^%% ^% %%^^.exe | Added by the IRCBOT.BAW BACKDOOR! |
| X | Flash Player2 | [path to worm] | Added by the IRCBOT.PD WORM! |
| X | Flash_Player_Install | ying.exe | Constructor VC2000 malware |
| ? | FLASH32 | -flash32.exe | ?? |
| X | Flash32 | FLASH32.COM | Added by the STARTER-F TROJAN! |
| U | FlashEnc | FlashEnc.exe | Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission, which is a pain. No need for it if you do not want these features |
| N | Flashget | FlashGet.exe | FlashGet download manager. Located in %ProgramFiles%\FlashGet |
| X | Flashget Download Manager | Flashget.exe | Added by the RBOT-AGZ WORM! Located in %System% |
| X | FlashGuard | FlashGuard.exe | Added by the AUTOIT.AL WORM! |
| U | FlashMute | FlashMute.exe | "FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively, or alternatively all sounds produced by the browser" |
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
| N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
| N | FlashPath Status | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
| N | FlashPath Status | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs |
| X | Flashy Bot | Flashy.exe | Added by the GLUPZY.A WORM! |
| X | FlenCPY | flencpy.exe | FlashEnhancer adware |
| U | Flex2K.exe | Flex2K.exe | FlexType 2k from Datecs - a program used to read and write in symbolic writing systems such as Cyrillic, Greek and Russian |
| U | Flexicd | Flexicd.exe | CD player - part of the Win95 Power Toys |
| U | FlexType 2K | FType2K.exe | FlexType 2k from Datecs - a program used to read and write in symbolic writing systems such as Cyrillic, Greek and Russian |
| U | FlexType 2K | Flex2K.exe | FlexType 2k from Datecs - a program used to read and write in symbolic writing systems such as Cyrillic, Greek and Russian |
| U | FlingRun | fling.exe | Fling - free FTP software from NCH Software |
| U | FLMBROWSERMOUSE | mouse32A.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse |
| U | FLMK08KB | MMKEYBD.EXE | Multimedia keyboard manager. Required if you use the additional keys |
| U | FLMK08KB | KbdAp32A.exe | Keyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard |
| U | FLMLABTECMOUSE | mouse32A.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse |
| U | FLMMEDIONMOUSE | mouse32a.exe | Mouse utility for a Medion branded Fellowes mouse |
| U | FLMOFFICE4DMOUSE | moffice.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse |
| U | FLMOFFICE4DMOUSE | mouse32a.exe | Mouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse |
| U | FLMTRUSTKB | KbdAp32A.exe | Keyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard |
| U | FLMTRUSTMOUSE | mouse32a.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse |
| X | FlnCPY | flncpy.exe | FlashEnhancer adware |
| X | FLooDNeT | FLooDeR.exe | Added by the ENDOOL TROJAN! |
| X | Floppy Master | [path to trojan] | Added by the ZONIT-F TROJAN! |
| ? | Flow Go TV | flogotv.exe | ?? |
| X | flps | flps.vbs | Added by the BYRON WORM! |
| X | flpycntl | flpycntl.exe | Added by the CRYPTER.C TROJAN! |
| ? | FLSVCI | FLSVCI.exe | ?? |
| Y | FltProcess | msinet.exe | Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done |
| X | FlyswatDesktop | flydesk.exe | Advertising spyware |
| U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used) |
| X | fmnwebassist | fmnwebassist.exe | Adware popup generator |
| U | FMStart | Fmstart.exe | GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop |
| X | FMSZ | fmsz.exe | Added by the FMSZ TROJAN! |
| X | fnmwebassist | fnmwebassist.exe | WinPL adware |
| ? | Focus | Focus.exe | ISDN configuration wizard? |
| X | fOEqVGtijLGLKa | fOEqVGtijLGLKa.exe | Added by the FAKEAV-DTH TROJAN! |
| X | foffice | nm.exe | Added by the DELF-CB TROJAN! |
| X | Folder Service | wssdtu.exe | Added by the MANIFEST TROJAN! |
| U | Folder View | folderview.exe | Folder View enhances the Windows file Explorer by making all folders you need available in a single click |
| U | FolderClone v*.*.* | folderclone.exe | Folderclone backup and synchronization software |
| X | FolderRaper | [path to worm] | Added by the VB.GOZ WORM! |
| U | FolderShare | FolderShare.exe | "FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends" |
| N | Folding@home | WINFAH.EXE | Folding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs |
| N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required |
| X | Font | boot.exe | Added by the AGENT-LZW TROJAN! |
| X | Font Viewer | fontviewer.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | FontFix | fontfix.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | fontnav | FontNav.exe | Font Navigator from Bitstream Inc. - a font management utility |
| X | FontsLoader | ldfnt32.hta | Unidentified malware |
| X | FONTVIEW | FONTVIEW.EXE | Added by the OPASERV.T WORM! |
| U | FooBar 1.0 | FooBar.exe | FooBar - "combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar" |
| X | foobin lptt01 | foobin.exe | RapidBlaster variant (in a "foo1" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | foobin ml097e | foobin.exe | RapidBlaster variant (in a "foo1" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |