Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2.65.0.0 66.67%
2, 0, 6, 0 33.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetUserNameW, RegSetValueExA, RegCreateKeyExW, RegQueryValueExA, RegQueryValueExW, RegDeleteKeyW, RegCreateKeyExA, RegOpenKeyExA, RegDeleteValueW, RegOpenKeyExW, RegEnumKeyExW, RegCloseKey, RegSetValueExW, RegQueryValueW, RegOpenKeyW, RegEnumKeyW, RegSetValueW, RegCreateKeyW
comdlg32.dll
GetFileTitleW
gdi32.dll
GetObjectW, CreateSolidBrush, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, DeleteDC, SelectObject, DeleteObject, GetStockObject, GetViewportExtEx, GetWindowExtEx, GetPixel, StartDocW, SetViewportOrgEx, OffsetViewportOrgEx, SetViewportExtEx, ScaleViewportExtEx, SetWindowOrgEx, OffsetWindowOrgEx, SetWindowExtEx, ScaleWindowExtEx, GetCurrentPositionEx, ArcTo, PolyDraw, PolylineTo, PolyBezierTo, ExtSelectClipRgn, CreateDIBPatternBrushPt, CreatePatternBrush, GetClipRgn, CreateBitmap, SelectPalette, SelectClipPath, GetObjectType, PlayMetaFile, CreatePen, ExtCreatePen, CreateHatchBrush, GetDCOrgEx, CreateRectRgnIndirect, PatBlt, GetBkColor, GetTextColor, CreateFontIndirectW, GetTextExtentPoint32W, SetRectRgn, CombineRgn, GetMapMode, DPtoLP, GetTextMetricsW, GetRgnBox, GetCharWidthW, CreateFontW, StretchDIBits, PlayMetaFileRecord, CopyMetaFileW, SelectClipRgn, SetColorAdjustment, SetArcDirection, SetMapperFlags, CreateDIBSection, Escape, ExtTextOutW, TextOutW, RectVisible, PtVisible, EnumMetaFile, SetTextCharacterExtra, SetTextJustification, SetTextAlign, MoveToEx, LineTo, OffsetClipRgn, IntersectClipRect, ExcludeClipRect, GetClipBox, SetMapMode, ModifyWorldTransform, SetWorldTransform, SetGraphicsMode, SetTextColor, SetStretchBltMode, SetROP2, SetPolyFillMode, SetBkMode, SetBkColor, RestoreDC, SaveDC, CreateDCW, CreateRectRgn
kernel32.dll
MultiByteToWideChar, lstrlenA, GetModuleFileNameW, lstrcmpW, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, CloseHandle, TerminateThread, GlobalFree, GlobalHandle, CreateThread, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, RaiseException, CreateMutexW, SetLastError, GetLastError, WideCharToMultiByte, FindResourceExW, FindResourceW, LoadResource, SetEnvironmentVariableA, CompareStringW, GetTimeZoneInformation, GetFullPathNameA, SetCurrentDirectoryW, GetCurrentDirectoryW, PeekNamedPipe, GetFileInformationByHandle, GetFullPathNameW, LockResource, GetDriveTypeA, FindFirstFileExW, GetDriveTypeW, FileTimeToLocalFileTime, FileTimeToSystemTime, lstrlenW, GetSystemInfo, FindClose, FindFirstFileW, GetFileSize, CreateFileA, FreeLibrary, GetVersionExW, GetProcAddress, SetEndOfFile, WriteConsoleW, CreateFileW, FlushFileBuffers, SetStdHandle, InterlockedExchange, SetConsoleCtrlHandler, GetConsoleMode, GetConsoleCP, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, FatalAppExitA, GetLocaleInfoW, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStringTypeW, WriteFile, HeapCreate, SetFilePointer, GetFileType, GetStdHandle, SetHandleCount, ReadFile, ExitProcess, TerminateProcess, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, LCMapStringW, GetCurrentThread, GetModuleHandleW, GetCurrentProcessId, ProcessIdToSessionId, GetCommandLineW, LocalFree, SetEvent, GetCurrentThreadId, Sleep, GetCurrentProcess, FindNextFileW, FlushInstructionCache, FindFirstFileExA, SizeofResource, OpenProcess, InterlockedDecrement, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, IsValidCodePage, GetOEMCP, GetACP, InterlockedIncrement, GetCPInfo, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer, GetSystemTimeAsFileTime, WaitForSingleObject, SetWaitableTimer, GetTickCount, CreateEventW, CreateWaitableTimerW, ResetEvent, ReleaseMutex, CreateProcessW, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, HeapDestroy, RtlUnwind, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, HeapAlloc, IsProcessorFeaturePresent, InterlockedPushEntrySList, InterlockedCompareExchange, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, LoadLibraryW, DllMain
ole32.dll
CoGetClassObject, OleUninitialize, CoRevokeClassObject, CreateStreamOnHGlobal, CoTaskMemAlloc, CLSIDFromString, CLSIDFromProgID, OleInitialize, OleLockRunning, StringFromGUID2, CoCreateInstance, CoReleaseServerProcess, CoAddRefServerProcess, ReadFmtUserTypeStg, OleRegGetUserType, WriteClassStg, WriteFmtUserTypeStg, ReadClassStg, CoTaskMemFree, CoInitialize, CreateBindCtx, ReleaseStgMedium, StringFromCLSID, CoTreatAsClass, OleDuplicateData, CoDisconnectObject, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, OleRun, CoFreeUnusedLibraries, CoUninitialize, CoInitializeEx, CoRegisterClassObject, OleSetClipboard, OleIsCurrentClipboard, OleFlushClipboard, CoRegisterMessageFilter, SetConvertStg
oledlg.dll
OleUIBusyW
psapi.dll
GetModuleFileNameExW, EnumProcesses, GetProcessMemoryInfo, EnumProcessModules
shell32.dll
SHGetFolderPathW, CommandLineToArgvW, SHGetFileInfoW, Shell_NotifyIconW, SHAppBarMessage, DragFinish, DragQueryFileW, ExtractIconW
shlwapi.dll
PathFindExtensionW, PathRemoveExtensionW, PathStripToRootW, PathIsUNCW, PathFindFileNameW, PathRemoveFileSpecW
urlmon.dll
UrlMkGetSessionOption, UrlMkSetSessionOption
user32.dll
BeginPaint, InvalidateRect, DispatchMessageW, TranslateMessage, TranslateAcceleratorW, GetActiveWindow, GetMessageW, SetWindowLongW, PostMessageW, ShowWindow, GetClassInfoExW, LoadCursorW, CopyRect, RegisterClassExW, CreateWindowExW, PostThreadMessageW, GetDesktopWindow, EnumChildWindows, FindWindowExW, GetWindowTextW, GetDlgItem, IsWindow, SendMessageW, MapDialogRect, EndDialog, GetWindowLongW, SetWindowPos, SendDlgItemMessageW, GetWindow, SetWindowContextHelpId, DefWindowProcW, GetSysColor, CharNextW, MoveWindow, GetClientRect, ClientToScreen, ScreenToClient, GetDC, UnregisterClassA, SetForegroundWindow, FindWindowW, GetWindowThreadProcessId, GetThreadDesktop, GetSystemMetrics, GetForegroundWindow, CreateDialogIndirectParamW, GetWindowPlacement, IsWindowVisible, EqualRect, SetParent, KillTimer, SetTimer, GetWindowRect, RegisterWindowMessageW, GetWindowTextLengthW, SetWindowTextW, CreateAcceleratorTableW, SetFocus, GetFocus, DestroyAcceleratorTable, InvalidateRgn, EndPaint, CallWindowProcW, DestroyWindow, FillRect, ReleaseCapture, GetClassNameW, GetParent, IsChild, SetCapture, RedrawWindow, ReleaseDC, DllMain
wininet.dll
InternetCrackUrlA, InternetQueryOptionW, InternetOpenW, InternetCrackUrlW, InternetCloseHandle, InternetConnectW, HttpOpenRequestW, InternetSetOptionW, HttpSendRequestW, InternetReadFile
winmm.dll
mixerGetLineControlsW, mixerSetControlDetails, mixerGetLineInfoW, mixerClose, mixerGetControlDetailsW, mixerOpen
winspool.drv
DocumentPropertiesW, ClosePrinter, OpenPrinterW
ws2_32.dll
WSASend, WSAWaitForMultipleEvents, WSARecv, WSAAccept, WSAEnumNetworkEvents, WSACloseEvent, WSACreateEvent, WSAEventSelect

FBW.exe

FBW Application by AnchorFree Inc (Signed)

Remove FBW.exe
Version:   2.65.0.0
MD5:   753a5929fc4ba1d25394cbec264b1189
SHA1:   a6f60f527bdd50ae7d446bca9708acb9da1f4791
SHA256:   267c2ac9705a65f7092c1343ffef9c8759eac49e474796c0fd67785240d3f3ba

About FBW.exe (from AnchorFree Inc)

Hotspot Shield creates a virtual private network (VPN) between your laptop or iPhone and our Internet gateway. This impenetrable tunnel prevents snoopers, hackers, ISP‘s, from viewing your web browsin

Overview

fbw.exe executes as a process with the local user's privileges typically within the context of its parent openvpntray.exe (by AnchorFree Inc). This is typically installed with the program Hotspot Shield 2.67 published by AnchorFree Inc and is most likely removed by most users once installed (64% removed). The file is digitally signed by AnchorFree Inc which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:fbw.exe
Product name:FBW Application
Typical file path:C:\Program Files\hotspot shield\bin\fbw.exe
File version:2.65.0.0
Size:500.86 KB (512,880 bytes)
Certificate
Issued to:AnchorFree Inc
Authority (CA):VeriSign
Expiration date:Sunday, April 13, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
AnchorFree Inc
  64% remove
If you are using the free Service, AnchorFree may deliver third-party Advertisements within the content of any web page accessed. Advertisements may be injected into the top of the page, inserted directly into the page content, or even displayed to overlay the page. A “hotspot” is a Wi-Fi connection access point. Usually this type of connection is public; therefore, it is completely insecure. Hotspot Shield allows you to create a VPN, ...
Network connections
  • [UDP] listens on port 55314

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00709396%
    0.028634%
    Kernel CPU:0.00381279%
    0.013761%
    User CPU:0.00328117%
    0.014873%
    Kernel CPU time:15,384 ms/min
    100,923,805ms/min
    Context switches:35/sec
    284/sec
    Memory
    Private memory:21.94 MB
    21.59 MB
    Private (maximum):36.5 MB
    Private (minimum):4.7 MB
    Non-paged memory:21.94 MB
    21.59 MB
    Virtual memory:107.48 MB
    140.96 MB
    Virtual memory (peak):116.71 MB
    169.69 MB
    Working set:28.27 MB
    18.61 MB
    Working set (peak):37.38 MB
    37.95 MB
    Resource allocations
    Threads:8
    12
    Handles:376
    600
    GUI GDI count:28
    103
    GUI GDI peak:106
    142
    GUI USER count:11
    49
    GUI USER peak:118
    71

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command line:-sp 896
    Owner:User
    Parent process:openvpntray.exe (by AnchorFree Inc)

    ResourcesThreads

    Averages
     
    fbw.exe (main module)
    Total CPU:0.50336883%
    0.272967%
    Kernel CPU:0.06038252%
    0.107585%
    User CPU:0.44298631%
    0.165382%
    CPU cycles:17,664,462/sec
    5,741,424/sec
    Context switches:47/sec
    79/sec
    Memory:512 KB
    1.16 MB
    wow64.dll
    Total CPU:0.09285232%
    Kernel CPU:0.01016853%
    User CPU:0.08268379%
    CPU cycles:2,781,115/sec
    Context switches:2/sec
    Memory:252 KB
    ntdll.dll
    Total CPU:0.05859758%
    Kernel CPU:0.04521012%
    User CPU:0.01338746%
    CPU cycles:1,466,304/sec
    Context switches:1/sec
    Memory:1.66 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 66.67%
    Windows 7 Ultimate 16.67%
    Windows 7 Professional 16.67%

    Distribution by countryDistribution by country

    United Kingdom installs about 33.33% of FBW Application.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    MSI 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE