Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

2.65.0.0 66.67%
2, 0, 6, 0 33.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetUserNameW, RegSetValueExA, RegCreateKeyExW, RegQueryValueExA, RegQueryValueExW, RegDeleteKeyW, RegCreateKeyExA, RegOpenKeyExA, RegDeleteValueW, RegOpenKeyExW, RegEnumKeyExW, RegCloseKey, RegSetValueExW, RegQueryValueW, RegOpenKeyW, RegEnumKeyW, RegSetValueW, RegCreateKeyW
comdlg32.dll
GetFileTitleW
gdi32.dll
GetObjectW, CreateSolidBrush, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, DeleteDC, SelectObject, DeleteObject, GetStockObject, GetViewportExtEx, GetWindowExtEx, GetPixel, StartDocW, SetViewportOrgEx, OffsetViewportOrgEx, SetViewportExtEx, ScaleViewportExtEx, SetWindowOrgEx, OffsetWindowOrgEx, SetWindowExtEx, ScaleWindowExtEx, GetCurrentPositionEx, ArcTo, PolyDraw, PolylineTo, PolyBezierTo, ExtSelectClipRgn, CreateDIBPatternBrushPt, CreatePatternBrush, GetClipRgn, CreateBitmap, SelectPalette, SelectClipPath, GetObjectType, PlayMetaFile, CreatePen, ExtCreatePen, CreateHatchBrush, GetDCOrgEx, CreateRectRgnIndirect, PatBlt, GetBkColor, GetTextColor, CreateFontIndirectW, GetTextExtentPoint32W, SetRectRgn, CombineRgn, GetMapMode, DPtoLP, GetTextMetricsW, GetRgnBox, GetCharWidthW, CreateFontW, StretchDIBits, PlayMetaFileRecord, CopyMetaFileW, SelectClipRgn, SetColorAdjustment, SetArcDirection, SetMapperFlags, CreateDIBSection, Escape, ExtTextOutW, TextOutW, RectVisible, PtVisible, EnumMetaFile, SetTextCharacterExtra, SetTextJustification, SetTextAlign, MoveToEx, LineTo, OffsetClipRgn, IntersectClipRect, ExcludeClipRect, GetClipBox, SetMapMode, ModifyWorldTransform, SetWorldTransform, SetGraphicsMode, SetTextColor, SetStretchBltMode, SetROP2, SetPolyFillMode, SetBkMode, SetBkColor, RestoreDC, SaveDC, CreateDCW, CreateRectRgn
kernel32.dll
MultiByteToWideChar, lstrlenA, GetModuleFileNameW, lstrcmpW, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, CloseHandle, TerminateThread, GlobalFree, GlobalHandle, CreateThread, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, RaiseException, CreateMutexW, SetLastError, GetLastError, WideCharToMultiByte, FindResourceExW, FindResourceW, LoadResource, SetEnvironmentVariableA, CompareStringW, GetTimeZoneInformation, GetFullPathNameA, SetCurrentDirectoryW, GetCurrentDirectoryW, PeekNamedPipe, GetFileInformationByHandle, GetFullPathNameW, LockResource, GetDriveTypeA, FindFirstFileExW, GetDriveTypeW, FileTimeToLocalFileTime, FileTimeToSystemTime, lstrlenW, GetSystemInfo, FindClose, FindFirstFileW, GetFileSize, CreateFileA, FreeLibrary, GetVersionExW, GetProcAddress, SetEndOfFile, WriteConsoleW, CreateFileW, FlushFileBuffers, SetStdHandle, InterlockedExchange, SetConsoleCtrlHandler, GetConsoleMode, GetConsoleCP, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, FatalAppExitA, GetLocaleInfoW, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStringTypeW, WriteFile, HeapCreate, SetFilePointer, GetFileType, GetStdHandle, SetHandleCount, ReadFile, ExitProcess, TerminateProcess, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, LCMapStringW, GetCurrentThread, GetModuleHandleW, GetCurrentProcessId, ProcessIdToSessionId, GetCommandLineW, LocalFree, SetEvent, GetCurrentThreadId, Sleep, GetCurrentProcess, FindNextFileW, FlushInstructionCache, FindFirstFileExA, SizeofResource, OpenProcess, InterlockedDecrement, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, IsValidCodePage, GetOEMCP, GetACP, InterlockedIncrement, GetCPInfo, GetStartupInfoW, HeapSetInformation, DecodePointer, EncodePointer, GetSystemTimeAsFileTime, WaitForSingleObject, SetWaitableTimer, GetTickCount, CreateEventW, CreateWaitableTimerW, ResetEvent, ReleaseMutex, CreateProcessW, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, HeapDestroy, RtlUnwind, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, HeapAlloc, IsProcessorFeaturePresent, InterlockedPushEntrySList, InterlockedCompareExchange, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, LoadLibraryW, DllMain
ole32.dll
CoGetClassObject, OleUninitialize, CoRevokeClassObject, CreateStreamOnHGlobal, CoTaskMemAlloc, CLSIDFromString, CLSIDFromProgID, OleInitialize, OleLockRunning, StringFromGUID2, CoCreateInstance, CoReleaseServerProcess, CoAddRefServerProcess, ReadFmtUserTypeStg, OleRegGetUserType, WriteClassStg, WriteFmtUserTypeStg, ReadClassStg, CoTaskMemFree, CoInitialize, CreateBindCtx, ReleaseStgMedium, StringFromCLSID, CoTreatAsClass, OleDuplicateData, CoDisconnectObject, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal, OleRun, CoFreeUnusedLibraries, CoUninitialize, CoInitializeEx, CoRegisterClassObject, OleSetClipboard, OleIsCurrentClipboard, OleFlushClipboard, CoRegisterMessageFilter, SetConvertStg
oledlg.dll
OleUIBusyW
psapi.dll
GetModuleFileNameExW, EnumProcesses, GetProcessMemoryInfo, EnumProcessModules
shell32.dll
SHGetFolderPathW, CommandLineToArgvW, SHGetFileInfoW, Shell_NotifyIconW, SHAppBarMessage, DragFinish, DragQueryFileW, ExtractIconW
shlwapi.dll
PathFindExtensionW, PathRemoveExtensionW, PathStripToRootW, PathIsUNCW, PathFindFileNameW, PathRemoveFileSpecW
urlmon.dll
UrlMkGetSessionOption, UrlMkSetSessionOption
user32.dll
BeginPaint, InvalidateRect, DispatchMessageW, TranslateMessage, TranslateAcceleratorW, GetActiveWindow, GetMessageW, SetWindowLongW, PostMessageW, ShowWindow, GetClassInfoExW, LoadCursorW, CopyRect, RegisterClassExW, CreateWindowExW, PostThreadMessageW, GetDesktopWindow, EnumChildWindows, FindWindowExW, GetWindowTextW, GetDlgItem, IsWindow, SendMessageW, MapDialogRect, EndDialog, GetWindowLongW, SetWindowPos, SendDlgItemMessageW, GetWindow, SetWindowContextHelpId, DefWindowProcW, GetSysColor, CharNextW, MoveWindow, GetClientRect, ClientToScreen, ScreenToClient, GetDC, UnregisterClassA, SetForegroundWindow, FindWindowW, GetWindowThreadProcessId, GetThreadDesktop, GetSystemMetrics, GetForegroundWindow, CreateDialogIndirectParamW, GetWindowPlacement, IsWindowVisible, EqualRect, SetParent, KillTimer, SetTimer, GetWindowRect, RegisterWindowMessageW, GetWindowTextLengthW, SetWindowTextW, CreateAcceleratorTableW, SetFocus, GetFocus, DestroyAcceleratorTable, InvalidateRgn, EndPaint, CallWindowProcW, DestroyWindow, FillRect, ReleaseCapture, GetClassNameW, GetParent, IsChild, SetCapture, RedrawWindow, ReleaseDC, DllMain
wininet.dll
InternetCrackUrlA, InternetQueryOptionW, InternetOpenW, InternetCrackUrlW, InternetCloseHandle, InternetConnectW, HttpOpenRequestW, InternetSetOptionW, HttpSendRequestW, InternetReadFile
winmm.dll
mixerGetLineControlsW, mixerSetControlDetails, mixerGetLineInfoW, mixerClose, mixerGetControlDetailsW, mixerOpen
winspool.drv
DocumentPropertiesW, ClosePrinter, OpenPrinterW
ws2_32.dll
WSASend, WSAWaitForMultipleEvents, WSARecv, WSAAccept, WSAEnumNetworkEvents, WSACloseEvent, WSACreateEvent, WSAEventSelect

FBW.exe

FBW Application by AnchorFree Inc (Signed)

Remove FBW.exe
Version:   2, 0, 6, 0
MD5:   dcb25c0714517509fc66cc6f734d77e5
SHA1:   19f3db49275749cfcbf7e86ac9bf91303181e320
SHA256:   385d3c17da0dddf7c24b23c32781df9a6b4f5edef9728a2da9ea7693c6ce471a

About FBW.exe (from AnchorFree Inc)

Hotspot Shield creates a virtual private network (VPN) between your laptop or iPhone and our Internet gateway. This impenetrable tunnel prevents snoopers, hackers, ISP‘s, from viewing your web browsin

Overview

fbw.exe executes as a process with the local user's privileges typically within the context of its parent openvpntray.exe (by AnchorFree Inc). This is typically installed with the program Expat Shield 2.24 published by AnchorFree Inc and is most likely removed by most users once installed (61% removed). The file is digitally signed by AnchorFree Inc which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:fbw.exe
Product name:FBW Application
Typical file path:C:\Program Files\hotspot shield\bin\fbw.exe
File version:2, 0, 6, 0
Size:852.82 KB (873,288 bytes)
Certificate
Issued to:AnchorFree Inc
Authority (CA):VeriSign
Expiration date:Sunday, April 13, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
AnchorFree Inc
  61% remove
Expat Shield is a VPN program that allows users to access UK TV websites such as BBC iPlayer and ITV when outside of the UK. Expat Shield routes your IP address via a UK IP address as if you were still in the UK wherever you are in the world. Normally, the BBC will block any IP address that is outside the UK from accessing its services both online and through the BBC iPlayer program.
Network connections
  • [UDP] listens on port 1293

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    Memory
    Private memory:8.91 MB
    21.59 MB
    Private (maximum):15.86 MB
    Private (minimum):4.91 MB
    Non-paged memory:8.91 MB
    21.59 MB
    Virtual memory:81.73 MB
    140.96 MB
    Virtual memory (peak):94.25 MB
    169.69 MB
    Working set:14.01 MB
    18.61 MB
    Working set (peak):15.86 MB
    37.95 MB
    Resource allocations
    Threads:6
    12
    Handles:248
    600
    GUI GDI count:45
    103
    GUI GDI peak:24
    142
    GUI USER count:26
    49
    GUI USER peak:19
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:32-bit
    Command line:C:\Program Files\expat shield\bin\fbw.exe -sp 896
    Owner:User
    Parent process:openvpntray.exe (by AnchorFree Inc)

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 66.67%
    Windows 7 Ultimate 16.67%
    Windows 7 Professional 16.67%

    Distribution by countryDistribution by country

    United Kingdom installs about 33.33% of FBW Application.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    MSI 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE