Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

9.60.2114 5.00%
9.05.2071 5.00%
9.05.2064 5.00%
9.05.2063 5.00%
9.04.2051 15.00%
9.04.2051 15.00%
9.02.2032 15.00%
9.02.2032 5.00%
8.02.1972 10.00%
8.02.1972 5.00%
6.61.1880 5.00%
5.12.1652 5.00%
4.50.1457 5.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExA, RegQueryValueExA, LookupPrivilegeValueW, RegCreateKeyExW, OpenThreadToken, GetTokenInformation, OpenProcessToken, AdjustTokenPrivileges, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegOpenKeyExW, CreateServiceW, ChangeServiceConfig2W, StartServiceA, RegEnumKeyExA, OpenSCManagerA, RegEnumKeyExW, RegQueryInfoKeyA, RegQueryInfoKeyW, RegCreateKeyExA, RegDeleteKeyA, RegDeleteKeyW, DeleteService, RegSetValueExA, RegDeleteValueA, RegDeleteValueW, ControlService, QueryServiceStatus, CloseServiceHandle, OpenServiceW, GetUserNameA, ConvertSidToStringSidW, LookupAccountNameW
comdlg32.dll
GetOpenFileNameW
gdi32.dll
GdiFlush, SetTextColor, GetStockObject, CreateSolidBrush, Rectangle, CreateRectRgn, SelectClipRgn, SetViewportOrgEx, OffsetViewportOrgEx, GetObjectW, SetBkColor, CreateBitmap, BitBlt, CreateCompatibleDC, DeleteDC, SelectObject, GetDIBits, DeleteObject, CreateDIBSection, GetDeviceCaps, GetCurrentObject, PtInRegion, OffsetRgn, CombineRgn, CreateFontA, SetBkMode, ExtCreatePen, TextOutA, MoveToEx, LineTo, SetDIBitsToDevice, GetRgnBox, GetPixel
gdiplus.dll
GdipDrawLinesI, GdipDrawLineI, GdipSetSmoothingMode, GdipCreateFromHDC, GdipSetStringFormatAlign, GdipSetPenLineJoin, GdipSetPenEndCap, GdipCreateSolidFill, GdiplusShutdown, GdipDrawString, GdipCreateFontFamilyFromName, GdipDeleteGraphics, GdipDeleteStringFormat, GdipCreateStringFormat, GdipDeletePen, GdipCreatePen1, GdipDeleteBrush, GdipAlloc, GdipCloneImage, GdipCreateFont, GdipDeleteFontFamily, GdipCloneBrush, GdiplusStartup, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipSetTextRenderingHint, GdipDeleteFont, GdipFree, GdipGetGenericFontFamilySansSerif, GdipDisposeImage, GdipGetImageWidth, GdipGetImageHeight, GdipCreateBitmapFromFile, GdipDrawRectangleI, GdipFillRectangleI, GdipCreateBitmapFromFileICM
iphlpapi.dll
GetTcpStatistics, GetAdaptersInfo
kernel32.dll
EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, SetEndOfFile, SetEnvironmentVariableA, CompareStringW, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, HeapReAlloc, GetLastError, GetModuleHandleA, InterlockedIncrement, InterlockedDecrement, CloseHandle, DeviceIoControl, GetCurrentThreadId, GetCommandLineW, GetModuleFileNameW, GetShortPathNameW, Beep, Sleep, CreateDirectoryW, FindFirstFileW, FindNextFileW, FindClose, ReleaseMutex, GetTickCount, CreateEventW, CreateMutexW, WaitForSingleObject, ResetEvent, SetEvent, CreateFileW, GetCurrentProcessId, VirtualQuery, GetConsoleMode, GetConsoleCP, SetStdHandle, HeapCreate, InitializeCriticalSectionAndSpinCount, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleFileNameA, HeapSize, IsValidCodePage, GetOEMCP, GetACP, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, GetTimeZoneInformation, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsProcessorFeaturePresent, HeapAlloc, GetCPInfo, LCMapStringW, ExitProcess, HeapFree, GetStartupInfoW, HeapSetInformation, GetCommandLineA, ExitThread, RaiseException, RtlUnwind, DecodePointer, EncodePointer, InterlockedExchange, InterlockedCompareExchange, ReadFile, WriteFile, SetFilePointer, GetStdHandle, GetFileSizeEx, OutputDebugStringA, OutputDebugStringW, MultiByteToWideChar, WideCharToMultiByte, GetLocalTime, GetSystemTime, LoadLibraryW, FreeLibrary, GetProcAddress, GetExitCodeThread, TerminateThread, CreateThread, SetLastError, GetCurrentProcess, CreateProcessW, OpenProcess, GetModuleHandleW, LocalFree, FormatMessageW, GetCurrentThread, GetExitCodeProcess, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, GlobalFree, TerminateProcess, LoadLibraryA, GetSystemDefaultLangID, GetSystemInfo, GetVersionExW, GetLocaleInfoW, GetFileAttributesW, SetFileAttributesW, FileTimeToSystemTime, FileTimeToLocalFileTime, GetFileTime, DeleteFileW, GetWindowsDirectoryW, GetSystemDirectoryW, GetCurrentDirectoryW, FlushFileBuffers, MoveFileW, CopyFileW, CompareFileTime, GetFileAttributesExW, SetCurrentDirectoryW, GetFullPathNameW, GetConsoleScreenBufferInfo, GetFileType, WriteConsoleW, ResumeThread, WaitForMultipleObjects, ReadProcessMemory, QueryPerformanceCounter, SetThreadPriority, GetThreadPriority, QueryPerformanceFrequency, GetSystemTimeAsFileTime, GetStringTypeW, CompareStringA, GetConsoleOutputCP, WriteConsoleA, VirtualAlloc, VirtualFree, GetStringTypeA, LCMapStringA, GetCurrentDirectoryA, FindNextFileA, CreateFileA, DeleteFileA, MoveFileA, GetFileAttributesA, SetFileAttributesA, GetSystemDirectoryA, GetWindowsDirectoryA, GetVersionExA, SetCurrentDirectoryA, GetFullPathNameA, LocalHandle, LocalLock, LocalAlloc, FormatMessageA, FindFirstFileA, CreateProcessA, SetFileTime, SystemTimeToFileTime, GetUserDefaultLangID, MulDiv, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, ReadConsoleW, SetFilePointerEx, LoadLibraryExW, GetProcessHeap, EnumSystemLocalesW, GetModuleHandleExW, GetComputerNameA, MoveFileExW, GetComputerNameW, SetConsoleCursorPosition
msimg32.dll
AlphaBlend
ole32.dll
CoTaskMemFree, CoCreateInstance, CoRevertToSelf, CoImpersonateClient, CoRegisterClassObject, CoRevokeClassObject, CoUninitialize, CoInitialize, CoTaskMemAlloc, StringFromCLSID
rasapi32.dll
RasHangUpA
rpcrt4.dll
UuidCreate
setupapi.dll
SetupCopyOEMInfW
shell32.dll
ShellExecuteW, ShellExecuteExW, Shell_NotifyIconW, SHGetFolderPathW, SHGetMalloc, SHGetSpecialFolderPathW, SHGetPathFromIDListW, SHGetSpecialFolderLocation, ShellExecuteA, ShellExecuteExA, SHGetPathFromIDListA, Shell_NotifyIconA
user32.dll
GetForegroundWindow, RegisterDeviceNotificationW, LoadImageW, GetWindowThreadProcessId, PostMessageW, GetKeyState, FillRect, InvalidateRect, SendInput, MessageBoxW, FindWindowW, SendMessageA, LoadCursorA, CharToOemA, MessageBoxA, SendMessageW, GetWindowLongA, GetClassNameA, MessageBoxIndirectW, EnumChildWindows, GetSystemMetrics, DestroyIcon, RegisterWindowMessageA, ReleaseDC, GetDC, SetWindowPos, OffsetRect, DispatchMessageA, TranslateMessage, IsDialogMessageA, GetMessageA, CreateIcon, ChildWindowFromPointEx, GetWindowRect, FindWindowA, PtInRect, IsRectEmpty, GetCursorPos, SetCursor, UnregisterClassW, SetClassLongW, GetClassLongW, SetWindowLongW, DestroyWindow, CreateWindowExW, SetForegroundWindow, ShowWindow, ShowWindowAsync, SetCapture, ReleaseCapture, GetWindowLongW, RegisterClassExW, AppendMenuW, DestroyMenu, TrackPopupMenu, RemoveMenu, IntersectRect, SubtractRect, UnionRect, SystemParametersInfoA, EqualRect, SetWindowLongA, GetWindowTextA, GetWindowTextW, GetClassNameW, EnumWindows, ScreenToClient, BeginPaint, EndPaint, GetUpdateRect, GetShellWindow, GetMonitorInfoA, MonitorFromRect, EnableWindow, UnregisterDeviceNotification, CreatePopupMenu, GetDesktopWindow, GetMenuItemCount, SetMenuDefaultItem, PostMessageA, PostQuitMessage, DefWindowProcW, SetClassLongA, GetClassLongA, DefWindowProcA, GetWindowModuleFileNameA, GetWindowModuleFileNameW, UnregisterClassA, LoadImageA, CreateWindowExA, AppendMenuA, RegisterClassExA, MessageBoxIndirectA, GetParent, DrawTextA, IsWindowVisible, GetWindowRgn, SetWindowRgn, ClientToScreen, CharToOemBuffA
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
winmm.dll
timeBeginPeriod, timeGetDevCaps, timeEndPeriod, timeGetTime

cfosspeed.exe

cFosSpeed Window by cFos Software GmbH (Signed)

Remove cfosspeed.exe
Version:   8.02.1972
MD5:   55e316712fc1af5e9aa00b200a0681ca
SHA1:   526ef66bcf84d4ad635b57dbabdae5662fdc1bdb
SHA256:   f47580916a9451d989616dd5b4fa10c5b0c53ae9677abbeb67353db68e7918f8

Overview

cfosspeed.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program cFosSpeed v8.02 published by cFos Software GmbH, Bonn. The file is digitally signed by cFos Software GmbH which was issued by the GlobalSign nv-sa certificate authority (CA).

DetailsDetails

File name:cfosspeed.exe
Publisher:cFos Software GmbH
Product name:cFosSpeed Window
Typical file path:C:\Program Files\cfosspeed\cfosspeed.exe
File version:8.02.1972
Size:1.23 MB (1,293,224 bytes)
Certificate
Issued to:cFos Software GmbH
Authority (CA):GlobalSign nv-sa
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
cFos Software GmbH, Bonn
5% remove
cFosSpeed is a software solution for traffic shaping for the Windows operating system. It improves Internet latency while maintaining high transfer rates. The program attaches itself as a device driver to the Windows network stack where it can then perform packet inspection and layer-7 protocol analysis. As such, it is particularly often used by online gamers and VoIP users.

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'XFast LAN' → C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe
  • 'cFosSpeed' → C:\Program Files\cFosSpeed\cFosSpeed.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.05017962%
0.028634%
Kernel CPU:0.03136226%
0.013761%
User CPU:0.01881736%
0.014873%
Kernel CPU time:390 ms/min
100,923,805ms/min
Memory
Private memory:3.65 MB
21.59 MB
Private (maximum):7.74 MB
Private (minimum):7.45 MB
Non-paged memory:3.65 MB
21.59 MB
Virtual memory:77.68 MB
140.96 MB
Virtual memory (peak):81.68 MB
169.69 MB
Working set:7.75 MB
18.61 MB
Working set (peak):8.79 MB
37.95 MB
Resource allocations
Threads:6
12
Handles:154
600
GUI GDI count:60
103
GUI GDI peak:64
142
GUI USER count:18
49
GUI USER peak:19
71

BehaviorsProcess properties

Tray notification:Yes
Integrety level:Medium
Platform:32-bit
Command line:"C:\Program Files\cfosspeed\cfosspeed.exe"
Owner:User
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 50.00%
Microsoft Windows XP 15.00%
Windows 8 Single Language 10.00%
Windows 8 Pro with Media Center 10.00%
Windows Vista Ultimate 5.00%
Windows 7 Home Premium 5.00%
Windows 7 Professional 5.00%

Distribution by countryDistribution by country

Egypt installs about 20.00% of cFosSpeed Window.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 31.25%
ASUS 25.00%
Toshiba 25.00%
American Megatrends 12.50%
Acer 6.25%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE