Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

16.4.3505.0912 50.00%
15.4.3555.0308 50.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
TraceMessage, EqualSid, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, RegGetValueW, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, LookupAccountSidW, ConvertSidToStringSidW, LookupAccountNameW, CreateWellKnownSid, GetLengthSid, CopySid, ConvertStringSidToSidW, FreeSid, AllocateAndInitializeSid, LogonUserW, RegCreateKeyExW, RegDeleteKeyW, RegDeleteValueW, RegEnumKeyExW, RegEnumValueW, CheckTokenMembership, CloseServiceHandle, OpenServiceW, OpenSCManagerW, ControlService, QueryServiceStatus, ChangeServiceConfigW, IsValidSid, IsWellKnownSid, EventWrite
crypt32.dll
CryptProtectData, CryptUnprotectData
fwpuclnt.dll
FwpmSubLayerDeleteByKey0, FwpmEngineOpen0, FwpmTransactionBegin0, FwpmEngineClose0, FwpmTransactionCommit0, FwpmTransactionAbort0, FwpmFilterDeleteByKey0, FwpmCalloutDeleteByKey0
gdi32.dll
DeleteObject, GetStockObject, GetObjectW, CreateSolidBrush, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, DeleteDC
gdiplus.dll
GdiplusStartup, GdipCloneImage, GdipCreateHBITMAPFromBitmap, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromFile, GdipDisposeImage, GdipAlloc, GdipFree, GdiplusShutdown
kernel32.dll
FlushInstructionCache, GetCurrentProcess, lstrcmpW, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, SetLastError, HeapSetInformation, SetDllDirectoryW, GlobalFree, LoadLibraryW, MultiByteToWideChar, lstrlenA, GlobalHandle, HeapFree, GetProcessHeap, HeapAlloc, HeapReAlloc, FormatMessageW, CreateFileW, GetTempPathW, GetLocaleInfoW, GetSystemTimeAsFileTime, GetProcAddress, FreeLibrary, GetThreadUILanguage, WideCharToMultiByte, CreateThread, SetThreadPriority, TlsGetValue, TlsSetValue, GetModuleHandleW, GetTickCount, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, InterlockedIncrement, InterlockedDecrement, GetCurrentThreadId, InitializeSRWLock, AcquireSRWLockShared, ReleaseSRWLockShared, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, EnterCriticalSection, LeaveCriticalSection, LocalFree, GetLastError, ProcessIdToSessionId, GetCurrentProcessId, InterlockedExchange, InitializeConditionVariable, Sleep, WaitForSingleObject, WakeAllConditionVariable, SleepConditionVariableSRW, SystemTimeToFileTime, GetComputerNameW, CompareFileTime, CloseHandle, GetProcessId, GetModuleFileNameW, OpenProcess, lstrlenW, RaiseException, InitializeCriticalSection, DeleteCriticalSection, CompareStringW, HeapDestroy, HeapSize, InterlockedCompareExchange, LoadLibraryA, IsProcessorFeaturePresent, GetTickCount64, GetFileAttributesW, CreateMutexW, IsWow64Process, GetVersionExW, VirtualUnlock, VirtualLock, TrySubmitThreadpoolCallback, CallbackMayRunLong, CreateThreadpool, SetThreadpoolThreadMinimum, SetThreadpoolThreadMaximum, CloseThreadpool, ConvertFiberToThread, WaitForMultipleObjectsEx, OpenThread, QueueUserAPC, IsThreadAFiber, TlsFree, TlsAlloc, ResetEvent, SetEvent, CreateEventW, LocalAlloc, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, VirtualFree, VirtualAlloc, GetStartupInfoW, SetUnhandledExceptionFilter, ReleaseMutex
msvcr90.dll
DllMain
netapi32.dll
NetUserGetLocalGroups, NetLocalGroupAddMembers, NetUserDel, NetUserAdd, NetApiBufferFree, NetGetJoinInformation, NetUserEnum
ole32.dll
CoInitializeSecurity, CLSIDFromProgID, CLSIDFromString, CoTaskMemAlloc, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoCreateGuid, CoTaskMemFree, CoSetProxyBlanket, CoCreateInstance, CoUninitialize, CoInitializeEx, CoAllowSetForegroundWindow, StringFromGUID2, OleLockRunning, CoGetClassObject
secur32.dll
GetUserNameExW
shell32.dll
SHAppBarMessage, CommandLineToArgvW, Shell_NotifyIconW, FindExecutableW, ShellExecuteW, SHGetKnownFolderPath, ShellExecuteExW, SHFileOperationW, SHGetFolderPathW
shlwapi.dll
UrlCanonicalizeA, PathCombineW, PathFileExistsW, PathAppendW, StrRChrW
user32.dll
SetWindowLongW, GetWindowLongW, AttachThreadInput, PostQuitMessage, GetForegroundWindow, SetProcessDefaultLayout, SetFocus, SetForegroundWindow, GetSysColor, CharNextW, GetClientRect, ClientToScreen, ScreenToClient, GetDC, ReleaseDC, InvalidateRect, InvalidateRgn, RedrawWindow, UnregisterClassA, SetCapture, IsChild, GetParent, GetDlgItem, GetClassNameW, ReleaseCapture, FillRect, CallWindowProcW, EndPaint, BeginPaint, GetDesktopWindow, DestroyAcceleratorTable, GetWindow, GetFocus, RegisterWindowMessageW, GetClassInfoExW, RegisterClassExW, CreateWindowExW, CreateAcceleratorTableW, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, CloseClipboard, FindWindowW, OpenClipboard, GetKeyState, PtInRect, GetCursorPos, ShowWindow, UpdateLayeredWindow, EndDialog, MapDialogRect, SendDlgItemMessageW, SetWindowContextHelpId, GetMonitorInfoW, MonitorFromWindow, DialogBoxIndirectParamW, EmptyClipboard, CallNextHookEx, SetWindowsHookExW, UnhookWindowsHookEx, AppendMenuW, DestroyMenu, CreatePopupMenu, TrackPopupMenu, UnregisterClassW, IsIconic, ChangeWindowMessageFilter, LoadIconW, MsgWaitForMultipleObjects, IsWindowUnicode, GetMessageW, GetMessageA, TranslateMessage, DispatchMessageW, DispatchMessageA, PeekMessageW, AllowSetForegroundWindow, DestroyIcon, SendMessageW, SystemParametersInfoW, MoveWindow, GetWindowRect, SetWindowPos, SetTimer, PostMessageW, SetClipboardData, GetWindowThreadProcessId, KillTimer, DefWindowProcW, LoadCursorW, IsWindow, DestroyWindow, SetCursor
uxcore.dll
DllMain
wininet.dll
InternetCrackUrlA, InternetCreateUrlA
wlidux.dll
WlidUxInitProcess, WlidUxUninitProcess, WlidUxCreateObject
wtsapi32.dll
WTSUnRegisterSessionNotification, WTSRegisterSessionNotification, WTSFreeMemory, WTSEnumerateSessionsW, WTSQuerySessionInformationW

fsui.exe

Windows Live Family Safety Filter by Microsoft Corporation (Signed)

Remove fsui.exe
Version:   15.4.3555.0308
MD5:   6dcfadda4f2a6d3396d13f0554d672e8
SHA1:   8b543c6423cdd5692b9862f0e7c0a6df6bec847d
SHA256:   5bf61db1b2bed27a286865c4564b6827d57c753a4e401c59d38b1279d84c6152

Overview

fsui.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including Windows Live Essentials published by Microsoft Corporation, Windows Live from Microsoft Corporation and Windows Live by Microsoft Corporation. The file is digitally signed by Microsoft Corporation.

DetailsDetails

File name:fsui.exe
Publisher:Microsoft Corporation
Product name:Windows Live Family Safety Filter
Typical file path:C:\Program Files\windows live\family safety\fsui.exe
File version:15.4.3555.0308
Size:863.85 KB (884,584 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Microsoft Corporation
10% remove
Windows Live Essentials is a suite of freeware applications by Microsoft that aims to offer integrated and bundled e-mail, instant messaging, photo-sharing, blog publishing, and security services. Essentials programs are designed to integrate well with each other, with Microsoft Windows, and with other Microsoft web-based services such as SkyDrive and Outlook.com, so that they operate as a seamless whole.
Microsoft Corporation
9% remove
Windows Live "is a way to extend the Windows user experience". Windows Vista provides a link in its user interface to download Windows Live Messenger, and Windows 7 saw the removal of applications such as Windows Mail, Windows Photo Gallery and Windows Movie Maker and replaced with the Windows Essentials suite, a software package that allows the downloading and installation of similar offerings from Windows Live. Windows Live offers int...
Microsoft Corporation
8% remove
Windows Live is the former collective brand name for a set of services and software products from Microsoft; part of their software plus services platform. A majority of these services are Web applications, accessible from a browser, but there are also client-side binary applications that require installation. There are three ways in which Windows Live services are offered: Windows Essentials applications, web services, and mobile servi...

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'fssui' → "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
Network connections
  • [UDP] listens on port 50588

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00019217%
    0.028634%
    Kernel CPU:0.00006746%
    0.013761%
    User CPU:0.00012470%
    0.014873%
    Kernel CPU time:31,465 ms/min
    100,923,805ms/min
    Memory
    Private memory:36.68 MB
    21.59 MB
    Private (maximum):8.6 MB
    Private (minimum):724 KB
    Non-paged memory:36.68 MB
    21.59 MB
    Virtual memory:154.79 MB
    140.96 MB
    Virtual memory (peak):161.24 MB
    169.69 MB
    Working set:2.92 MB
    18.61 MB
    Working set (peak):33.4 MB
    37.95 MB
    Resource allocations
    Threads:17
    12
    Handles:420
    600
    GUI GDI count:22
    103
    GUI USER count:32
    49

    BehaviorsProcess properties

    Tray notification:Yes
    Integrety level:Medium
    Platform:32-bit
    Command line:"C:\Program Files\windows live\family safety\fsui.exe" -autorun
    Owner:User
    Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    fsui.exe (main module)
    Total CPU:0.00331856%
    0.272967%
    Kernel CPU:0.00226862%
    0.107585%
    User CPU:0.00104994%
    0.165382%
    CPU cycles:31,787/sec
    5,741,424/sec
    Memory:872 KB
    1.16 MB
    ntdll.dll
    Total CPU:0.00200185%
    Kernel CPU:0.00136348%
    User CPU:0.00063838%
    CPU cycles:263,963/sec
    Memory:1.16 MB
    RPCRT4.dll
    Total CPU:0.00126000%
    Kernel CPU:0.00126000%
    User CPU:0.00000000%
    CPU cycles:7,247/sec
    Memory:780 KB
    MSVCR90.dll
    Total CPU:0.00005157%
    Kernel CPU:0.00004689%
    User CPU:0.00000469%
    CPU cycles:526/sec
    Memory:652 KB
    UXCore.dll
    Total CPU:0.00004688%
    Kernel CPU:0.00002344%
    User CPU:0.00002344%
    CPU cycles:524/sec
    Memory:2.4 MB
    ole32.dll
    Total CPU:0.00004219%
    Kernel CPU:0.00003751%
    User CPU:0.00000469%
    CPU cycles:1,019/sec
    Memory:1.27 MB
    winhttp.dll (Windows HTTP Services by Microsoft)
    Total CPU:0.00003438%
    Kernel CPU:0.00002501%
    User CPU:0.00000938%
    CPU cycles:5,331/sec
    Memory:384 KB

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 50.00%
    Windows Vista Home Premium 50.00%

    Distribution by countryDistribution by country

    Mexico installs about 50.00% of Windows Live Family Safety Filter.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Hewlett-Packard 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE