Known-Malware Check
Scope and Limitations
Last updated: July 30, 2026
When Forward to Safety checks a computer, part of what it does is look for files that match malware seen in real attacks. This page states exactly what that check covers, so that a result of “no known malware found” in your report means something specific rather than something reassuring.
This is not antivirus software. It does not run continuously, does not watch programs as they execute, and does not remove, quarantine, or block anything. It is a point-in-time check performed while the scan runs, and it does not replace antivirus software or any other protective measure on your computer.
How the check works
We calculate a fingerprintof each file in scope — three standard mathematical digests of the file's contents — and compare those fingerprints against threat-intelligence databases of files confirmed to be malicious. A file is reported only when its fingerprint is an exact match.
The contents of your files never leave your computer. Only the fingerprints are transmitted, and a fingerprint cannot be turned back into the file it came from. The comparison itself is performed on our servers rather than on your computer, because a computer that has been compromised cannot be trusted to report honestly on its own condition.
What we examine
We fingerprint the files that start automaticallyon the computer. That is where software installs itself to survive a restart, and it is a small, well-defined set — typically fewer than two hundred files. Specifically:
Programs set to run at sign-in
The Windows registry keys that launch programs when the computer starts or a person signs in — for every user account signed in to the computer, and including the separate locations used by 32-bit and 64-bit programs.
The Windows sign-in programs
The two entries Windows itself uses to start the desktop shell and the sign-in process — classic targets for replacement.
Libraries loaded into every window
The registry setting that forces a code library to load into every program that shows a window.
Program-launch redirections
Registry entries that hijack the launch of a named program and run something else in its place.
Windows services
The program file behind every installed service, whether or not the service is currently running.
Scheduled tasks
The program each scheduled task is configured to launch. We read the program path only, not the rest of the task's configuration.
The Startup folders
The shared Startup folder and each user account's own Startup folder. Files sitting directly in those folders only — we do not descend into sub-folders.
Sign-in entries are read for every user account whose profile is loaded at the time of the scan — not only the account running it — so the same locations are covered whether a person starts the check themselves or it runs unattended on a schedule. The profile of a user who is not signed in at that moment cannot be read without modifying the computer, which this tool never does; their Startup folder is still examined.
What we do not examine
This is not a full-disk scan and is not intended to be one. We do not read, open, or fingerprint:
- Documents, photos, downloads, and everything else in personal folders
- Email messages, attachments, and mail storage files
- Web browser profiles, extensions, history, and saved data
- Installed programs generally — only the ones set to start automatically
- Files on network drives, shared folders, or removable media such as USB drives
- Anything running only in memory, and anything that leaves no file behind
Files on network drives and removable media are excluded deliberately: reading them can stall for a long time when the drive is slow or disconnected, and a check-up that appears to hang the computer is worse than one with a stated boundary.
Limits on the check itself
The check runs on a working computer, often while someone is using it, so it is deliberately bounded. It will skip files it would otherwise fingerprint when:
- a file is unusually large (over 32 MB), or the check has already read a large total volume, or it has already run for a sustained period
- a file is in use, has been removed, or the account running the check is not permitted to read it
- the number of automatically-starting programs on the computer is extraordinarily high
When this happens, your report says so. A report that could not fingerprint every file in scope states how many were checked out of how many were found, rather than describing the check as complete.
If the comparison against threat-intelligence databases cannot be completed at all — because the service is unreachable, for example — the report says the check could not be performed. It never reports an unperformed check as a clean one.
What “no known malware found” means
It means that at the moment of the scan, the files in the scope described above did not match any file in the threat-intelligence databases we checked against.
It does not mean the computer is clean. In particular:
- Only knownmalware can match. Newly created malware, and malware altered even slightly so that its fingerprint differs, will not match — and altering a file to change its fingerprint is trivial and routine.
- Malware that does not start automatically, or that hides somewhere outside the locations listed above, is not examined.
- Threat-intelligence databases are incomplete by nature. A file being absent from them is not evidence that the file is safe.
- The result describes the moment the scan ran. It says nothing about the computer before or after that moment.
A match, on the other hand, is a strong signal and should be treated seriously. It means a file on the computer is byte-for-byte identical to one recorded in a threat-intelligence database. There are two kinds of match, and your report says which one you have, because they do not support the same conclusion:
- An identified sample. The record names the malware family the file belongs to. This is the stronger of the two: the file has been analysed and identified, not merely observed.
- A file seen being distributed by attackers. The record shows the file was served from a web address known to distribute malware, but does not name what it is. That is serious and worth acting on, but it is not the same as identifying the file, and we do not describe it as though it were.
We say which kind of match you have rather than reporting both with the stronger wording. The majority of records in these databases are of the second kind.
This scope may change as we extend the check to additional locations. Material changes will be reflected on this page. See Terms of Service §2.5 for the contractual terms covering this check, and Privacy Policy for how scan data is handled.
