Information and startup locations can be examined on this page: verify all your files to make sure that they are legitimate, digitally signed and from the company Microsoft Corporation to which they should belong.
ctfmon.exe security and file info
ctfmon.exe
- Microsoft® Windows® Operating System
- Microsoft Corporation
 |
 |
 |
| Filetype : executable |
An executable file is a program that can be executed in your windows environment.
|
|
What is ctfmon.exe?
Ctfmon.exe is the part of Microsoft Office XP and later that is responsible for activating the Alternative User Input Text Input Processor and the Microsoft Office Language Bar. Essentially, it provides support for speech recognition, handwriting recognition, and other types of alternative user input. It may start on system boot, even if no other Microsoft Office applications are running.
This is a nonessential process that can safely be terminated as long as there are no Microsoft Office programs running. It is not recommended to terminate it while a Microsoft Office application is running or if you are using handwriting recognition, speech recognition, the language bar, or any other type of alternative user input. If you do not need the functionality this process provides and wish to permanently eliminate it, you can remove Alternative User Input support from your installation of Microsoft Office via the Add/Remove Programs control panel.
Dangers of ctfmon
As this is a process that runs on most Windows systems that have Microsoft Office installed, it is common for virus writers and spyware vendors to disguise their malware as the genuine ctfmon.exe.
Some malicious files will have the same name as this process but will be stored somewhere other than in %SystemRoot%\System32. Other malware will use a name that appears similar to that of the legitimate process but with slight differences in spelling or with appended digits. The following malware is known to disguise itself as ctfmon.exe:
- SpyHoax-A
- This is a trojan horse that attempts to convince the user to download SpySheriff, which claims to be anti-spyware software.
- Infostealer.Raidys
- This is a trojan horse that attempts to steal confidential information from an infected system.
- CTFMONB (ctfmon.exe or ctfmonb.exe)
- CTFMONB is a trojan horse that displays a blue screen with a yellow warning. Soon after, roaches appear on the screen, appearing to eat it. Once the roaches finish eating the screen, the system may restart.
- Ctfmon32.exe
- This filename is used by various spyware applications and viruses. If you see this filename, run a full virus and spyware scan immediately.
There will typically be only one copy of this process running at a given time. If more copies than this are running, one of the instances may be malware.
Common problems
- Ctfmon.exe continues running after closing all Microsoft Office applications
- This normal behavior. If you wish to eliminate the process, follow the instructions above.
- The active window occasionally loses focus
- If you do not need ctfmon.exe, uninstalling Alternative User Input should correct this problem.
|
|
|
|
|
|
| MD5 File security rating |
A MD5 hash is a unique fingerprint of a file.
Different files/versions can have the same filenames. The MD5 hash verifies that the legitimate file is not altered.
Runscanner (Freeware) can help you checking the file's MD5 hashes
| Ctfmon.exe files in Runscanner database |
 |
|
313 different item(s) in database |
 |
|
2 different item(s) in database |
 |
|
1 different item(s) in database |
 |
|
167 different item(s) in database |
|
 |
Green items are verified safe to use |
 |
Unrated items are not yet checked for safety. |
 |
Red items are not safe (typically virusses, spyware or other malware) |
 |
This file is digitally signed by it's publisher.
This means that the file is from the company claiming to created it, this does not mean by default that the file is safe
|
|
|
|
| General file info |
| Product name: |
Microsoft® Windows® Operating System
|
| Description: |
ctfmon.exe
|
| Company: |
Microsoft Corporation
|
| Fix CTFMON.EXE errors: Free registry scan |
|
|
|
| Pacman startup database |
|
CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example |
|
Family Keylogger is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Keystroke logger/monitoring program - remove unless you installed it yourself! Found in the SystemCTF (9x/Me) or System32CTF (NT/2K/XP) folder |
|
Added by the RAIDYS TROJAN! Note - this should not be confused with the valid Office XP file, see here |
| info provided by sysinfo.org |
|
|
|
Automatic startup locations
 |
| |
 |
001 Running Processes |
| |
 |
002 Autorun registry entries local machine |
| |
 |
003 Autorun registry entries Current User |
| |
 |
004 All users startup startmenu |
| |
 |
005 Current user startup startmenu |
| |
 |
007 Roaming Start Menu\Programs\Startup |
| |
 |
008 Autorun registry entries Default user |
| |
 |
009 Autorun registry entries SYSTEM user |
| |
 |
010 Installed services |
| |
 |
050 Explorer ShellExecuteHooks |
| |
 |
052 Explorer Browser Helper Objects (BHO) |
| |
 |
067 Winlogon notify |
| |
 |
166 HKCU Policies\Explorer\Run |
User comments for this file
 |
It's part of Microsoft's Office Suite. Google how to remove it permanently from your system - it's not mandatory |
|
|
|
More system processes
|
|
| Filename / Process |
|
| Guid / CLSID |
|
| MD5 hash |
|
|
|
483 MD5 version(s) found
only top 10 displayed
|
|
|
| Check your autostart files
|
|
|
|