Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.2.9200.16384 (win8_rtm.120725-1247) 0.21%
6.2.9200.16384 (win8_rtm.120725-1247) 0.21%
6.1.7600.16385 (win7_rtm.090713-1255) 0.82%
6.1.7600.16385 (win7_rtm.090713-1255) 0.82%
6.0.6000.16386 (vista_rtm.061101-2205) 0.21%
6.0.6000.16386 (vista_rtm.061101-2205) 0.21%
5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 62.27%
5.1.2600.5512 (xpsp.080413-2105) 1.65%
5.1.2600.5512 (xpsp.080413-2105) 1.44%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 1.86%
5.1.2600.5512 (xpsp.080413-2105) 2.27%
5.1.2600.5512 (xpsp.080413-2105) 0.41%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 2.06%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 1.03%
5.1.2600.5512 (xpsp.080413-2105) 1.65%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteValueA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegCreateKeyA, RegCreateKeyExA
kernel32.dll
lstrcpynA, lstrlenA, GetSystemDirectoryA, GetSystemWindowsDirectoryA, GetVersionExA, GetACP, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LocalFree, CloseHandle, ResetEvent, OpenEventA, CreateProcessA, lstrcatA, GetSystemInfo, lstrcmpiA, FreeLibrary, LoadLibraryA, CreateEventA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, LocalAlloc, GetProcAddress, RegisterApplicationRestart, GetModuleHandleW, GetCommandLineW, GetStartupInfoW, InterlockedCompareExchange, Sleep, InterlockedExchange
msctf.dll
TF_InitSystem, TF_GetGlobalCompartment, TF_InvalidAssemblyListCacheIfExist, TF_InvalidAssemblyListCache, TF_PostAllThreadMsg, TF_CreateCicLoadMutex, TF_UninitSystem
msctfmonitor.dll
DoMsCtfMonitor
msutb.dll
ClosePopupTipbar, GetPopupTipbar
msvcrt.dll
DllMain
user32.dll
EnumWindows, GetClassNameA, FindWindowA, PostMessageA, SetTimer, KillTimer, MsgWaitForMultipleObjects, PeekMessageA, TranslateMessage, DispatchMessageA, GetMessageA, SetWindowPos, LoadCursorA, RegisterClassExA, DefWindowProcA, PostQuitMessage, CreateWindowExA, GetSystemMetrics

CTFMON.exe

CTF Loader by Microsoft

Remove CTFMON.exe
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   24232996a38c0b0cf151c2140ae29fc8
SHA1:   b36d03b56a30187ffc6257459d632a4faac48af2
SHA256:   d2fed8ccae118f06fd948a4b12445aa8c29a3e7bb5b6fe90970fbc27f426f0b0
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is CTFMON.exe?

CTF Loader, a Microsoft Windows process relating to the ctfmon.exe file, which monitors active windows and provides text support for speech and handwriting recognition, keyboard, translation, and other technologies.

Overview

ctfmon.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. This version is installed on Windows XP and is compiled as a 32 bit program.

DetailsDetails

File name:ctfmon.exe
Publisher:Microsoft Corporation
Product name:CTF Loader
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\ctfmon.exe
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:15 KB (15,360 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:6.118468
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'ctfmon.exe' → C:\WINDOWS\system32\ctfmon.exe
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\ctfmon.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00798533%
0.028634%
Kernel CPU:0.00469650%
0.013761%
User CPU:0.00328883%
0.014873%
Kernel CPU time:146 ms/min
100,923,805ms/min
Context switches:10/sec
284/sec
Memory
Private memory:1.29 MB
21.59 MB
Private (maximum):3.58 MB
Private (minimum):2.86 MB
Non-paged memory:1.29 MB
21.59 MB
Virtual memory:32.94 MB
140.96 MB
Virtual memory (peak):37.56 MB
169.69 MB
Working set:3.01 MB
18.61 MB
Working set (peak):3.86 MB
37.95 MB
Page faults:1,605/min
2,039/min
I/O
I/O read transfer:142 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O other transfer:913 Bytes/sec
448.09 KB/min
I/O other operations:4/sec
1,671/min
Resource allocations
Threads:1
12
Handles:96
600
GUI GDI count:42
103
GUI USER count:19
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • ctfmon.exe
  • "C:\Windows\System32\ctfmon.exe"
Owner:User
Parent processes:

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 97.00%
Windows 7 Home Premium 1.00%
Windows Vista Home Premium 1.00%
Windows 7 Home Basic 0.50%
Windows 8 Pro with Media Center 0.50%

Distribution by countryDistribution by country

United States installs about 29.23% of CTF Loader.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 30.33%
Intel 12.30%
Toshiba 10.66%
American Megatrends 9.84%
Hewlett-Packard 6.97%
GIGABYTE 6.56%
Compaq 6.56%
ASUS 4.92%
Sahara 3.69%
Lenovo 3.28%
Gateway 2.46%
Acer 1.64%
Sony 0.82%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE