VersionsVersions

6.2.9200.16384 (win8_rtm.120725-1247) 0.21%
6.2.9200.16384 (win8_rtm.120725-1247) 0.21%
6.1.7600.16385 (win7_rtm.090713-1255) 0.82%
6.1.7600.16385 (win7_rtm.090713-1255) 0.82%
6.0.6000.16386 (vista_rtm.061101-2205) 0.21%
6.0.6000.16386 (vista_rtm.061101-2205) 0.21%
5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 62.27%
5.1.2600.5512 (xpsp.080413-2105) 1.65%
5.1.2600.5512 (xpsp.080413-2105) 1.44%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 1.86%
5.1.2600.5512 (xpsp.080413-2105) 2.27%
5.1.2600.5512 (xpsp.080413-2105) 0.41%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 2.06%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 1.03%
5.1.2600.5512 (xpsp.080413-2105) 1.65%
5.1.2600.5512 (xpsp.080413-2105) 1.03%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.41%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.3311 (xpsp.080212-0004) 0.41%
5.1.2600.3300 (xpsp.080125-2028) 0.21%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 11.96%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.21%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.41%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.21%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.21%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.21%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.21%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.21%

Relationships

CTFMON.exe

CTF Loader by Microsoft

Remove CTFMON.exe
This is a Windows system installed file with Windows File Protection (WFP) enabled.
Warning 14 antivirus scanners has detected malware in various versions of CTFMON.exe.

Overview

There are 50 versions of ctfmon.exe in the wild, the latest version being 6.2.9200.16384 (win8_rtm.120725-1247). ctfmon.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. The average file size is about 19.89 KB. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 1.37 MB with the maximum memory reaching around 4 MB. Addionally, typically read and write I/O disk operations is about 170 Bytes per minute for reads and 0 Bytes per minute for writes.

What is ctfmon.exe?

CTF Loader, a Microsoft Windows process relating to the ctfmon.exe file, which monitors active windows and provides text support for speech and handwriting recognition, keyboard, translation, and other technologies.

DetailsDetails

File name:ctfmon.exe
Publisher:Microsoft Corporation
Product name:CTF Loader
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\ctfmon.exe

BehaviorsBehaviors

(Note, the behaviors below are for all versions of ctfmon.exe, select a unique version for details.)
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'ctfmon.exe' → C:\WINDOWS\system32\ctfmon.exe
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\ctfmon.exe'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 14 of them detected the following malware.
Antivirus engineEngine versionDetectionFile version
eSafe 7.0.17.0 Win32.Banker 5.1.2600.5512 (xpsp.080413-2105)
eSafe 7.0.17.0 Win32.Banker 5.1.2600.5512 (xpsp.080413-2105)
Kingsoft 2013.1.8.219 Win32.Malware.Generic.a.(kcloud) 5.1.2600.5512 (xpsp.080413-2105)
Kingsoft 2013.4.9.267 Win32.Malware.Generic.a.(kcloud) 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.62.0.140 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.70.0.9 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.62.0.140 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.70.0.9 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.75.0.1 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.75.0.1 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.75.0.1 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Malwarebytes 1.75.0.1 Trojan.FakeMS 5.1.2600.5512 (xpsp.080413-2105)
Symantec 20121.3.0.76 WS.Reputation.1 5.1.2600.5512 (xpsp.080413-2105)
Vba32 AntiVirus 3.12.16.4 Trojan.Patched.al 5.1.2600.3300 (xpsp.080125-2028)

VersionsAll file variations of ctfmon.exe

MD5SHA-1File size
78a83b17f5dda47fac0b0643456f7bac 132dbae4869b043bdd7db9a56062bd22c15e9153 9.5 KB
7978b91b70462045b01f114223fa5871 2ea2cef5d1d67f93964611d0f0092be5f6a903f0 10 KB
42b6a94dd747df2b5f628a2752e62a98 8ee03b706ea8c0142cd3140ac15f901d479a0b4d 9.5 KB
4a3cdcef8ed41b221f3dbef5792fb52d 6c04499f7406e270b590374ef813c4012530273e 8.5 KB
22bfd03df51065a9ed8d17f8fb72296b 9fa4c29a69b3224670d0d3f28df2f3655f3c31c0 8.5 KB
7e370df3743b39cd375c52f7995783c4 d8c094a8230b8fdf2a52fd01524b8af733dda70f 9.5 KB
5017cac616d0215ad82e63500cd7cb76 7ab6255d91379c6dee9a1799b8a3709f592b6203 20.5 KB
5f1d5f88303d4a4dbc8e5f97ba967cc3 99cb7370f16773c8e2d0c86fe805ec638ab126e9 15 KB
b5dc70bb43a14093e00c5a735cc5dfd4 38e961dc3403743c7b5af1deb32ab93e6203bba5 15 KB
c1d50243355a290cb3aa684fd8b38170 b300d96d548b380a45008026393228da4927f568 39.5 KB
07f27822a1376c2da7f8c7265015cedc fa93d393175b3ee7fcccd4e4690869733f9a3864 15 KB
59dc5bb82e4c8e0b3eadcfdbc44ba6e4 35c39ea5a43cdffeec150e00593e4e838a964458 15 KB
daae1cb1b1875b760496e7d3336da1ad 27ae077066eaaa03ec36748276e1591ce642751b 15 KB
f089e5f41489a3161f068b61b8484712 aeac6a5716248b89afe001df8ff2399526d48071 39.5 KB
b5e8782d4af1b3756f38e11e7c157bbe 5a294662d1e3751427aeacedf272743205832062 24.5 KB
0d17d896b613f169f7041e020e09d21c d4cb38f99b640d2d0d961e8cb6697aba32c565e4 25 KB
c314b6b3589d3a71efd4405f597ec248 0a482bc81b53fcb0d9ec4a07736b52454e84dc97 29.5 KB
b8b35f99dadaa5459fba639f20045fe2 071abaec03948f328d846dc62620601bc043d3e0 29.5 KB
a756b8f0f7bafba6dfe39f7d169f2519 6c899bd5b72a56177babbfb0ba2ccc2dffc24658 15 KB
252f972131eb23596c20b82ca190dc5c 225799035f5f0bfed3e6c177def99056ceb1b176 15 KB
01b4e6e990b6c5ea8856d96c7fd044b2 40ff417a5e7043723911131c29a3914a9c478cde 15 KB
8c7c0b7838c45c009ca080c3efd60342 20e13780adc753b24cac2a6ee85182a28a0b0417 15 KB
e98a8c802cdb31fcf4121d9dfbea3677 1f88d868f7edfec74edfe56893c785eac8186241 15 KB
4e486adfe3a0b9ed0eb0639902e9f64f 884532a3b2e32efef40166f43ac9ad8b48b7082f 15 KB
4d9a9a3ebdd3193531b98fd96c2a9fb8 269a6626a5b471e167b67c458275207f0e7907fa 15 KB
9a2cd21b28bc41e8cdf22083c277dd8f 2a0c4fdc233e6fb5f3d18181298bc70e60d19602 15 KB
3fc7cc8501e0dee1563d31a72d77d967 8bbc76bbe3b7a6cb68b1658b58b4620dda79d698 17 KB
e880528acb65c5e05ee7cf83b08464ea 0eec03ea34fde550a2601c83db2af89febd9a7d6 36.5 KB
f602475c9a05bde4908cca670857eae0 1204f841df03f5219292660dfa65883d6b56b65f 29.5 KB
665aa9b770070a3f6c8a0bbbf275aaa3 083e0913e0fafbf2969097fbcb60119b8d7b5025 15 KB
4f7877463d93858b8f6d9b334b263699 6ef9dc4bbe8801ca952195416be36dc249e29bb9 29.5 KB
cb8d8ab9ced50556501014f97a9fa270 2f93afd70cd33b32cf49fa394d722c71d6f232a8 15 KB
0de18690e4223998e471048889f09b8b 666eb2ac17eaf0a38794649f29d3b57a0503cb5f 36.5 KB
ca2d7abfb096e6b32c4ff01862bbbef6 b862771d9717a6ceff5568e4716c59d21ceabe5c 29.5 KB
a620c1f0be509f9f6c73eabf78722bf6 1f2c1e745b17f9fd062685e4fa47d7803602b755 17 KB
4c97cbad0cf9e6263c49cfa57bccaedd bef011ceca017aca6899b7714da8e3656afd42d2 15 KB
adf2752a6e08c470fd49bb548af20cd4 9b6ad12741e8c9b858674007b5b684f7e388b619 15 KB
d8fd74f8e91a89255e708a50f25bfe4c 03bd9e54eb4578d7a2920079e735ed35d0ae4137 36.5 KB
58db2ee838d5b7bad0f7f10a6c920390 3647a9828b88976b57f021f066775fd097ade568 40 KB
4e6787d5662f4bd807903ebf5f4c5ba6 72644f9f27268456ca1585e03841c398b37a9bcf 29.5 KB
a3f00130a3177af0a263ae640dfcfe4c c569572e48bced1a4d7980352d396f8e3e968a1b 15 KB
8324ed41ea4b936fab28e2bf101b7657 4bf62e7f8d80c09e356b8a097a80993f6280ee90 15 KB
24232996a38c0b0cf151c2140ae29fc8 b36d03b56a30187ffc6257459d632a4faac48af2 15 KB
e00dfa816fa5521eb44c5d63109de2a9 c945164b6887b55a2aa433d326ed45798a17890d 39.5 KB
25ecfa69af1563fde8dfd31f9954497a 48570d8c9f076d41496b8f082670d8fb44e1768a 15 KB
e510f9cfe8618b2aa839bac607255e51 3cf9ef2c6984e59f9845fa66847cf7fd9c478644 15 KB
64e41e8fee655b03e3f19ded21ba5118 2b4acaaace339bf841579dfde628f27644d14f7e 15 KB
5584247b568c2e53934873f4b655fe6a a77492cd2a3819b44fd3c074fa584d8f128d051a 15 KB
3bcef6b66827ec0b9923d20e62d067ba 4398bd14f26b2bb0fec638d166ed9e13276ee6a4 15 KB
89b4c9e0a760204257cd09c8859667f7 44989bc5b283ef8ec550989a90034c23a3f5edc1 15 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 93.25%
Windows XP Home Edition 2.00%
Windows XP Professional 1.50%
Windows 7 Home Premium 1.00%
Windows 7 Home Basic 0.50%
Windows Vista Home Premium 0.50%
Microsoft Windows XP Home Edition 0.50%
Windows 7 Ultimate 0.50%
Windows 8 Pro with Media Center 0.25%

Distribution by countryDistribution by country

United States installs about 35.90% of CTF Loader.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 35.12%
Intel 11.31%
Toshiba 8.93%
American Megatrends 8.63%
Compaq 7.14%
Hewlett-Packard 6.55%
GIGABYTE 5.95%
ASUS 5.36%
Sahara 2.98%
Lenovo 2.38%
Gateway 2.38%
Acer 1.49%
Sony 1.19%
MSI 0.60%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE