Autorun Details: CTFMON.EXE

Name: Ctfmon.exe
Command: ctfmon32.exe
Status: Definitely not required. Usually Malware.
Description: CoolWebSearch Ctfmon32 parasite variant

Name: ctfmon.exe
Command: ctfmon.exe
Status: Definitely not required. Usually Malware.
Description: Added by the RAIDYS TROJAN! Note - this overwrites the legitimate ctfmon.exe process associated with alternate text inputs which is located in %System%

Name: ctfmon.exe
Command: msupdate32.exe
Status: Definitely not required. Usually Malware.
Description: Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe

Name: ctfmon.exe
Command: ctfmon.exe
Status: User's choice. Start if necessary.
Description: Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example

Name: ctfmon.exe
Command: ctfmon.exe eminem.exe
Status: Definitely not required. Usually Malware.
Description: Added by the BHARAT.A WORM!

Name: CTFMON.EXE
Command: svchost.exe
Status: Definitely not required. Usually Malware.
Description: Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%

Name: ctfmon.exe
Command: CTFM0N.EXE
Status: Definitely not required. Usually Malware.
Description: Added by the AUTORUN-AYX WORM! Notice the digit "0" in the filename rather than the upper case "o"

Name: ctfmon.exe
Command: ctfmon.exe
Status: User's choice. Start if necessary.
Description: TotalSpy keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %ProgramFiles%\TS Trial

Name: CTFMON.EXE
Command: ctfmon.exe
Status: Definitely not required. Usually Malware.
Description: Added by the VBSP-A WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1126" sub-folder

Back to the autorun list

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner