Autorun Details: Ctfmon

Name: ctfmon
Command: ctfmon.exe
Status: User's choice. Start if necessary.
Description: Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or, for example, if speech is selected as an alternative input for MS Office or Notepad. Required to support advanced text services (such as right to left text) for East Asian users. Can be disabled via Start → Control Panel → Regional and Language Options → Languages → Text Services and Input Languages → Details → Advanced → System Configuration → Turn off advanced text services (which also turns off the language bar). See also here and here. Can also cause problems with some other programs if left enabled - see here for such an example

Name: ctfmon
Command: taskmgr32*.exe [* = number]
Status: Definitely not required. Usually Malware.
Description: Added by the SOWSAT.B WORM!

Name: ctfmon
Command: cftmon.exe
Status: Definitely not required. Usually Malware.
Description: Added by the DELIVE-A BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%

Name: ctfmon
Command: mIRC.dll
Status: Definitely not required. Usually Malware.
Description: Added by the DELBOT-E TROJAN!

Name: ctfmon
Command: WinConst.exe
Status: Definitely not required. Usually Malware.
Description: Added by the ASSASIN-G TROJAN!

Name: CTFMon
Command: ctfmon.exe
Status: User's choice. Start if necessary.
Description: Family KeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in a "CTF" sub-folder

Name: ctfmon
Command: msnmsgr.exe
Status: Definitely not required. Usually Malware.
Description: Added by the BDOOR-JV BACKDOOR! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%

Name: CTFMON
Command: wscript.exe /E:vbs winjpg.jpg
Status: Definitely not required. Usually Malware.
Description: Added by the RUNAUTO.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "winjpg.jpg" file is located in %System%

Name: CTFMON
Command: wscript.exe /E:vbs regedit.sys
Status: Definitely not required. Usually Malware.
Description: Added by the VBSAUTO-A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "regedit.sys" file is located in %System%

Name: CTFMON
Command: win.exe
Status: Definitely not required. Usually Malware.
Description: Added by the VBS.RUNAUTO.G WORM!

Name: Ctfmon
Command: wmisys.exe
Status: Definitely not required. Usually Malware.
Description: Added by the IRCBOT-ADS WORM!

Name: ctfmon
Command: WinUP.exe
Status: Definitely not required. Usually Malware.
Description: Added by the BANKER-VV TROJAN!

Name: ctfmon
Command: ctfmon.exe
Status: Definitely not required. Usually Malware.
Description: Added by the AUTORUN-G WORM! Note - this is not the legitimate ctfmon.exe process associated with alternate language and method inputs which is always located in %System%. This one is located in a "1046" sub-folder

Name: ctfmon
Command: svhost.exe
Status: Definitely not required. Usually Malware.
Description: Added by the BACKDR-EL BACKDOOR!

Back to the autorun list

The autorun list is presented in association with Sysinfo.org

Our Tip: Emsisoft Anti-Malware - Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - June 2009
Read more about the test winner