PDA

View Full Version : Ctfmon.exe malware or not



Mosesthekitty
2008-12-19, 18:53
In Spybot, Tools, System Start up, I came across some concerning info about ctfmon.exe. Both are in the C:/windows/system32 folder.

The database status to the right reads that "is not required, virus, spyware, malware or other resource hog." In the description portion it reads that it is "added by the Raidys trojan. Note; This should not be confused with the valid Office XP file. " . It's listed a second time and under description it reads "Cool Web search parasite variant". That makes me think its malware.

Spybot, Adaware, Norton antivirus, and Spyware Doctor do not pick it up during scans. When I googled it, I found an article stating that if ctfmon.exe is in the system32 folder it's legit. That makes me think they are ok.

So now I'm conflicted. Should I just delete them? Is it some kind of bad malware stealing my passwords?
Thank You in advance , your help is appreciated.

Tom.K
2008-12-19, 20:27
ctfmon.exe in C:\WINDOWS\system32 is legit and you can disable if you want.
MD5 of file: 24232996A38C0B0CF151C2140AE29FC8

These files: ctfmon32.exe, msupdate32.exe in C:\WINDOWS\system32 are threats.

If ctfmon.exe is located in other folders then it's a threat.

About ctfmon.exe from Microsoft Support: Frequently asked questions about Ctfmon.exe (http://support.microsoft.com/kb/282599).

Mosesthekitty
2008-12-19, 21:28
Thanks for the fast response. I appreciate your time.
I'm glad it's not malware but also annoyed that Spybot has it read it is.