File details
File name: ctfmon.exe
Name: CTF Loader
Description: Microsoft® Windows® Operating System
Version: 5.1.2600.5512 (xpsp.080413-2105)
Product version: 5.1.2600.5512
Size: 15 KB
Original file name: CTFMON.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.1178587752%
Privileged CPU:
0.0139516021%

User CPU:
0.10390717304628%

Total CPU time: 6 ms
Total CPU time /min: 1 ms
Privileged CPU time: 5328.35 ms
Privileged CPU time /min: 2 ms
User CPU time: 2.39 ms
User CPU time /min: 0 ms
Context switches /sec:
260
 | Memory utilization averages |
Committed memory:
35.44 MB
Peak committed memory: 38.23 MB
Paged memory:
1.38 MB
Peak paged memory: 1.55 MB
Paged system memory:
56.19 KB
Non-paged system memory: 4.59 KB
Working set memory:
3.08 MB
Peak working set memory: 4.25 MB
Min working set memory: 2.8 MB
Private memory:
1.38 MB
Page faults:
5,150
Page faults /min: 46
 | Process I/O averages |
Total read operations:
8
Read operations /min: 1
Total read transfer: 26.91 KB
Read transfer /min: 92 Bytes
Total write operations:
7
Write operations /min: 1
Total write transfer: 508 Bytes
Write transfer /min: 0 Bytes
Total other operations:
1,562
Other operations /min: 9
Total other transfer: 83.41 KB
Other Transfer /min: 398 Bytes
 | GUI Object Averages |
GDI objects:
55
USER objects:
25
Resources
Handle count average: 114
Thread count average: 1
Thread resource averages
Total CPU: 0.010994164379%
Privileged CPU: 0.007829286777%
User CPU: 0.003164877602%
Context switches /sec: 7
Module memory size: 24 KB
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Parent Processes
Process Commands
ctfmon.exe
"C:\WINDOWS\system32\ctfmon.exe"
"C:\Windows\System32\ctfmon.exe"
"C:\WINXP\system32\ctfmon.exe"
ctfmon.exe -n
Startup files (user) run details
Name: ctfmon.exe
Command: C:\WINDOWS\system32\ctfmon.exe
Network connectivity
Windows Firewall allowed program: Yes
Image hashes
MD5: 5f1d5f88303d4a4dbc8e5f97ba967cc3
SHA-1: 99cb7370f16773c8e2d0c86fe805ec638ab126e9
SHA-256: 5fb24fc7916a6e6b3be7d84cb1684215b266cd1495575c2e5672b8447932e5b1
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.11847
File packed: No
Import Table
advapi32.dll

RegDeleteValueA
RegOpenKeyExA
RegCloseKey
RegSetValueExA
RegCreateKeyA
RegCreateKeyExA
kernel32.dll

lstrcpynA
lstrlenA
GetSystemDirectoryA
GetSystemWindowsDirectoryA
GetVersionExA
GetACP
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
LocalFree
CloseHandle
ResetEvent
OpenEventA
CreateProcessA
lstrcatA
GetSystemInfo
lstrcmpiA
FreeLibrary
LoadLibraryA
CreateEventA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetModuleHandleA
GetStartupInfoA
LocalAlloc
GetProcAddress
RegisterApplicationRestart
GetModuleHandleW
GetCommandLineW
GetStartupInfoW
InterlockedCompareExchange
Sleep
InterlockedExchange
msctf.dll

TF_InitSystem
TF_GetGlobalCompartment
TF_InvalidAssemblyListCacheIfExist
TF_InvalidAssemblyListCache
TF_PostAllThreadMsg
TF_CreateCicLoadMutex
TF_UninitSystem
msctfmonitor.dll

msutb.dll

ClosePopupTipbar
GetPopupTipbar
msvcrt.dll
user32.dll

EnumWindows
GetClassNameA
FindWindowA
PostMessageA
SetTimer
KillTimer
MsgWaitForMultipleObjects
PeekMessageA
TranslateMessage
DispatchMessageA
GetMessageA
SetWindowPos
LoadCursorA
RegisterClassExA
DefWindowProcA
PostQuitMessage
CreateWindowExA
GetSystemMetrics