BleepingComputer.com: Question about ctfmon.exe

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Question about ctfmon.exe

#1 User is offline   davour 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 01-November 11

Posted 01 November 2011 - 01:31 PM

I have a question regarding this part of the log HijackThis produced:

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

In the StartUps list in this site, there are two entries for something similar to these: This one and this one.

How do I know if these are entries generated by Office XP or by that trojan horse?

Thanks

This post has been edited by Orange Blossom: 02 November 2011 - 02:40 AM
Reason for edit: Moved to Startup Database forum. ~ OB


#2 User is offline   Akashi 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Malware Study Hall Senior
  • Posts: 301
  • Joined: 25-October 11
  • Gender:Male

Posted 03 November 2011 - 03:59 PM

You cannot tell just by looking at that part of the HijackThis log.

The trojan you are referring to overwrites the genuine ctfmon.exe and userinit.exe files with malware files of the same name.

To tell whether a file is infected, you can upload it to an online virus scanner such as VirusTotal or VirSCAN.org

#3 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 03 November 2011 - 04:12 PM

Comments on HJT log are not allowed outside of malware removal forum.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#4 User is offline   Akashi 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Malware Study Hall Senior
  • Posts: 301
  • Joined: 25-October 11
  • Gender:Male

Posted 03 November 2011 - 04:18 PM

Oops, sorry about that. I won't do it again. :thumbup2:

#5 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 03 November 2011 - 04:21 PM

No problem :)
I'm sure you weren't simply aware of it.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#6 User is offline   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,603
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 04 November 2011 - 09:56 PM

Akashi's answer, though, is valid. I am going to make a safe bet and tell you that the ctfmon entry is legit, but the only way to tell is to scan the file with a service like virustotal.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users