Hello AVG Community. I recently bought AVG protection but I think I have a malware. A few days ago I reformatted my hardrive by conducting a factory reset on my windows 7 PC. I ran a full scan recently and no threats were detected. I then proceeded to start a scan in safe mode and everything is fine according to the recults. However, whenever I look at my Task Manager, theres this suspicious process that runs on startup. This process is called "ctfmon.exe". I researched this process and according to http://www.howtogeek.com/howto/windows-vista/what-is-ctfmonexe-and-why-is-it-running/, this process is only used as "Microsoft process that controls Alternative User Input and the Office Language bar. It’s how you can control the computer via speech or a pen tablet, or using the onscreen keyboard inputs for asian languages." I am NOT using the computer via speech, pen tablet, or for keyboard input for asian languages. Also, when I open the file location via the Task Manager, the file path is C:\Windows\SysWOW64 instead of C:\WINDOWS\system32\ctfmon.exe. Is this a Tilebot-JR or IRC backdoor?(http://www.bleepingcomputer.com/startups/ctfmon.exe-18326.html) Here are 2 photos showing I did full system scans in normal mode and safe mode. So the arising question, is this process legit or some type of malware? If so, how can I remove it?
Hello Jonathan. Ctfmon.exe is a legitimate windows process. And for the SysWOW64 folder structure, this is where 32-bit applications are supported on a system running a 64-bit version of Windows. If it is a 64 bit version of Windows you are using, there is nothing unusual happening with this process. To determine whether your OS is a 32-bit or 64-bit, please click on this link. http://support.microsoft.com/en-us/kb/827218 . Please contact us back should you need any further assistance. Thank you.
Ctfmon.exe is a legitimate windows process. And for the SysWOW64 folder structure, this is where 32-bit applications are supported on a system running a 64-bit version of Windows. If it is a 64 bit version of Windows you are using, there is nothing unusual happening with this process. To determine whether your OS is a 32-bit or 64-bit, please click on this link. http://support.microsoft.com/en-us/kb/827218 .
Please contact us back should you need any further assistance. Thank you.