<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Adobe</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/adobe//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>How to safely remove AcroRd32Info.exe</title>
		<link>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</link>
		<comments>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 13:05:00 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Acrobat Reader]]></category>

		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[AcroRd32Info]]></category>

		<category><![CDATA[acrotray]]></category>

		<category><![CDATA[AdobeReader.K]]></category>

		<category><![CDATA[Explorer]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[pdf]]></category>

		<category><![CDATA[prefetching]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/</guid>
		<description><![CDATA[<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package  for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>

<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for  browsing the folder without opening any PDF files yet.</p> 

<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p> 

<p>AcroRd32Info stay in your memory so consider it as a pest. So how to disabled it?</p>
]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/11/acrord32info.jpg' alt='AcroRd32Info' style="float:left;margin-right:3px;margin-bottom: 0px" /><strong><a href="http://www.adobe.com/products/acrobat/readstep2.html">AcroRd32Info</a></strong> is a another creative pieces of crap from <a href="http://www.adobe.com">Adobe</a> a package for Acrobat Reader. Embed in Windows Explorer Shell, its main role is to start an initial prefetching for PDF documents in the Memory.</p>
<p><span id="more-37"></span></p>
<p>To test this program behavior, you will need to open your windows task manager (ctrl+alt+del once) and browse to any folder that contained a PDF documents and stay idle. Within just few seconds <strong>AdobeRd32Info</strong> will be loaded in the background and stay in memory.That was just for browsing the folder without opening any PDF files yet.</p>
<p>Windows has a standard prefetch modes and its fairly stable for most of the applications out there. Having a another background prefetcher hook on explorer is plain abusive not to mention its running without the owner permissions.</p>
<p>Adobe Reader is cheating. Its understable that with this methods it will improve the Acrobat boot time log, but I dont see much differences when its running in the background preparing to load a single PDF documents, its a pollutions.</p>
<p>AcroRd32Info stay in your memory so consider it as a <span class="hilite-3">pestware</span>.</p>
<p>Here&#8217;s how you can <em>safely</em> removed this programs. </p>
<h3 id="removed">The proper way</h3>
<ul>
<li>open <strong>Adobe AcroRd32</strong></li>
<li>Edit &raquo; Preferences </li>
<li>Select the <strong>internet</strong> categories in the menu list then disabled <br /><strong>Allow fast web view</strong> &#038; <strong>Allow speculative downloading in the background</strong></li>
</ul>
<p>If thats doesnt work, you try this <strong>unrecommended</strong> method to disabled it.</p>
<ul>
<li>Browse to Adobe Reader directory usually at &#8220;Program Files\Adobe\Reader\&#8221; </li>
<li>Find <strong>AcroRd32Info.exe</strong></li>
<li>Rename it from <strong>AcroRd32Info.exe</strong> to <strong>Acro_Rd32Info.exe</strong></li>
</ul>
<h2>Recent Exploit on Adobe Reader</h2>
<h3 id="AdobeReaderK">Exploit:W32/AdobeReader.K</h3>
<p class="notice" style="padding:10px;margin:18px auto;border:1px solid #ccc">From FSECURE, <a href="http://blog.kakkoi.net/uri/d3d3LmYtc2VjdXJlLmNvbS92LWRlc2NzL2V4cGxvaXRfdzMyX2Fkb2JlcmVhZGVyX2suc2h0bWw.curie,80,302" rel="external" title="External site">Exploit:W32/AdobeReader.K</a> is detection of a malicious PDF file that is being heavily spammed through e-mail and it appears as an attachment.<br />
This malicious PDF file takes advantage of a vulnerability on the URI handling of PDF files. This vulnerability affects IE7, Adobe Acrobat, and Adobe Reader on some platforms.<br />
Users should update their Adobe Reader installations. </p>
<h3>Affected Software Versions</h3>
<p>Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier. Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier.</p>
<p>More info on this exploits at <a href="http://blog.kakkoi.net/uri/bnZkLm5pc3QuZ292L252ZC5jZm0_Y3ZlbmFtZT1DVkUtMjAwNy01MDIw.curie,80,302">National Vulnerability Database</a></p>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/windows/how-to-safely-removed-acrord32infoexe-adobe-reader/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove Adobe Version Cue CS3</title>
		<link>http://42.kaizeku.com/adobe/adobe-photoshop-cs3-removed-bonjour/</link>
		<comments>http://42.kaizeku.com/adobe/adobe-photoshop-cs3-removed-bonjour/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 15:22:35 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Bonjour]]></category>

		<category><![CDATA[cs3]]></category>

		<category><![CDATA[rivo+uninstaller]]></category>

		<category><![CDATA[version+cue]]></category>

		<category><![CDATA[winsock]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/adobe/adobe-photoshop-cs3-removed-bonjour/</guid>
		<description><![CDATA[Removed the whole Bonjour crap (both mDNSResponder.exe and mdnsNSP.dll) using the following steps]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/adobe-version-cue-cs3-bonjour.png' alt='adobe-version-cue-cs3-bonjour.png' width='128' height='128' class="photo thumb- fl" /><br />
<h2>What is Adobe Version Cue (Bonjour)</h2>
<blockquote class="mgt"><p class="cite">Bonjour is a file management tool that is integrated in Adobe Photoshop, Adobe InDesign, Adobe Acrobat, Adobe Illustrator and other creative applications within the Creative Suite. It is client/server based. The clients are integrated into each of the applications and they all communicate with the Version Cue Server.</p>
</blockquote>
<p><span id="more-6"></span><br />
To make setup and configuration easier, Adobe uses Apple&#8217;s Bonjour technology to enable the connectivity to Version Cue servers on a local area network. Bonjour is widely used throughout Mac OS X and Windows in applications like iTunes and popular printers to allow users to set up a network service without any configuration.</p>
<p>As adobe install this programs <em class="hilite-3">without your permission</em>, running in the background silently and there is no options to disabled it!. You should consider adobe version cue as a <span class="hilite-4">pestware</span> and should be remove immediately.</p>
<p>There is four methods to removed bonjour services aka Adobe Version Cue CS3 Component.</p>
<h2 class="cb mgb-"><big class="fl">1<span>)</span></big> &nbsp;Manual removal</h2>
<ul class="exturl pdt">
<li>Stop <strong>Bonjour service</strong> <tt class="di">RUN &gt; sc stop &#8220;bonjour service&#8221;</tt></li>
<li>Remove Bonjour services from windows startup <tt class="di">RUN&gt; sc delete &#8220;bonjour service&#8221;</tt></li>
<li>Disable the Bonjour socket driver:<br />
<tt class="di">RUN &gt; Regedit:</tt></p>
<pre class="smallbox">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\
Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004</pre>
<p>find key:<br />
<tt class="di">Enabled=REG_DWORD:00000001</tt> change it from 1 to 0.</li>
<li>Reboot, the driver will not be loaded any more.</li>
<li>Delete the Bonjour directory (with the files <strong>mDNSResponder.exe</strong> and <strong>mdnsNSP.dll</strong>).</li>
</ul>
<h2 class="mgt"><big class="fl">2<span>)</span></big> &nbsp;Apple Bonjour Official Uninstaller</h2>
<p>Download <a href="/uri/d3d3LmFwcGxlLmNvbS9zdXBwb3J0L2Rvd25sb2Fkcy9ib25qb3VyZm9yd2luZG93cy5odG1s.curie,80,302" title="Apple Bonjour for Windows 2.1MB" class="exturl icn-r1">Apple Bonjour for Windows</a> and run the bonjour uninstaller.</p>
<h2><big class="fl">3<span>)</span></big> &nbsp;Optional Methods</h2>
<p>Third methods will disabled bonjour services from running in the background. You&#8217;ll need to removed bonjour manually.<br />
<code>RUN &gt; C:\Program Files\Bonjour\mDNSResponder.exe -remove</code></p>
<h2 class="cb mgt mgb-"><big class="fl">4<span>)</span></big> &nbsp;Third party Uninstaller</h2>
<ul class="xoxo exturl pdt">
<li>
<a href="/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2NjAzNg.curie,80,302"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004666036.jpg" width="130" height="103" class="fr" alt="uninstalled bonjour with rivo uninstaller" /></a>This is the prefer methods, as it wont affect others shared programs that depend on bonjour (ie: itunes, quicktime). Read on <a href="/uri/bGlmZWhhY2tlci5jb20vc29mdHdhcmUvZmVhdHVyZWQtd2luZG93cy1kb3dubG9hZC9jb21wbGV0ZWx5LXJlbW92ZS1wcm9ncmFtcy13aXRoLXJldm8tdW5pbnN0YWxsZXItMjgyMzM3LnBocA.curie,80,302" class="exturl icn-r">lifehacker</a> for more info about Revo Uninstaller. Its free.
</li>
<li>Download and Installed <a href="http://www.revouninstaller.com/revo_uninstaller_free_download.html" class="exturl icn-r1">Revo uninstaller</a>.</li>
<li>Start Revo uninstaller and wait till it finished populating the lists with all your applications and its components.</li>
<li>Find and select <strong>Adobe Version Cue CS3</strong>. Click the Uninstall Icon to proceed. Select the &#8220;Moderate&#8221; options.</li>
<li>After the first &amp; second step is done (dont click finish yet), proceed with removing all bonjour registry.</li>
</ul>
<p class="notice">You can used Revo Uninstaller to removed others &#8220;hidden&#8221; installed components package with Adobe CS3.</p>
<h3 class="cb">Related info</h3>
<h5>Software registry keys</h5>
<dl>
<dt id="Adobe-Version-Cue">Adobe Version Cue CS3 Client</dt>
<dd>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}</dd>
</dl>
<h3 class="cb mgb-">External Links</h3>
<ul class="xoxo exturl">
<li><a href="/uri/Y2V4eC5vcmcvbHNwZml4Lmh0bQ.curie,80,302" title="Repairs Winsock 2 settings, caused by buggy or improperly-removed Internet software " rel="nofollow external">Repairs Winsock 2 settings, caused by buggy or improperly-removed Internet software</a></li>
<li><a href="http://wxpnews.com/archives/wxpnews-322-20080408.htm" rev="vote-for" title="Who Owns That File Format?">WXPNews: Who Owns That File Format?</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/adobe/adobe-photoshop-cs3-removed-bonjour/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
