<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="HardwareAnalysis.Com" -->
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="">
        <title>Hardware Analysis - Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <description>Hardware Analysis Community Forums</description>
        <link>http://www.hardwareanalysis.com/content/topic/6509/</link>
        <image rdf:resource="http://media.hardwareanalysis.com/halogo.gif" />
       <dc:date>2008-10-14T15:45:03-05:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#534201"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#115859"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#67957"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#67889"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#67817"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52770"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52769"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52745"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52739"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52712"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52655"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52613"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52612"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52606"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52595"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://media.hardwareanalysis.com/halogo.gif">
        <title>Hardware Analysis</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/</link>
        <url>http://media.hardwareanalysis.com/halogo.gif</url>
    </image>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#534201">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-22T13:58:54-05:00</dc:date>
        <dc:creator>Chad Mcaculay</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#534201</link>
        <description>Wow, I'm posting to a 5 year old topic.  Man, I'm really up to date&lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile11.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:cool:&quot; title=&quot;:cool:&quot;&gt;  I just wanted to share an experience I had with this ctfmon.exe.  When I would quickly close a program, be it DVD Fab, Sound Forge 6.0, Nuendo 2, etc., there would be an unexplainable lag of about two seconds.  Nothing would respond.  For instance, if I would close a folder in explorer and then quickly right click on the desktop, there would be a two second delay before my right click options would appear.  &lt;br /&gt;
&lt;br /&gt;
As far as program performance and gaming, no lag during operation, only after closing a program or folder.  Once I ended the task ctfmon.exe, the lag problem went away.  As I'm sure most people in here know, you can permanently end this task under control panel, regional and language options, languages tab, details, advanced and check the box &amp;quot;Turn off advanced text services.&amp;quot;  It's just funny how a process that's taking up about 4MB can cause an entire system hang&lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile5.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:P&quot; title=&quot;:P&quot;&gt;</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#115859">
        <dc:format>text/html</dc:format>
        <dc:date>2004-03-19T02:57:44-05:00</dc:date>
        <dc:creator>Kris Diggy</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#115859</link>
        <description>I use windows XP and that has the regenerate function for all files in the   C:windows/system32    folder, even screen savers regenerate when deleted!&lt;br /&gt;
So it seems clever? and u want all files to regenerate? well they do! &lt;br /&gt;
But if u look in   C:windows/system32/dllcache   folder, you will find a copy of every file in the system32 folder, so basically if windows detects that u deleted a file from the sys32 folder it just puts it back again, (u have to empty the recycle bin before it does this).&lt;br /&gt;
&lt;br /&gt;
So all you have to do is delete it from both of these directories, then empty the recycle bin, then Windows will tell you that you have deleted system files and need to insert your operating system CD, just click cancel and there u have it, no more annoying file!</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#67957">
        <dc:format>text/html</dc:format>
        <dc:date>2003-10-19T17:57:39-05:00</dc:date>
        <dc:creator>Corvus Raven</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#67957</link>
        <description>It should be under %root%\system32</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#67889">
        <dc:format>text/html</dc:format>
        <dc:date>2003-10-19T09:53:58-05:00</dc:date>
        <dc:creator>Ecosse</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#67889</link>
        <description>Try  =  START - RUN msconfig - OK   Go to startup tab.</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#67817">
        <dc:format>text/html</dc:format>
        <dc:date>2003-10-19T01:49:58-05:00</dc:date>
        <dc:creator>John Doe</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#67817</link>
        <description>Okay... I've looked for that page to disable executions of listed files... and it wasn't there. I used a run command to get it, like you said, and it couldn't find it. Is there a shortcut/directory for accessing that page?</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52770">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T20:10:25-05:00</dc:date>
        <dc:creator>Corvus Raven</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52770</link>
        <description>I just had a thought about something very recent.&lt;br /&gt;
&lt;br /&gt;
If it weren't for REMOTE Process Calls being enabled by default - Who would have kown about Blaster worm?&lt;br /&gt;
&lt;br /&gt;
-Corvus</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52769">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T20:07:59-05:00</dc:date>
        <dc:creator>Corvus Raven</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52769</link>
        <description>I am a self proclaimed paranoid schizophrinac..and so am I &lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile1.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:)&quot; title=&quot;:)&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
(I never said anything about spelunz)</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52745">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T18:12:07-05:00</dc:date>
        <dc:creator>software-analysis</dc:creator>
        <title>Disabling unneeded programs.</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52745</link>
        <description>Nothing to do with paranoia for me.  It has everything to do with memory and resource consumption.  This was especially true on Win98/ME, but bottom line is why do I want to run processes that I don't use?  Same goes for Linux -- fully open source...no &amp;quot;paranoia&amp;quot; involved.  Simple common sense dictates one shouldn't run processes that one doesn't need.  It reduces the complexity of the overall system and lowers the risk of software failures (or security holes).  If I am not hosting a web site, why would I want to run MS personal web-site server or apache?  &lt;br /&gt;
&lt;br /&gt;
Would you vote for everyone running apache on their system if it was included and turned on by default?&lt;br /&gt;
Why or why not?  Does the choice have paranoia as a motivating factor (other than paranoia about unfound security holes).  Besides -- it's often said that the best security experts are always at least a bit paranoid.  Good security is based on the premise that something will go wrong -- and when it does, how will you detect and/or mitigate the damage?  How can you lessen _risk_?  Disabling&lt;br /&gt;
unnecessary processes should, in general, lower potential causes for failure.  It's just good sense.&lt;br /&gt;
If that = paranoia...well, so be it.&lt;br /&gt;
&lt;br /&gt;
SA&lt;br /&gt;
</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52739">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T17:30:01-05:00</dc:date>
        <dc:creator>Corvus Raven</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52739</link>
        <description>&lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile1.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:)&quot; title=&quot;:)&quot;&gt;  try ..umm how to say..&lt;br /&gt;
&lt;br /&gt;
&amp;quot;&lt;a class=&quot;ext&quot; href=&quot;/action/r/http://www.puckmicrosopt.com&amp;quot;&quot; target=&quot;_blank&quot;&gt;http://www.puckmicrosopt.com&amp;quot;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
 ..You know what letter to reflace the p's with?&lt;br /&gt;
I am sure you can Pigure it out. &lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile4.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;;)&quot; title=&quot;;)&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
humm.. seems that my tyfing has been misconstrued.. some letters are being re fositioned.  &lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile1.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:)&quot; title=&quot;:)&quot;&gt;  hehe</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52712">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T14:44:40-05:00</dc:date>
        <dc:creator>Wildwood</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52712</link>
        <description>Mine was bitterness. &lt;br /&gt;
&lt;br /&gt;
I save paranoia for holidays and family gatherings.&lt;br /&gt;
&lt;br /&gt;
</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52655">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T06:47:26-05:00</dc:date>
        <dc:creator>Andy Parker</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52655</link>
        <description>Damn, have we all taken a paranoid pill today?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Andy</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52613">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T02:08:28-05:00</dc:date>
        <dc:creator>software-analysis</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52613</link>
        <description>Harris Walktin writes...&lt;br /&gt;
CTFMon...&lt;br /&gt;
     yes, you can disable it, but various programs will reinstall and re-enable it -- like if you run any of the 'repair' options or reinstall options.  In find it more permanent to disable the program's execution -- then if it is releaded and reneabled later on, it still won't run.,&lt;br /&gt;
&lt;br /&gt;
Same goes for LoadQM -- but this one is in 98 and such. Best advice there is to create a directory in the same location.  Standard open/delete calls won't delete a directory so it's not so easy for &lt;br /&gt;
a program to recreate /reinstall/re-enable the file.&lt;br /&gt;
The programs have to know enough to examine the error code and risk removing an unexpected directory.  Most programs just give up when they can't create the file.   To be extra obstinate, you can set the hidden, system and read-only bits on the dir.  So any program that might delete might at least check permissions before just upping and deleting the name entry.&lt;br /&gt;
&lt;br /&gt;
 Mobsync...Well...Again -- you can *try* to disable Mobsync, but I found it kept getting reinstalled.&lt;br /&gt;
&lt;br /&gt;
Ups and downs to every technique and often many ways to do the same thing.&lt;br /&gt;
&lt;br /&gt;
SA</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52612">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T02:08:03-05:00</dc:date>
        <dc:creator>software-analysis</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52612</link>
        <description>Harris Walktin writes...&lt;br /&gt;
CTFMon...&lt;br /&gt;
     yes, you can disable it, but various programs will reinstall and re-enable it -- like if you run any of the 'repair' options or reinstall options.  In find it more permanent to disable the program's execution -- then if it is releaded and reneabled later on, it still won't run.,&lt;br /&gt;
&lt;br /&gt;
Same goes for LoadQM -- but this one is in 98 and such. Best advice there is to create a directory in the same location.  Standard open/delete calls won't delete a directory so it's not so easy for &lt;br /&gt;
a program to recreate /reinstall/re-enable the file.&lt;br /&gt;
The programs have to know enough to examine the error code and risk removing an unexpected directory.  Most programs just give up when they can't create the file.   To be extra obstinate, you can set the hidden, system and read-only bits on the dir.  So any program that might delete might at least check permissions before just upping and deleting the name entry.&lt;br /&gt;
&lt;br /&gt;
 Mobsync...Well...Again -- you can *try* to disable Mobsync, but I found it kept getting reinstalled.&lt;br /&gt;
&lt;br /&gt;
Ups and downs to every technique and often many ways to do the same thing.&lt;br /&gt;
&lt;br /&gt;
SA</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52606">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T01:45:43-05:00</dc:date>
        <dc:creator>Harris Walktin</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52606</link>
        <description>CTFMon.exe&lt;br /&gt;
&lt;br /&gt;
(Microsoft) CTFMon comes with Microsoft Office XP and Windows XP – it activates the Alternative User Input Text Input Processor (TIP) and the Microsoft Office XP Language Bar.  As long as the Text Services &amp;amp; Speech are enabled in the Control Panel, this program will force itself back into your list of background programs.&lt;br /&gt;
&lt;br /&gt;
Recommendation : &lt;br /&gt;
Disable  &amp;quot;Text Services &amp;amp; Speech&amp;quot;  in the Control Panel if you are not using them.  Then, disable CTFMon using Startup Manager.  (Note that if you use Word, Excel or PowerPoint to write in different languages, eg. English and Arabic, then you will be using  &amp;quot;Text Services &amp;amp; Speech&amp;quot;  facilities). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
LoadQM.exe&lt;br /&gt;
&lt;br /&gt;
(Microsoft) This task loads the MSN Queue Manager and is installed when you install MSN Explorer or MSN Messenger.  LOADQM gobbles up system resources and appears on most end-users’ Task Lists who come to us complaining of low System &amp;amp; User Resources or very slow, &amp;quot;crawling&amp;quot;, PCs.  In January 2003 this is still one of the worst behaved Microsoft programs !&lt;br /&gt;
&lt;br /&gt;
Recommendation : &lt;br /&gt;
Disable immediately, or Delete using Starter. Next, reboot your PC and find LOADQM in the C:\WINDOWS folder.  Rename it to LOADQM.EXE.OLD as if you do not it will otherwise get put back in your Task List at some stage or other (on some PCs you may need to boot into Safe Mode before you are able to rename LOADQM). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
MobSync.exe&lt;br /&gt;
&lt;br /&gt;
(Microsoft)&lt;br /&gt;
 Microsoft Synchronization Manager.  This program, which is part of Internet Explorer 5.x/6, runs in the background when you are using the &amp;quot;View pages offline&amp;quot; feature of Internet Explorer, and you have set parameters for when your pages should be automatically synchronised, or you decide to manually synchronise your offline content with the web through the &amp;quot;Start \ Programs \ Accessories \ Synchronize&amp;quot; function.  This program will also run if you are doing development using Microsoft SQL 7 and using SQL 7 replication.&lt;br /&gt;
&lt;br /&gt;
Recommendation : &lt;br /&gt;
Harmless. If you never use the &amp;quot;Synchronize&amp;quot; function, then disable it with Startup Manager.&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/6509/?l=1#52595">
        <dc:format>text/html</dc:format>
        <dc:date>2003-08-13T00:41:39-05:00</dc:date>
        <dc:creator>software-analysis</dc:creator>
        <title>Re: Real Suspicious possibility from, Mirosoft!!!!(CTFMON.EXE as an example).</title>
        <link>http://www.hardwareanalysis.com/content/topic/6509/?l=1#52595</link>
        <description>Got to run a program (windows-R), type &amp;quot;secpol.msc&amp;quot;&lt;br /&gt;
to modify local security policy.&lt;br /&gt;
&lt;br /&gt;
Select Software Restriction Policies, Additional Rules, then in right panel, right click (menu), and &lt;br /&gt;
Add new path rule.  Type in the path of the &lt;br /&gt;
executable you want to disable.&lt;br /&gt;
&lt;br /&gt;
Choose the disable option.&lt;br /&gt;
&lt;br /&gt;
It takes effect when anything tries to load the program using that path.  It won't stop a currently&lt;br /&gt;
running copy (use task manager and kill process for&lt;br /&gt;
that).&lt;br /&gt;
&lt;br /&gt;
Learn to take control of you computer....learn how to pull the plug! &lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile1.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:-)&quot; title=&quot;:-)&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
Of course the new MS updates have disabled my ability to use font smoothing or clear type...and haven't figured out how to fix that one yet....have a feeling it's another MS bug in directX, since it's the onlything I've installed recently that should be affecting the display.  But text displays at the speed of drying mud...&lt;img src=&quot;http://media.hardwareanalysis.com/smilies/smile2.gif&quot; width=&quot;14&quot; height=&quot;14&quot; border=&quot;0&quot; alt=&quot;:-(&quot; title=&quot;:-(&quot;&gt;  &lt;br /&gt;
&lt;br /&gt;
If someone has any ideas there, that'd be cool!&lt;br /&gt;
&lt;br /&gt;
SA</description>
    </item>
</rdf:RDF>
