1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

what are these files

Discussion in 'Legacy Windows' started by johngkerr, 2003/08/19.

Thread Status:
Not open for further replies.
  1. 2003/08/19
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    dose anyone know what these files are

    RNAAPP.EXE
    RSRCMTR.EXE
    PSTORES.EXE

    COULD THAY BE CAUSING MY COMPUTOR TO RUN SLOW WHEN IT IS ON THE INTERNET. IT SCROLES SLOW TYPING THIS IN WAS SLOW TO SHOW WHAT I WAS TYPING:confused: MOUSE ALSO MOVES SLOW

    HELP
     
  2. 2003/08/19
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    RNAAPP.EXE Dial Up Networking
    RSRCMTR.EXE Resource Monitor
    PSTORES.EXE Protected Storage Service. It is invoked by Microsoft Internet programs such as Outlook Express and Internet Explorer, to securely store a variety of secure and confidential data into the registry, such as Outlook Express passwords, SSL certificates, auto-complete fields (usernames and passwords to enter websites, etc...) and web forms data. Under Windows 9x/ME, PSTORES will only run as and when required "“ leave it alone.
     

  3. to hide this advert.

  4. 2003/08/19
    BillyBob Lifetime Subscription

    BillyBob Inactive

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    RNAAPP is telling me that you are on a Dialup connection and it is part of that and is needed.

    RSRCMTR.EXE can be shut down. It just monitors Resource usage but increases same at the same time. USELESS.

    PSTORES.EXE. I believe it can be shut down also. I really have no idea what it realy is but it is not needed.

    BillyBob
     
  5. 2003/08/19
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    You may have a bunch of Spyware trying to "phone home" while surfing. Down load SpyBot or Adaware, update them, then remove whatever they find. I don't have the links on this puter, I'm sure someone will post them.
     
  6. 2003/08/20
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  7. 2003/08/20
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    I have adaware i remove all spyware it finds and use taskmon to check what is running nothing i can find:confused:
     
  8. 2003/08/20
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Also run Spybot before Adaware and delete all it finds - no one program is perfect in finding all spyware.

    Was the KB Article of any help?
     
  9. 2003/08/20
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    Also when interner explorer can't find a page it dosen't got to
    The page cannot be displayed
    it goes to a search page how do i change that and could this be some of my problem:confused:
     
  10. 2003/08/20
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Shot in the dark
    Does this sound familur
    * Redirections to CoolWebSearch related pages
    * Redirections when mistyping URLs
    * Enormous IE slowdowns when typing
    * IE start page/search page changing on reboot
    * Sites in the IE Trusted Zone you didn't add
    cwshredder

    SpyBot targets this BUT they keep evovling , Im unsure if adaware does
    Post the search page

    Lonny
     
  11. 2003/08/21
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    lonny thank you very much cwshredder work to fix my slow down on Ie but didn't fix my redirect problem. when IE can't find a page it still goes to websearch.com ? I am going to get sypboot and will let you no if it fixes the redirect problem. thank you all for your help, you all are great;)
     
  12. 2003/08/21
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    johngkerr
    Yep SpyBot is a good choice i prefer it to adaware But also use it
    Here is a search fix found at SpyWare info
    Copy and paste everything below lines into note pad
    save it (as anything) exit then rename to something easy to remember fixSearch.reg then right click choose merge
    or double left click
    Afterwards if you choose you can again Modifie it the usual way
    hit the search icon then customize. PS dont include the lines :)
    ------------------------------------------------------------------------------------
    REGEDIT4

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
    "SearchAssistant "= "http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
    "CustomizeSearch "= "http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"
    "Default_Search_URL "= "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Default_Search_URL "= "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "
    "Search Page "= "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main]
    "Search Page "= "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "
    "Search Bar "= "http://g.msn.com/0SEENUS/SAOS01 "

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
    " "= "http://home.microsoft.com/access/autosearch.asp?p=%s"

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main]
    "Search Page "= "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch "
    "Search Bar "= "http://search.msn.com/spbasic.htm "
    "Use Custom Search URL "= dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497} "=" "

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
    @= "http:// "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
    "ftp "= "ftp:// "
    "gopher "= "gopher:// "
    "home "= "http:// "
    "mosaic "= "http:// "
    "www "= "http:// "
    ==============================================
     
    Last edited: 2003/08/21
  13. 2003/08/23
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    lonny thanks you The regedit worked great. know tell me why this key keeps coming back after i remove it

    it may have been for websearch.com don't know


    [HKEY_CLASSES_ROOT\WUSN.1]
    "WUSN_Id "=hex:20,56,f7,ee,09,d4,d7,11,91,dc,f3,4e,6b,ad,b3,7c:D :) :) :)
     
  14. 2003/08/23
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    johngkerr Hi
    Is this a trick question :)
    I didnt prepose any regedit , I suggested merging
    especaily stay out of HKEY_CLASSES_ROOT
    first google search
    do you have Kazza installed, or for that matter any file sharring programs,
    Are you sure Adaware is the latest version with the latest ref file
    and you dont have any excludes, I would also use spyBot.
    and let it clean everything including tracks.
    How did it work for you ?
    If you realy want a clean system (after above and a restart)
    get and run highjackthis post its log here , dont fix anything please as most of what it finds is nessesary !
    There logs are alittle over my head( i can spot some) but others here will help
    http://www.tomcoyote.org/hjt/
    If you must use a file sharring program there are spyware free alternatives.
    http://www.spywareinfo.com/articles/p2p/

    Lonny
     
  15. 2003/08/23
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    I did have kazza installed but i got ride of all of it. But guess not.
    I don't have spybot yet but will get it. Adware finds it, I delete it but it come's back?

    My son download kazza and I have beed trying to get it off my pc. I have a copy of highjackthis but justed use it when I know that this is the problem file. I can see that most of what it show you you don't need to fix

    I cut and paste your fix and made it a .reg file. then click on it.
    I don't like playing with reg. I did look at the keys the were different.:)

    I will get back to you after I clean my pc It's work good know thanks
     
  16. 2003/08/26
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    I got spybot and ran it. I found more thinking and I remove them.
    My computor is running fine but
    [HKEY_CLASSES_ROOT\WUSN.1]
    "WUSN_Id" =hex:20,56,f7,ee,09,d4,d7,11,91,dc,f3,4e,6b,ad,b3,
    7c

    still get put back in my reg. ??? I think it get put back by one of the sites my son go's to, I am trying to find out. How do you want me to post highjackthis log. ?

    I gave donation to spybot I works great thanks
     
  17. 2003/08/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    johngkerr

    [HKEY_CLASSES_ROOT\WUSN.1]
    I this something Adaware or spybot cleans up , then returns later or are you manualy deleting the key ?

    Is your IE security set at default the advanced section to ?
    How to surf the Internet more safely with Internet Explorer - Windows-Help.NET:
    http://www.windows-help.net/features/surf-safe.html

    I would get and use KazaaBegone and
    CoolWebShredder( already done)
    Scroll to
    "Programs I wrote " Mike Healan
    http://www.spywareinfo.com/~merijn/

    Then post Highjackthis log: please clean up again with adawre spybot , restart pc connect to internet hit config then misc tools and check for updates(1.96) if none hit the back button bottom right
    Hit scan the scan button turns into save log
    other forum members will need to help with the log :)
    Lonny
     
    Last edited: 2003/08/26
  18. 2003/08/26
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    when i get the log were do is send it or post it. have update ver first get back with you
     
  19. 2003/08/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    johngkerr

    Guess I should have said == post it here
    also say if youve used Kazzabegone and mention those reg entries, so others can see all within one post
    Lonny
     
  20. 2003/08/26
    johngkerr

    johngkerr Inactive Thread Starter

    Joined:
    2002/10/22
    Messages:
    193
    Likes Received:
    0
    I have done all the think you said this is the log

    Logfile of HijackThis v1.95.0
    Scan saved at 9:22:17 PM, on 08/26/2003
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\CMMPU.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\CLOCKSYNC\SYNC.EXE
    C:\PROGRAM FILES\EZ-S.M.A.R.T\EZSMART.EXE
    C:\WINDOWS\RSRCMTR.EXE
    C:\PROGRAM FILES\CALLWAVE\IAM.EXE
    C:\WINDOWS\START MENU\PROGRAMS\STARTUP\WALLSMART.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\START MENU\PROGRAMS\ACCESSORIES\SYSTEM TOOLS\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://my.att.net/cgi-bin/mywn
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet Explorer provided by AT&T WorldNet Service
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride=;<local>
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=c:\windows\SYSTEM\blank.htm
    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    F1 - win.ini: run=c:\windows\SYSTEM\cmmpu.exe
    O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - D:\PANICWARE\POP-UP STOPPER\CCHELPER.DLL
    O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS\SYSTEM\BTIEIN.DLL
    O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - D:\PANICWARE\POP-UP STOPPER\PSTOPPER.DLL
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe /q
    O4 - Startup: EZSMART App.lnk = C:\Program Files\EZ-S.M.A.R.T\EZSMART.exe
    O4 - Startup: Resource Meter.lnk = C:\WINDOWS\RSRCMTR.EXE
    O4 - Startup: Internet Answering Machine.lnk = C:\Program Files\CallWave\IAM.EXE
    O4 - Startup: WallSmart.exe
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: MS&N Messenger Service (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50017/btiein.cab
    O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct0_x.cab
     
  21. 2003/08/27
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    with highjackthis fix these:>
    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS\SYSTEM\BTIEIN.DLL
    HuntBar "“ See http://www.doxdesk.com/parasite/HuntBar.html
    O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - C:\PROGRA~1\COMMON~1\BTLINK\BTLINK.DLL
    HuntBar "“ See http://www.doxdesk.com/parasite/HuntBar.html
    O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50017/btiein.cab

    "After removing the software you may want to delete the shortcuts the HuntBar/Side and TS variants add to the desktop, start menu and favourites menu, and reset your search and home pages back to normal (Tools->Internet Options->Programs->Reset Web Settings)." "(That wont return all search settins)

    I see no anti virus program nor firewall ?
    Thats all I can see(not an expert) check back to see if others reply :)
    If you realy need a messenger service
    consider uninstalling all but one. and media players to.

    You could get SpywareBlaster and Spyware gaurd, Blaster once set does not need to run
    for protection , and you could hid it from other users. with spyware gaurd you can setup
    a password, though if other users just take it out of the startup folder it wont protect.
    Both are here:>
    http://www.javacoolsoftware.com/spywareblaster.html
    Regards
    Lonny
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.