Please help - Windows Object Recognized

Discussion in 'Malware Help (A Specialist Will Reply)' started by ppkk, Mar 18, 2005.

  1. ppkk

    ppkk Private E-2

    Hi folks
    Grateful if you could help a newbie.
    After running Ad-Adawre, I got the following:

    Started registry scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Windows Object Recognized!
    Type : RegData
    Data :
    Category : Vulnerability
    Comment : URL Prefix Possibly Compromised
    Rootkey : HKEY_USERS
    Object : .DEFAULT\software\microsoft\windows\currentversion\url\prefixes
    Value : ftp
    Data :

    Windows Object Recognized!
    Type : RegData
    Data :
    Category : Vulnerability
    Comment : URL Prefix Possibly Compromised
    Rootkey : HKEY_USERS
    Object : S-1-5-18\software\microsoft\windows\currentversion\url\prefixes
    Value : ftp
    Data :

    Windows Object Recognized!
    Type : RegData
    Data :
    Category : Vulnerability
    Comment : URL Prefix Possibly Compromised
    Rootkey : HKEY_USERS
    Object : S-1-5-21-1229272821-484763869-725345543-1003\software\microsoft\windows\currentversion\url\prefixes
    Value : ftp
    Data :

    Registry Scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 3
    Objects found so far: 3

    ======================================

    Is it possible to correct the problem in the registry? Can someone please help? Thanks!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Lets start with a General Cleanup and then we will focus more on any remaining problems.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal


    After doing ALL of the above if you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds