
Zararlı İsmi : PersonalAntiSpy
Url :
personalantispy.com
Konum :
C:\Program Files\PersonalAntiSpy Free\pas.exe
C:\Program Files\PersonalAntiSpy Free\upascw.exe
C:\Program Files\Common Files\PersonalAntiSpy\pbm.exe
Hijackthis Raporunda Görünen Girdileri :
O4 - HKLM\..\Run: [PersonalAntiSpy Free] "C:\Program Files\PersonalAntiSpy Free\pas.exe" /min
O4 - HKLM\..\Run: [upascw] C:\Program Files\PersonalAntiSpy Free\upascw.exe -c
O4 - HKLM\..\Run: [PASMonitor] "C:\Program Files\Common Files\PersonalAntiSpy\pbm.exe" dm=http://personalantispy.com;http://load.personalantispy.com ad=http://personalantispy.com;http://load.personalantispy.com sd=http://log.personalantispy.com
|
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
veya
http://rapidshare.com/files/156856918/mbam-setup1.30.zip
İlk olarak yukarıdan Malwarebytes'Anti Malware'i indirin.(2 mb)
Programı kurun.

Update bölümünden güncelleyin.

Perform full scan diyip bütün sürücüleri işaretleyip ; taramanın bitmesini bekliyorsunuz.

Tarama bittiğinde show results diyince bulduğu zararlıları görebilirsiniz.

Remove selected deyip ; biraz bekliyorsunuz.
Bilgisayarınızı yeniden başlatın.
Restart sonunda Bulduğu nesneler karantinaya geldi..
Buradakileri de delete all diyerek uçurabilirsiniz.
Başlat > Programlar menüsünde kalan artıkları ( tıklanınca hatalı kısayol uyarısı veren kısayol ve klasörü el ile silin)
Malwarebytes' Anti-Malware ile temizleyebileceğiniz PersonalAntiSpy girdileri :
Kayıt Defteri Girdileri:
HKEY_CURRENT_USER\Software\PersonalAntiSpy Free
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ExplorerUPAS
HKEY_CLASSES_ROOT\CLSID\{_CLSID_WAShellExecuteCheck}
HKEY_CLASSES_ROOT\CLSID\{1924FA29-9740-4F6B-A683-90FB42FC1237}
HKEY_CLASSES_ROOT\CLSID\{5CAB6A79-7710-405a-9B08-A13E908534E9}
HKEY_CLASSES_ROOT\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B11}
HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\ExplorerUPAS
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\ExplorerUPAS
HKEY_CLASSES_ROOT\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
HKEY_CLASSES_ROOT\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95411}
HKEY_CLASSES_ROOT\Interface\{ABCD4567-D8E8-4DF1-A3EA-D0AA72F42611}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
HKEY_CLASSES_ROOT\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37411}
HKEY_CLASSES_ROOT\TypeLib\{C766ED4F-EF37-4C77-8F71-288661A2D513}
HKEY_CLASSES_ROOT\upashellext.ShellHook
HKEY_CLASSES_ROOT\upashellext.ShellHook.1
HKEY_CLASSES_ROOT\upashellext.WASContextMenu
HKEY_CLASSES_ROOT\upashellext.WASContextMenu.1
HKEY_CLASSES_ROOT\uwasfsd.CreationNotifier
HKEY_CLASSES_ROOT\uwasfsd.CreationNotifier.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PersonalAntiSpy Free_is1
HKEY_LOCAL_MACHINE\SOFTWARE\PersonalAntiSpy Free
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uwasfsd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\uwasfsd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\5.0\User Agent\Post Platform "UPAS 3.2.155.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "PASMonitor"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "PersonalAntiSpy Free"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "upascw"
Klasörler :
c:\END
c:\Program Files\Common Files\PersonalAntiSpy
c:\Program Files\PersonalAntiSpy Free
c:\Documents and Settings\All Users\Application Data\PersonalAntiSpy
c:\Documents and Settings\All Users\Application Data\PersonalAntiSpy\Data
c:\Documents and Settings\All Users\Application Data\PersonalAntiSpy\Data\Abbr
c:\Documents and Settings\All Users\Application Data\PersonalAntiSpy\Data\ProductCode
c:\Documents and Settings\All Users\Application Data\SalesMon
c:\Documents and Settings\All Users\Application Data\SalesMon\Data
c:\Documents and Settings\All Users\Start Menu\Programs\PersonalAntiSpy
C:\Documents and Settings\Kullanıcı Adı\Application Data\\PersonalAntiSpy Free
C:\Documents and Settings\Kullanıcı Adı\Application Data\\PersonalAntiSpy Free\Logs
Dosyalar :
c:\Program Files\Common Files\PersonalAntiSpy\pbm.exe
c:\Program Files\PersonalAntiSpy Free\Activate.dat
c:\Program Files\PersonalAntiSpy Free\AsAgents.dll
c:\Program Files\PersonalAntiSpy Free\AsAgents.xml
c:\Program Files\PersonalAntiSpy Free\atl71.dll
c:\Program Files\PersonalAntiSpy Free\AutoProcess.dat
c:\Program Files\PersonalAntiSpy Free\bnlink.dat
c:\Program Files\PersonalAntiSpy Free\err.log
c:\Program Files\PersonalAntiSpy Free\InstHelp.exe
c:\Program Files\PersonalAntiSpy Free\lapv.dat
c:\Program Files\PersonalAntiSpy Free\license.rtf
c:\Program Files\PersonalAntiSpy Free\mfc71.dll
c:\Program Files\PersonalAntiSpy Free\monstate.dat
c:\Program Files\PersonalAntiSpy Free\msvcp71.dll
c:\Program Files\PersonalAntiSpy Free\msvcr71.dll
c:\Program Files\PersonalAntiSpy Free\pas.exe
c:\Program Files\PersonalAntiSpy Free\pas.ini
c:\Program Files\PersonalAntiSpy Free\pas.xml
c:\Program Files\PersonalAntiSpy Free\pv.dat
c:\Program Files\PersonalAntiSpy Free\readme.rtf
c:\Program Files\PersonalAntiSpy Free\scanlog.xml
c:\Program Files\PersonalAntiSpy Free\shellext.dll
c:\Program Files\PersonalAntiSpy Free\shellext.xml
c:\Program Files\PersonalAntiSpy Free\sr.log
c:\Program Files\PersonalAntiSpy Free\Summary.dat
c:\Program Files\PersonalAntiSpy Free\unins000.dat
c:\Program Files\PersonalAntiSpy Free\unins000.exe
c:\Program Files\PersonalAntiSpy Free\up.dat
c:\Program Files\PersonalAntiSpy Free\upascw.exe
c:\Program Files\PersonalAntiSpy Free\updater.dat
c:\Program Files\PersonalAntiSpy Free\updaterdb.dat
c:\Program Files\PersonalAntiSpy Free\UserAgent.dll
c:\Program Files\PersonalAntiSpy Free\uwasffNT.exe
c:\Program Files\PersonalAntiSpy Free\vbpv.dat
c:\Program Files\PersonalAntiSpy Free\database
c:\Program Files\PersonalAntiSpy Free\database\appupdate.dat
c:\Program Files\PersonalAntiSpy Free\database\dbupdate.dat
c:\Program Files\PersonalAntiSpy Free\database\enemies.dat
c:\Program Files\PersonalAntiSpy Free\database\knownfiles.dat
c:\Program Files\PersonalAntiSpy Free\database\tasks.dat
c:\Program Files\PersonalAntiSpy Free\database\TEBase.dat
c:\Program Files\PersonalAntiSpy Free\database\threatnet.dat
c:\Program Files\PersonalAntiSpy Free\quaratine.dat
c:\Program Files\PersonalAntiSpy Free\quaratine.dat\#post_quarantine
c:\WINDOWS\system32\atl71.dll
c:\WINDOWS\system32\gdiplus.dll
c:\WINDOWS\system32\mfc71.dll
c:\WINDOWS\system32\msvcp71.dll
c:\WINDOWS\system32\drivers\uwasfsd.sys
c:\Documents and Settings\All Users\Start Menu\Programs\PersonalAntiSpy\
PersonalAntiSpy.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\PersonalAntiSpy\
Uninstall PersonalAntiSpy.lnk
C:\Documents and Settings\Kullanıcı Adı\Application Data\\PersonalAntiSpy Free\Logs\
update.log
C:\Documents and Settings\Kullanıcı Adı\Desktop\PersonalAntiSpy.lnk
RSS


































