Remove Antispyware Soldier. Description and removal instructions

 
Title: Antispyware Soldier

Type: Trojans
Severity scale:Antispyware Soldier severity is 70  (70 / 100)
 
Antispyware Soldier is a trojan that displays an icon in the system tray. This icon shows a message, which says that the compromised computer is infected with dangerous spyware parasites and asks the user to download and install a removal program, which actually is AntiSpyware Soldier, the same named corrupt illegally distributed spyware remover. Once the user clicks on that message, the trojan opens a web site distributing AntiSpyware Soldier. It may also try to download the application. The trojan is able to change the Internet Explorer default home page and redirect the web browser to malicious web sites. Furthermore, it can secretly download from the Internet and install malicious parasites to the infected system. Antispyware Soldier automatically runs on every Windows startup.

Antispyware Soldier Removal Guide


Related files: alexaie.dll, alxie328.dll, alxres.dll, alxtb1.dll, bridge.dll, btgrab.dll, bz.dll, dailytoolbar.dll, dlmax.dll, jao.dll, office_pnl.dll, pynix.dll, questmod.dll, runsrv32.dll, smaexp32.dll, tcpservice2.exe, txfdb32.dll, udpmod.dll, winblsrv.dll, wstart.dll, zserv.dll, winlogon.ini

Antispyware Soldier properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Antispyware Soldier removal:

remover for Antispyware Soldier

Antispyware Soldier manual removal:

Kill processes:
a.exe, antispysoldier.exe, officescan.exe, runsrv32.exe, smartdrv.exe, susp.exe, updwebmin.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Adware.Srv32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\srv32 spool service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\srv32 spool service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B53455DB-5527-4041-AC41-F86E6947AA47}
HKEY_CLASSES_ROOT\AlxTB.BHO
HKEY_CLASSES_ROOT\Bridge.brdg
HKEY_CLASSES_ROOT\DailyToolbar.IEBand
HKEY_CLASSES_ROOT\DailyToolbar.SysMgr
HKEY_CLASSES_ROOT\IEToolbar.AffiliateCtl
HKEY_CLASSES_ROOT\jao.jao
HKEY_CLASSES_ROOT\office_pnl.office_panel
HKEY_CLASSES_ROOT\Popup.HTMLEvent
HKEY_CLASSES_ROOT\PopMenu.Menu
HKEY_CLASSES_ROOT\Popup.PopupKiller
HKEY_CLASSES_ROOT\url_relpacer.URLResolver
HKEY_CLASSES_ROOT\WStart.WHttpHelper
HKEY_CLASSES_ROOT\WStart.WHttpHelper.1
HKEY_CLASSES_ROOT\AppID\DailyToolbar.DLL
HKEY_CLASSES_ROOT\AppID\WStart.DLL
HKEY_CLASSES_ROOT\AppID\{951B3138-AE8E-4676-A05A-250A5F111631}
HKEY_CLASSES_ROOT\AppID\{F6BDB4E5-D6AA-4D1F-8B67-BCB0F2246E21}
HKEY_CLASSES_ROOT\CLSID\{B53455DB-5527-4041-AC41-F86E6947AA47}
HKEY_CLASSES_ROOT\Interface\{900FBC20-6AEE-4E05-ABA9-AC46E309C029}
HKEY_CLASSES_ROOT\TypeLib\{8B076501-1D1B-4B26-9492-FDB8EEE00D7F}
HKEY_CURRENT_USER\Software\Microsoft\IPCheck
HKEY_LOCAL_MACHINE\SOFTWARE\DailyToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\NIX Solutions\DailyToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\RespondMiter
HKEY_LOCAL_MACHINE\SOFTWARE\Software\TPS108
HKEY_LOCAL_MACHINE\SOFTWARE\Transponder
HKEY_LOCAL_MACHINE\SOFTWARE\WSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bridge
Delete files:
alexaie.dll, alxie328.dll, alxres.dll, alxtb1.dll, bridge.dll, btgrab.dll, bz.dll, dailytoolbar.dll, dlmax.dll, jao.dll, office_pnl.dll, pynix.dll, questmod.dll, runsrv32.dll, smaexp32.dll, tcpservice2.exe, txfdb32.dll, udpmod.dll, winblsrv.dll, wstart.dll, zserv.dll, winlogon.ini
Delete directories:
C:\Program Files\Antispyware Soldier
C:\Documents and Settings\[Current User]\Local Settings\Application Data\AntispywareSoldier
Misc:
Exact file location:
antispysoldier.exe, bz.dll - C:\Program Files\Antispyware Soldier
susp.exe, alexaie.dll, alxie328.dll, alxtb1.dll, btgrab.dll, dlmax.dll, pynix.dll, zserv.dll - C:\Windows or C:\Winnt
a.exe, officescan.exe, runsrv32.exe, smartdrv.exe, updwebmin.exe, alxres.dll, bridge.dll, dailytoolbar.dll, jao.dll, office_pnl.dll, questmod.dll, runsrv32.dll, smaexp32.dll, tcpservice2.exe, txfdb32.dll, udpmod.dll, winblsrv.dll, wstart.dll, winlogon.ini - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Domain Name: ANTISPYWARESOLDIER.COM (216.195.35.105)
Registrant:
AntiSpyware Coalition
Artur Podlaski (admin@antispywaresoldier.com)
str. Nowogrodzka 14
Warszawa
null, 00511, PL
Tel. +48.228253883

Domain Name: ANTISPYNET.COM (85.255.118.98)
Registrant:
Michael Brown
Artur Podlaski (michael.brown70@yahoo.com)
Friedrich-Str. 10
Dusseldorf
null, 40215, DE
Tel. +561.4595318

AVOID THESE DOMAINS AND THESE IPs! Better block them in your Hosts file.

Other programs to remove Antispyware Soldier:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 07/08/06
Information updated: 10/08/06

Additional resources related to Antispyware Soldier:

Attention: If you know or you have a website or page about Antispyware Soldier removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Antispyware Soldier parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites: