Antispyware Soldier manual removal:
Kill processes:
a.exe, antispysoldier.exe, officescan.exe, runsrv32.exe, smartdrv.exe, susp.exe, updwebmin.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Adware.Srv32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\srv32 spool service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\srv32 spool service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B53455DB-5527-4041-AC41-F86E6947AA47}
HKEY_CLASSES_ROOT\AlxTB.BHO
HKEY_CLASSES_ROOT\Bridge.brdg
HKEY_CLASSES_ROOT\DailyToolbar.IEBand
HKEY_CLASSES_ROOT\DailyToolbar.SysMgr
HKEY_CLASSES_ROOT\IEToolbar.AffiliateCtl
HKEY_CLASSES_ROOT\jao.jao
HKEY_CLASSES_ROOT\office_pnl.office_panel
HKEY_CLASSES_ROOT\Popup.HTMLEvent
HKEY_CLASSES_ROOT\PopMenu.Menu
HKEY_CLASSES_ROOT\Popup.PopupKiller
HKEY_CLASSES_ROOT\url_relpacer.URLResolver
HKEY_CLASSES_ROOT\WStart.WHttpHelper
HKEY_CLASSES_ROOT\WStart.WHttpHelper.1
HKEY_CLASSES_ROOT\AppID\DailyToolbar.DLL
HKEY_CLASSES_ROOT\AppID\WStart.DLL
HKEY_CLASSES_ROOT\AppID\{951B3138-AE8E-4676-A05A-250A5F111631}
HKEY_CLASSES_ROOT\AppID\{F6BDB4E5-D6AA-4D1F-8B67-BCB0F2246E21}
HKEY_CLASSES_ROOT\CLSID\{B53455DB-5527-4041-AC41-F86E6947AA47}
HKEY_CLASSES_ROOT\Interface\{900FBC20-6AEE-4E05-ABA9-AC46E309C029}
HKEY_CLASSES_ROOT\TypeLib\{8B076501-1D1B-4B26-9492-FDB8EEE00D7F}
HKEY_CURRENT_USER\Software\Microsoft\IPCheck
HKEY_LOCAL_MACHINE\SOFTWARE\DailyToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\NIX Solutions\DailyToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\RespondMiter
HKEY_LOCAL_MACHINE\SOFTWARE\Software\TPS108
HKEY_LOCAL_MACHINE\SOFTWARE\Transponder
HKEY_LOCAL_MACHINE\SOFTWARE\WSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bridge
Delete files:alexaie.dll, alxie328.dll, alxres.dll, alxtb1.dll, bridge.dll, btgrab.dll, bz.dll, dailytoolbar.dll, dlmax.dll, jao.dll, office_pnl.dll, pynix.dll, questmod.dll, runsrv32.dll, smaexp32.dll, tcpservice2.exe, txfdb32.dll, udpmod.dll, winblsrv.dll, wstart.dll, zserv.dll, winlogon.ini
Delete directories:C:\Program Files\Antispyware Soldier
C:\Documents and Settings\[Current User]\Local Settings\Application Data\AntispywareSoldier
Misc:Exact file location:
antispysoldier.exe, bz.dll - C:\Program Files\Antispyware Soldier
susp.exe, alexaie.dll, alxie328.dll, alxtb1.dll, btgrab.dll, dlmax.dll, pynix.dll, zserv.dll - C:\Windows or C:\Winnt
a.exe, officescan.exe, runsrv32.exe, smartdrv.exe, updwebmin.exe, alxres.dll, bridge.dll, dailytoolbar.dll, jao.dll, office_pnl.dll, questmod.dll, runsrv32.dll, smaexp32.dll, tcpservice2.exe, txfdb32.dll, udpmod.dll, winblsrv.dll, wstart.dll, winlogon.ini - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Domain Name: ANTISPYWARESOLDIER.COM (216.195.35.105)
Registrant:
AntiSpyware Coalition
Artur Podlaski (admin@antispywaresoldier.com)
str. Nowogrodzka 14
Warszawa
null, 00511, PL
Tel. +48.228253883
Domain Name: ANTISPYNET.COM (85.255.118.98)
Registrant:
Michael Brown
Artur Podlaski (michael.brown70@yahoo.com)
Friedrich-Str. 10
Dusseldorf
null, 40215, DE
Tel. +561.4595318
AVOID THESE DOMAINS AND THESE IPs! Better block them in your Hosts file.