Security Stronghold security made easy

How to Remove Win32.Trojan.Spy

Trojans is one of the most wide-spread threat in the internet. They can spread in lot of ways (torrents, e-mail attachments, video codecs etc.). Win32.Trojan.Spy as well as any other trojan can harm your PC in different ways. Originally, trojans stole just your e-mail contacts and some personal data. Nowadays, they can steal any type of private information, being serious threat. In this tutorial we will show how to deal with Win32.Trojan.Spy detect and remove it from your PC.

Choose option :

* Win32.Trojan.Spy description and technical details.

* Manual removal of Win32.Trojan.Spyl.

* Download tool that will solve your problem automatically.

* Professional support that will help you remove Win32.Trojan.Spy from our Security Support Team.

Various types of malware, advertising-supported software and worm are improperly termed "viruses" as those softwares don't self-propagate, that's why when performing Win32.Trojan.Spy removal, it's duly obligatory to fix the sort of malicious programs. The nickname "Win32.Trojan.Spy" is somewhile treated as collective name when treatment Win32.Trojan.Spy removal tools to consist all kinds of malware. Platform specific autorun script files are also cracked by virus dangers that's why it's rushly needful to execute Win32.Trojan.Spy removal by a worthy Win32.Trojan.Spy removal tool as long as it is really low to remove viruses. Virus threats target manifold sorts of comminication medium or keeps, one of the first are binaries. With a view to evade detection by users and Win32.Trojan.Spy removal tools, some virus dangers use varied kinds of fraud. Virus dangers can accomplish infesting files by transcribing redundant areas of runfiles.

Threat indicator: HIGH

Trojan's detail table

Trojan alias:

Executable file:

Threat class:

Affected OS:




Win32 (Windows 9x, Windows XP, Windows Vista, Windows Seven)

Win32.Trojan.Spy infiltration

As we already said there numerous ways trojan can get to your PC from the internet. Win32.Trojan.Spy copies its file(s) to your hard disk. File name typical to Win32.Trojan.Spy is winampa.exe . Then it runs itself and creates new startup key in registry with name Win32.Trojan.Spy and value winampa.exe . If you will look into running processes list you will see some extra process with name like winampa.exe or any random name that uses decent amount of your CPU.

If you would like to remove Win32.Trojan.Spy use WiperSoft Antispyware Malware Remediation Tool (see below)

Automatic Trojan Removal

So what is Win32.Trojan.Spy Removal Tool? Basically, it is the tool that will remove every file and registry key that was created by Win32.Trojan.Spy. It was created after analyzing all versions and types of this threat on test PCs and every file and key was added to the database. Removal Tool is updated regularly to make sure it can remove latest versions of Win32.Trojan.Spy:

Download WiperSoft Antispyware to remove Win32.Trojan.Spy

* WiperSoft Antispyware was developed to remove threats like Win32.Trojan.Spy in automatic mode. Remover has active module to protect PC from hijackers, trojans, ransomware and other viruses. Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.

How to remove Win32.Trojan.Spy manually?

During all time since adding Win32.Trojan.Spy to our database we track it changes and add them in the list below, removing files mentioned from your hard drive and deleting them from starup list and also unregistering all corresponding DLLs will result cleaning your computer drom the trojan. But also, missing DLL's that can be removed or corrupted by Win32.Trojan.Spy should be restored from your Windows CD .

So, here is the simple process to remove Win32.Trojan.Spy:

1. Delete following processes form startup and files from your hard drive:

no information

2. Delete the following folders that are assosiated with Win32.Trojan.Spy:

no information

3. Finally, remove this registry keys:

no information

Warning: Sometimes, trojan can use system file names or randomly generated names for its executable. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.

If you are already our customer or you have additional questions ask our support team for help in removing Win32.Trojan.Spy!

Let our support team solve your problem with Win32.Trojan.Spy and remove Win32.Trojan.Spy right now!

support person

Submit support ticket below and describe your problem with Win32.Trojan.Spy. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove Win32.Trojan.Spy. Trouble-free tech support with over 10 years experience removing malware.

Submit support ticket

Write a few words of how you got Win32.Trojan.Spy with all circunstances in the form below. Our support team open support ticket for you in an hour and we will start solving your problem with Win32.Trojan.Spy. Attach suspicious files that you see that possibly a part of Win32.Trojan.Spy.

Click to ask professional of Win32.Trojan.Spy solution

Describe your problem here and we'll contact you in several minutes:

We'll reply you in 10 minutes or less
* Your Name:
* Your E-mail:
* Problem summary:
* Detailed description:
Attach suspicious file:
Here you can attach file you suspect to be virus or source of problem. If you want to attach several files, put them into one archive and attach it instead.

Click on this button to submit request.

Solution guaranteed!


It is important:

  1. We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you Win32.Trojan.Spy removal solution.
  2. All fields of this form are obligatory.

Here are the descriptions of problems connected with Win32.Trojan.Spy and winampa.exe we received earlier:

Problem Summary: Trojan in my eventlog.dll

I tried to download ad aware to my computer and it won't work. Instead it downloaded Eco antivirus. It took over my computer and messed it up. I got rid of the Eco antivirus but there is still a Trojan in my enentlog.dll. I can't run any of my scans like sypbot or malwarebytes antimalware. It won't let me run those scans. When I get on the internet to Trojan tells me that the sights that I usually to to is blocked because of a virus. My question is how do you get rid of a trojan in my eventlog.dll

Problem was successfully solved. Ticket was closed.

Problem Summary: Virus in system

Can not load antivirus software as virus in system

Problem was successfully solved. Ticket was closed.

Problem Summary: password of trojan-apy.win32.zbot.ikh

تظهر صفحة بلغة المانية تطلب فيها الباسورد لهذا الفيروس

Problem was successfully solved. Ticket was closed.

Problem Summary: spywarewarning.mht problems

My machine is infected with this virus, cannot open notepade, firefox, i get the, can't update anti-virus software (mcafee), can't run spybot or suparantyspyware, i get popup windows (critical system warning! message, system alert:trojan-spy.win32@mx message) problems when surfing with IExplorer.

This is the log from HiJackThis i got last week (hope is useful)
Logfile of HijackThis v1.99.1
Scan saved at 01:28:55 p.m., on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\Archivos de programa\Intel\Wireless\Bin\EvtEng.exe
C:\Archivos de programa\Intel\Wireless\Bin\S24EvMon.exe
C:\Archivos de programa\Intel\Wireless\Bin\WLKeeper.exe
C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\archivos de programa\archivos comunes\mcafee\mna\mcnasvc.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Java\jre1.6.0_05\bin\jusched.exe
C:\Archivos de programa\Intel\Wireless\bin\ZCfgSvc.exe
C:\Archivos de programa\Intel\Wireless\Bin\ifrmewrk.exe
C:\Archivos de programa\McAfee\MPF\MPFSrv.exe
C:\Archivos de programa\Dell\QuickSet\quickset.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\Archivos de programa\Dell\MediaDirect\PCMService.exe
C:\Archivos de programa\SiteAdvisor\6261\SiteAdv.exe
C:\Archivos de programa\\Agent\mcagent.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Archivos de programa\McAfee\MSK\MskSrver.exe
C:\Archivos de programa\Intel\Wireless\Bin\RegSrvc.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Archivos de programa\NetWaiting\netWaiting.exe
C:\Archivos de programa\SiteAdvisor\6261\SAService.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Archivos de programa\Digital Line Detect\DLG.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\Generic.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\varios\disco 80\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\system32\spywarewarning.mht
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Archivos de programa\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\ARCHIV~1\mcafee\msk\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Archivos de programa\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Archivos de programa\BAE\BAE.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Archivos de programa\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Archivos de programa\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Archivos de programa\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Archivos de programa\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\ARCHIV~1\ARCHIV~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Archivos de programa\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Archivos de programa\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Archivos de programa\\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SeePassword] C:\Archivos de programa\SeePassword\SeePassword.exe
O4 - HKLM\..\Run: [McENUI] C:\ARCHIV~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [IEUpdate] C:\WINDOWS\system32\2052z.exe
O4 - HKLM\..\RunServices: [IEUpdate] C:\WINDOWS\system32\2052z.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Archivos de programa\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [IEUpdate] C:\WINDOWS\system32\2052z.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunServices: [IEUpdate] C:\WINDOWS\system32\2052z.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Enviar a &Bluetooth - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Archivos de programa\SiteAdvisor\6261\SiteAdv.dll
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Archivos de programa\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\ARCHIV~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\archivos de programa\archivos comunes\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\ARCHIV~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\ARCHIV~1\ARCHIV~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\ARCHIV~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\ARCHIV~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Archivos de programa\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Archivos de programa\McAfee\MSK\MskSrver.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Archivos de programa\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Archivos de programa\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Archivos de programa\SiteAdvisor\6261\SAService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Archivos de programa\Intel\Wireless\Bin\WLKeeper.exe

Thanks in advance

Problem was successfully solved. Ticket was closed.

Problem Summary: spywarewarning.mht

The same problem as you describe at your website ::
fake popup virus C:\\WINDOWS\\system32\\spywarewarning.mht
this same popup keeps coming up titled"cridical system warning" i obviousley know it's fake,and also this page automatically became my home page. evin when i tried to change it it went back as the home page wich says "C:\WINDOWS\system32\spywarewarning.mht"

Problem was successfully solved. Ticket was closed.

Problem Summary: fake popup virus C:\WINDOWS\system32\spywarewarning.mht

this same popup keeps coming up titled"cridical system warning" i obviousley know it's fake,and also this page automatically became my home page. evin when i tried to change it it went back as the home page wich says "C:\WINDOWS\system32\spywarewarning.mht" please help me!! it's annoying i even went to the file where it was located and says canont delete a program is using it right now please close the program,the file is lo
cated in system please help asap,please.

Problem was successfully solved. Ticket was closed.

Problem Summary: spywarewarning.mht

When I load internet explorer I get the message spywarewarning click here to remove (which is fake i know) I cannot delete the file that is located in the System 32 because it is in use. I can only delete it once I have started the computer in safe mode and once the computer is restarted back to normal mode the file magically appears again. I ran superantispyware and found 2 other Trojan horses that may be linked to this they were located in the system 32 folder: NT10256.sys & protector.exe Can you help me get rid of this?

Problem was successfully solved. Ticket was closed.

Problem Summary: Win32 and Windows security alert.

I have been infected with Trojan-spyWin32@Mx and critical warning adware. I have found spywarewarning.mht and spywarewarning2.mht in Windows/System32 folder, which tries to take over my Internet Options Home Page address and redirect to the above >mht The only way to bypass it and get onto the Internet has been to press "Use Default" and keep "Internet Options" open after pressing the Apply key, without pressing O.K. I have tried McAfee; Malwarebytes, mbam; SmitfraudFix; removed the hard drive from the computer and put it into an external case to delete the spywarewarning.mht objects, all to no avail. All I can think of doing now is to save my most treasured bits and pieces to an external hard drive, format and start from scratch. WIll this help?

Problem was successfully solved. Ticket was closed.

Problem Summary: Trojan virus

My computer is infected with what I believe is a trojan virus. I used a program called passgen.exe that came with a .zip file to unpack, since then my computer is noticeably slower, and bombarded w/ pop-ups saying I need to download spyware protection software that I don't need. My Norton 360 is unable to connect to the network. Also, when I start windows, it disable the windows automatic updates. Internet explorer homepage redirects me to a page that looks like a website but is actually a a file that is in the windows/win32 folder called spywarewarning.mht. When I discovered this problem I ran a program called process manager plus to identify any high-risk programs running on my system, and it located the program aaaamonw.exe, which I didn't recognize and deleted. That helped stop the pop-ups, and I thought the problem was gone but when I did a google search on the spywarewarning.mht filename to see what it was, my internet explorer is being crashed by excessive pop-ups, so I know the virus is still there. My tech-savvy friend told my that the only way to fix it is to delete everything from the hard drive (a system restore?). Is this the only solution? I have backed up my most important files but would like to avoid deleting files that haven't been backed up. Thank you for you help!


Problem was successfully solved. Ticket was closed.

Problem Summary: Trojan.Win32.Qhost.exe


I have Nod32 antivirus in my laptop when i start the windows, nod32 is giving message that Trojan.Win32.Qhost.exe
Is exists, it has infected the svchost file in the system32 folder i try to clean it with the nod32 but it say access denied to svchost,
i have search for qhost remover in the internet i find your solution sword true , i have install in the laptop and run it it fine some virus but it didnt find the trojan qhost.
please give me your advise how to remove this trojan from svchost file in ,my system.


Problem was successfully solved. Ticket was closed.

Show more


Next threat: Win32.Trojan.Starter »

« Back to catalog

Home | Partners | Shop | Support | Terms of use | Contact Us | Privacy Policy | Sitemap

Copyright © 2023 Security Stronghold. All Rights Reserved. All content on this website is protected and belongs to Security Stronghold LLC.