W32.ASpam.Trojan - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: April 6, 2000
Updated: February 13, 2007 11:52:21 AM
Also Known As: W32/ASpam, TROJ_ASPAM.A, Aspam.Trojan
Type: Trojan Horse


To remove this Trojan:
  1. Using Windows Explorer delete the file C:\Windows\System\Amcis32.dll.
  2. Using Regedit, delete the following registry keys or values:

    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{657B9354-BB3B-4500-A9B0-109B4FA64815}
    (delete entire key)

    HKEY_LOCAL_MACHINE\Software\Classes\AMCIS32.IEClass
    (delete entire key)

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {657B9354-BB3B-4500-A9B0-109B4FA64815}
    (delete this value only)


Writeup By: Andy Cianciotto
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security