just got a trojan adware.w32.expdwnldr virus which keeps popping up a system alert saying I have to pay for anti spyware to fix it. I’ve read that people have downloaded and removed it with spynomore, so i payed dollars did a full system scan deleted and removed any trojan viruses that were found. I’ve restarted the computer several times and also tryed different programs like kaspersky, super anti virus remove, registry cleaner, and trojan removed. Still no luck. All it really did was cut down on popups and the alert doesn’t pop up as much, but it still does. I want to get rid of for good! Please help me!


Here you have some free software that may help you:
http://kiete.com/antispyware.html
Get Kaspersky Antivirus
It can take care of your problem easily.
Troj/FakeVir-AA is a Trojan downloader for the Windows platform.
http://www.sophos.com/security/analyses/trojfakeviraa.html
The Trojan displays fake spyware alerts to try and lure the user into installing software from a remote location. The alert is displayed in the form of the following message:
"Warning!
Trojan Adware.W32.ExpDwnldr spyware detected. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This also prompts advertising popups.
This process is a security risk and should be removed from your system.
System Affected: Windows 98, 2000, NT, ME, XP
Security Risk(0-5): 4
Adware.W32.ExpDwnldr
http://www.spynomore.com/onlinestability-com.htm
Description: http://www.onlinestability.com is a hijacker that is installed by a trojan. It infects the user’s computer then displays warning messages (similar to the one shown below) in an attempt to force the user into purchasing one of several rogue antispyware / antivirus products such as WinAntiSpyware, WinAntiVirus or SystemDoctor. A common message on infected computers warns of ‘Adware.W32.ExpDwnldr’ infections.
Once installed, onlinestability.com can hijack your desktop and show a message similar to the one shown below:
Adware.W32.ExpDwnldr Warning Message Screenshot:
Smitfraud Variants including PestCapture, WinAntivirus Pro 2007, and other similar Malware Removal Instructions and Help
http://www.pchell.com/support/smitfraud.shtml
==========================
You have malware installed on your system. If you follow all the following steps it should get rid of your problem and prevent future problems. All programs listed are free.
OS Reinstallation vs. Virus Removal
http://safecomputing.umn.edu/guides/rebuild_repair.html
When should I re-format? How should I reinstall? (#10063)
http://www.dslreports.com/faq/10063
Securing a Personal Machine
http://safecomputing.umn.edu/studentchecklist.html
———————————————————
Update your antivirus and run a full scan
If you do not have full time (active) virus protection install (only one) all are excellent:
AVG Antivirus 7.5 Free Edition
http://free.grisoft.com/freeweb.php/doc/avg-anti-virus-free/lng/us/tpl/v5
http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10669237.html?tag=lst-0-1
or
Free antivirus – avast! 4 Home Edition
http://www.avast.com/eng/avast_4_home.html
or
AOL Active Virus Shield (powered by Kaspersky)
http://www.activevirusshield.com/antivirus/freeav/index.adp
———————————————————
Install Windows Defender (full time spyware protection)
Perform a full scan in save mode
http://www.microsoft.com/athome/security/spyware/software/default.mspx
or
AOL Automatic Protection Against Spyware and Malware
http://daol.aol.com/safetycenter/spyware
http://daol.aol.com/safetycenter/
———————————————————
Install the following five programs and run weekly or at least monthly. You need all five. They will greatly increase your protection. They are not a substitute for full time spyware and virus protection.
Ad-Aware SE Personal (update + full scan)
http://www.lavasoftusa.com/products/ad-aware_se_personal.php
Spybot Search & Destroy (update + immunize + scan)
Do not enable Tea Timer and SDHelper
After installation: update + scan + immunize
http://www.safer-networking.org/en/mirrors/index.html
SpywareBlaster: Update then open and click “enable all protection”.
http://www.javacoolsoftware.com/spywareblaster.html
SUPERAntiSpyware free version: (update + scan)
http://www.superantispyware.com/
CCleaner: Do not install toolbar option
Removes tracking cookies, unneeded files, history
In options.
Set to run when computer starts.
Place cookies you want to keep in save list
http://www.ccleaner.com/
————————————————————-
Note if a scan detects a problem but is unable to remove, start the computer in safe mode with the internet line disconnected and run a full scan.
In severe cases your system restore files will also be infected. In these cases you will need to turn off system restore to prevent malware hiding in the system restore files and reinfecting the computer during removal or during a future system restore. Turning off system restore deletes the system restore files.
Right click on "my computer"> Properties > System Restore Tab > Check box turn off system restore
After the malware is removed turn on system restore.
———————————————
McAfee Site Advisor: Internet Explorer and Firefox
http://www.siteadvisor.com/
Indicates if a site is unsafe and can link to a page to explain why it is unsafe.
———————————————————————-
Additional run this time and monthly.
Microsoft Update "Custom Mode" install everything
http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us
Microsoft OneCare Live, run “full service scan”
Updates windows, virus and spyware scan, disk cleanup, disk fragmentation (if needed), backs up registry and then cleans registry, and checks for open firewall ports
http://onecare.live.com/site/en-us/default.htm
Malicious Software Removal Tool (run “full scan”)
http://www.microsoft.com/security/malwareremove/default.mspx
——————————————————-
RootkitRevealer v1.71
http://www.microsoft.com/technet/sysinternals/Security/RootkitRevealer.mspx
Rootkit Removal Guide
http://safecomputing.umn.edu/guides/scan_unhackme.html
Rootkits Removers
Pick any 2 install and run one each month
AVG Anti-Rootkit
http://www.grisoft.com/doc/products-avg-anti-rootkit-update-app-art/?ver=1.1.0.29
F-Secure BlackLight
http://www.f-secure.com/blacklight/
Trend Micro Rootkit Buster
http://www.trendmicro.com/download/rbuster.asp
Sophos Anti-Rootkit
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html
———————————————————-
———————————————————-
Online Free Scanners:
Run Trend Micro, Kaspersky, and Panda Scan now.
Run a different one each month.
Trend Micro: HouseCall Free Scan (removes what it finds)
http://housecall.trendmicro.com/
BitDefender Online Scanner http://www.bitdefender.com/scan8/ie.html
Kaspersky Labs Online Scanner http://www.kaspersky.com/virusscanner
McAfee http://us.mcafee.com/root/mfs/default.asp?affid=294
Edwido Spyware Scan
http://www.ewido.net/en/onlinescan/
F-Secure
http://support.f-secure.com/enu/home/ols.shtml
Panda ActiveScan Free Online Scanner http://www.pandasoftware.com/products/activescan?
Symantic Online Scanner http://security.symantec.com/sscv6/ssc_eula.asp?langid=ie&venid=sym&plfid=23&pkj=ALUFRHYTINMHDKDCWLL&vc_scanstate=2
————————————————————-
Special Removal Tools
Run this time only if indicated.
CWShredder: run
http://www.trendmicro.com/cwshredder/
Roguefix.bat
http://www.internetinspiration.co.uk/roguefix.htm#uninstall
Shoot The Messenger
http://www.grc.com/stm/shootthemessenger.htm
SmitFraudFix
http://www.geekstogo.com/forum/How_to_use_SmitFraudFix-t109268.html
Vundo Fix and
VirtumundoBegone (if VundoFix does not work)
http://www.bleepingcomputer.com/forums/topic18610.html
VX2 tool for Ad-Aware and run tool (Install and run)
http://www.lavasoftusa.com/support/securitycenter/vx2_cleaner.php
—————————————
Additional Information read:
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview
http://wiki.castlecops.com/Malware_Prevention:_Prevent_Re-infection
http://www.castlecops.com/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html
http://aumha.org/a/quickfix.htm
http://aumha.org/secure.htm
http://aumha.org/a/parasite.php
http://www.castlecops.com/t102301-Hijackthis_Guidelines_Read_Before_Posting.html
http://www.techsupportforum.com/security-center/hijackthis-log-help/15968-updated-important-read-before-posting-log.html
http://forum.aumha.org/viewtopic.php?t=4075&sid=901703d08c2ace31389ffef2d84b6607
Run spynomore in safemode.
For Windows XP
If the computer is running it is best to shut down Windows and then turn off the power.
Begin by first clicking on the Start Button and then click on Turn Off Computer.
Now click on the Turn Off red colored icon to shut down your computer system.
It is best to wait between 15 to 30 seconds before you turn your system back on.
Turn on your computer and start tapping the F8 key on your keyboard.
Some Computers may display a keyboard error message if you begin tapping F8 too quickly.
Restart your computer again and begin tapping the F8 key a brief second or two later.
When the Windows Advanced Options Menu appears, Choose the Safe Mode option and hit Enter.
Windows will now boot your computer up in Safe Mode.
What is "trojan adware.w32.expdwnldr"?
You will see this name on the dialog box that is popping if your system was infected with MyGeek Cpvfeed.
Further information and removal method can be found here:
http://www.spyware-removal-guideline.com/mygeek-cpvfeed-removal