A week and a half ago, my computer caught the "Warning! Your're in danger!" malware that is referenced in other posts on this site. My computer's background turned to the "Warning! Your're in danger!" message and the piece of fake antivirus software began running, as described in other threads on this forum. I lost all control of the computer, wasn't able to click on anything or ctrl+alt+delete etc. Eventually I pulled the power plug. After a few tries, I was able to boot in safe mode and run my McAfee antivirus software, which detected the infection and "quarantined" it. I then re-booted in normal mode, and was able to run programs, access the internet, etc.
I then followed the first several steps in this site's Malware and Spyware Cleaning Guide. My most recent Malwarebytes log (I've run it several times, most recently this evening) is posted at the end of this message. As you can see from the log, I'm running XP with Service Pack 2. Step 3 of the guide wants me to install all updates, but I've read accounts of trouble with SP3, including that it might cause stability problems if the computer has other issues. I'm concerned that my computer falls into the category of having "issues". Would it be in my best interest to install SP3 anyhow?
The computer has "relapsed" a few times since then, with the fake anti-virus software attempting to run. Each time I have been able to stop it by running either McAfee or Malwarebytes. Malwarebytes always detects a trojan and claims to have quarantined and deleted it, but if I reboot and run Malwarebytes again, it detects the trojan again.
I guess I'm first trying to figure out if I should install SP3, or just proceed on to step 5 (Rootkit Detection) to get rid of this malware. Or should I do something else entirely?
Your assistance would be greatly appreciated, and I'm happy to provide more information if needed.
Thanks,
Brian
Malwarebytes' Anti-Malware 1.40
Database version: 2555
Windows 5.1.2600 Service Pack 2
8/13/2009 8:59:42 PM
mbam-log-2009-08-13 (20-59-42).txt
Scan type: Quick Scan
Objects scanned: 117069
Time elapsed: 4 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
\\?\globalroot\systemroot\system32\geyekreoxlnxwk.dll (Trojan.TDSS) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
\\?\globalroot\systemroot\system32\geyekreoxlnxwk.dll (Trojan.TDSS) -> Quarantined and deleted successfully.

