Davidboon
In the zone
Avast detected a few viruses on my computer named nmdfgds0.dll.
Even after removal it reappears at startup.
As the Consequences: computer is slowed down,its impossible to launch the applications a few times, operation of hard drives in new windows, can not display hidden files ... So thank you to anyone for helping me out.
This is shown by avast
File name : D:\WINDOWS\SYSTEM32\nmdfgds0.dll
Type : Rootkit: hidden process
Here is malwarebytes log
Malwarebytes' Anti-Malware 1.34
Database version: 1888
Windows 5.1.2600 Service Pack 3
3/25/2009 12:04:19 PM
mbam-log-2009-03-25 (12-04-19).txt
Scan type: Quick Scan
Objects scanned: 58940
Time elapsed: 4 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
D:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.
i am using avast professional edition 4.8 and i have also tried malwarebytes anti malware to remove this rookit but none of them are unable to remove it permanently.
Even after removal it reappears at startup.
As the Consequences: computer is slowed down,its impossible to launch the applications a few times, operation of hard drives in new windows, can not display hidden files ... So thank you to anyone for helping me out.
This is shown by avast
File name : D:\WINDOWS\SYSTEM32\nmdfgds0.dll
Type : Rootkit: hidden process
Here is malwarebytes log
Malwarebytes' Anti-Malware 1.34
Database version: 1888
Windows 5.1.2600 Service Pack 3
3/25/2009 12:04:19 PM
mbam-log-2009-03-25 (12-04-19).txt
Scan type: Quick Scan
Objects scanned: 58940
Time elapsed: 4 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
D:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.
i am using avast professional edition 4.8 and i have also tried malwarebytes anti malware to remove this rookit but none of them are unable to remove it permanently.