[HELP] system infected by nmdfgds0.dll

Status
Not open for further replies.

Davidboon

In the zone
Avast detected a few viruses on my computer named nmdfgds0.dll.
Even after removal it reappears at startup.

As the Consequences: computer is slowed down,its impossible to launch the applications a few times, operation of hard drives in new windows, can not display hidden files ... So thank you to anyone for helping me out.

This is shown by avast

File name : D:\WINDOWS\SYSTEM32\nmdfgds0.dll
Type : Rootkit: hidden process

Here is malwarebytes log

Malwarebytes' Anti-Malware 1.34
Database version: 1888
Windows 5.1.2600 Service Pack 3

3/25/2009 12:04:19 PM
mbam-log-2009-03-25 (12-04-19).txt

Scan type: Quick Scan
Objects scanned: 58940
Time elapsed: 4 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
D:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.


i am using avast professional edition 4.8 and i have also tried malwarebytes anti malware to remove this rookit but none of them are unable to remove it permanently.
 
D

Deleted member 26636

Guest
use ESET Undll...you can download it from the ESET website..just select the infected dll file & it will delete it.
 

Disc_Junkie

Call me D_J!
You can also try Noob Killer. Download it. You can do a 8-X Kill which will clear all the malware or you can it delete the file yourself. It has got many options. Try it.:)
 

mrintech

Technomancer
Go for a full scan with the following softwares:

* *www.superantispyware.com/download.html
* *www.emsisoft.com/en/software/free/

Also make sure that they are updated to latest definition files and go for Full System Scan.

Else

You can always try Online Scanning. Here's the list of best Online Scanners: *mrintech.com/5-best-online-virus-scanners-you-can-use ;)
 

phuchungbhutia

Om Ma Ni Pä Me Hum
There's a bat file which can remove such files . . try searching it . . its kinza removal bat file . . Small and quite useful . . And u can edit it to use it for more usefulness and no installation hassle either . .
 

rhitwick

Democracy is a myth
Here's ur full data on dat virus.
*www.threatexpert.com/files/nmdfgds0.dll.html

B/W try Malwarebytes Antimalware
 
D

Deleted member 26636

Guest
@Davidboon: do tell us what you used to get rid of the infection.
 
OP
Davidboon

Davidboon

In the zone
At last i got rid of the virus but still i have to open all my partitions using the explore option instead of double click . only my system partition is accessible with double click .

i just did a boot scan of all the partitions using avast and deleted all suspicious files .
and use malwarebytes too.
 

ico

Super Moderator
Staff member
At last i got rid of the virus but still i have to open all my partitions using the explore option instead of double click . only my system partition is accessible with double click .
Enable 'Show hidden files and folders' and also the 'protected system files' from the Folder Options........go to each Disk drive and delete the file 'autorun.inf' manually. :) And Restart. :)
 
Status
Not open for further replies.
Top Bottom