Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 25-03-2009, 12:27 PM   #1 (permalink)
IM ThE DEVIL
 
Davidboon's Avatar
 
Join Date: Apr 2008
Location: Inside your mind
Posts: 397
Unhappy [HELP] system infected by nmdfgds0.dll


Avast detected a few viruses on my computer named nmdfgds0.dll.
Even after removal it reappears at startup.

As the Consequences: computer is slowed down,its impossible to launch the applications a few times, operation of hard drives in new windows, can not display hidden files ... So thank you to anyone for helping me out.

This is shown by avast

File name : D:\WINDOWS\SYSTEM32\nmdfgds0.dll
Type : Rootkit: hidden process

Here is malwarebytes log

Malwarebytes' Anti-Malware 1.34
Database version: 1888
Windows 5.1.2600 Service Pack 3

3/25/2009 12:04:19 PM
mbam-log-2009-03-25 (12-04-19).txt

Scan type: Quick Scan
Objects scanned: 58940
Time elapsed: 4 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\cdoosoft (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Advanced\Folder\Hidden\SHOWALL \CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
D:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnLineGames) -> Delete on reboot.


i am using avast professional edition 4.8 and i have also tried malwarebytes anti malware to remove this rookit but none of them are unable to remove it permanently.
__________________
AMD Phenom II X6 1055T||MSI 890FXA-GD70||CORSAIR 4GB DDR3||2 * SEAGATE 500GB + WD 500GB ||ASUS EA5870 1GB||RAZER ARCTOSA||RAZER DEATHADDER||NZXT M59||BENQ G2220HD||CORSAIR TX650W||Canon 550D
Davidboon is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 25-03-2009, 12:39 PM   #2 (permalink)
Alpha Geek
 
himadri_sm's Avatar
 
Join Date: Jun 2007
Location: mumbai
Posts: 997
Default Re: [HELP] system infected by nmdfgds0.dll

use ESET Undll...you can download it from the ESET website..just select the infected dll file & it will delete it.
__________________
View my Portfolio here-

Pixels and Polygons | On Linkedin | On Facebook

Available for freelance. PM me for details.

MSI 890 GXM G65, Phenom X6 1055T, G.Skill 1600Mhz "Ripjaws" 2x2gb Kit, MSI GTX 470, WD Black 500Gb, NZXT Gamma, Corsair Vx550, Hp 22x DVD-Rw, Benq G2420HD, Logitech Mx-518, Xbox 360 Gamepad for PC
himadri_sm is offline  
Old 25-03-2009, 01:20 PM   #3 (permalink)
IM ThE DEVIL
 
Davidboon's Avatar
 
Join Date: Apr 2008
Location: Inside your mind
Posts: 397
Default Re: [HELP] system infected by nmdfgds0.dll

@sekhar thanks for your help , i'll give it a try.
__________________
AMD Phenom II X6 1055T||MSI 890FXA-GD70||CORSAIR 4GB DDR3||2 * SEAGATE 500GB + WD 500GB ||ASUS EA5870 1GB||RAZER ARCTOSA||RAZER DEATHADDER||NZXT M59||BENQ G2220HD||CORSAIR TX650W||Canon 550D
Davidboon is offline  
Old 25-03-2009, 02:02 PM   #4 (permalink)
Call me D_J!
 
Disc_Junkie's Avatar
 
Join Date: Nov 2008
Location: INDIA
Posts: 866
Default Re: [HELP] system infected by nmdfgds0.dll

You can also try Noob Killer. Download it. You can do a 8-X Kill which will clear all the malware or you can it delete the file yourself. It has got many options. Try it.
__________________
ASUS K42JA-VX032D RAWKS !!!!!!:grin:
Disc_Junkie is offline  
Old 25-03-2009, 02:14 PM   #5 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: Bhopal, India
Posts: 1,930
Default Re: [HELP] system infected by nmdfgds0.dll

Go for a full scan with the following softwares:

* http://www.superantispyware.com/download.html
* http://www.emsisoft.com/en/software/free/

Also make sure that they are updated to latest definition files and go for Full System Scan.

Else

You can always try Online Scanning. Here's the list of best Online Scanners: http://mrintech.com/5-best-online-vi...rs-you-can-use
__________________
- MrinTech :)
mrintech is offline  
Old 25-03-2009, 04:08 PM   #6 (permalink)
Om Ma Ni Pä Me Hum
 
phuchungbhutia's Avatar
 
Join Date: Jun 2007
Location: sikkim
Posts: 383
Default Re: [HELP] system infected by nmdfgds0.dll

There's a bat file which can remove such files . . try searching it . . its kinza removal bat file . . Small and quite useful . . And u can edit it to use it for more usefulness and no installation hassle either . .
__________________
Om Ma Ni Pä Me Hum: (perfection of-)
Om: generosity,- Ma: pure ethics,-Ni: tolerance n patience.- Pä: perseverance,- Me: concentration,-Hum: wisdom... Using Opera Mini Airtel NOP
phuchungbhutia is offline  
Old 25-03-2009, 06:32 PM   #7 (permalink)
IM ThE DEVIL
 
Davidboon's Avatar
 
Join Date: Apr 2008
Location: Inside your mind
Posts: 397
Default Re: [HELP] system infected by nmdfgds0.dll

thanx phuchung , mrintech , disc_junkie for ur solutions .

and puchung can u name the exact file ?
__________________
AMD Phenom II X6 1055T||MSI 890FXA-GD70||CORSAIR 4GB DDR3||2 * SEAGATE 500GB + WD 500GB ||ASUS EA5870 1GB||RAZER ARCTOSA||RAZER DEATHADDER||NZXT M59||BENQ G2220HD||CORSAIR TX650W||Canon 550D
Davidboon is offline  
Old 25-03-2009, 06:49 PM   #8 (permalink)
Democracy is a myth
 
rhitwick's Avatar
 
Join Date: Apr 2004
Location: Kaikhali,Kolkata
Posts: 2,159
Thumbs up Re: [HELP] system infected by nmdfgds0.dll

Here's ur full data on dat virus.
http://www.threatexpert.com/files/nmdfgds0.dll.html

B/W try Malwarebytes Antimalware
__________________
"My opinions may have changed, but not the fact that I am right."

"I'm never wrong. Once I thought I was wrong, but I was wrong"
rhitwick is online now  
Old 25-03-2009, 08:19 PM   #9 (permalink)
Alpha Geek
 
himadri_sm's Avatar
 
Join Date: Jun 2007
Location: mumbai
Posts: 997
Default Re: [HELP] system infected by nmdfgds0.dll

@Davidboon: do tell us what you used to get rid of the infection.
__________________
View my Portfolio here-

Pixels and Polygons | On Linkedin | On Facebook

Available for freelance. PM me for details.

MSI 890 GXM G65, Phenom X6 1055T, G.Skill 1600Mhz "Ripjaws" 2x2gb Kit, MSI GTX 470, WD Black 500Gb, NZXT Gamma, Corsair Vx550, Hp 22x DVD-Rw, Benq G2420HD, Logitech Mx-518, Xbox 360 Gamepad for PC
himadri_sm is offline  
Old 04-04-2009, 01:49 AM   #10 (permalink)
IM ThE DEVIL
 
Davidboon's Avatar
 
Join Date: Apr 2008
Location: Inside your mind
Posts: 397
Default Re: [HELP] system infected by nmdfgds0.dll

At last i got rid of the virus but still i have to open all my partitions using the explore option instead of double click . only my system partition is accessible with double click .

i just did a boot scan of all the partitions using avast and deleted all suspicious files .
and use malwarebytes too.
__________________
AMD Phenom II X6 1055T||MSI 890FXA-GD70||CORSAIR 4GB DDR3||2 * SEAGATE 500GB + WD 500GB ||ASUS EA5870 1GB||RAZER ARCTOSA||RAZER DEATHADDER||NZXT M59||BENQ G2220HD||CORSAIR TX650W||Canon 550D
Davidboon is offline  
Old 05-04-2009, 12:52 PM   #11 (permalink)
ico
.
 
ico's Avatar
 
Join Date: Jun 2007
Location: New Delhi
Posts: 8,929
Default Re: [HELP] system infected by nmdfgds0.dll

Quote:
Originally Posted by Davidboon View Post
At last i got rid of the virus but still i have to open all my partitions using the explore option instead of double click . only my system partition is accessible with double click .
Enable 'Show hidden files and folders' and also the 'protected system files' from the Folder Options........go to each Disk drive and delete the file 'autorun.inf' manually. And Restart.
__________________
.
ico is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Sarath
- by clmlbx
- by ico
- by clinton
- by icebags
- by Charan

Advertisement




All times are GMT +5.5. The time now is 01:34 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2