nmdfgds0.dll

The library nmdfgds0.dll has been detected as malware by 31 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
239a17bc73fb30296ce34249cbe76861

SHA-1:
2e228b6f818195d56960e47d34d4927c9a8d3614

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
5/2/2024 10:10:20 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.WOW
7.1.1

AhnLab V3 Security
Trojan/Win32.OnlineGameHack
2013.04.08

Avira AntiVirus
TR/Crypt.XPACK.Gen2
7.11.70.250

avast!
Win32:Kavos [Trj]
2014.9-170315

AVG
Win32/Heur
2018.0.2439

Bitdefender
Gen:Heur.Krypt.18
1.0.20.370

Comodo Security
Packed.Win32.MNSP.Gen
15850

Dr.Web
Trojan.Packed.2474
9.0.1.074

Emsisoft Anti-Malware
Gen:Heur.Krypt.18
8.17.03.15.02

ESET NOD32
Win32/PSW.OnLineGames.NMP
11.8203

F-Prot
W32/OnlineGames.CR.gen
v6.4.7.1.166

F-Secure
Trojan-PSW:W32/OnlineGames.gen!E
11.2017-15-03_4

G Data
Gen:Heur.Krypt.18
17.3.22

IKARUS anti.virus
Packed.Win32.Krap
t3scan.2.0.0.0

K7 AntiVirus
Trojan
13.164.8482

Kaspersky
Trojan-GameThief.Win32.OnLineGames
14.0.0.-1311

Malwarebytes
Spyware.Zbot.USBV
v2017.03.15.02

McAfee
Generic PWS.ak
5600.6095

Microsoft Security Essentials
TrojanDownloader:Win32/Frethog.C
1.163.1557.0

NANO AntiVirus
Trojan.Win32.OnLineGames.tpjpd
0.24.0.51813

Norman
Suspicious_Gen2.TJCLD
11.20170315

nProtect
Trojan-PWS/W32.WebGame.86528.Z
13.04.07.01

Panda Antivirus
Generic Trojan
17.03.15.02

Quick Heal
Worm.AutoRun.gen
3.17.12.00

Rising Antivirus
Trojan.Win32.Generic.122ED520
23.00.65.17313

Sophos
Mal/EncPk-IG
4.87

Total Defense
Win32/Frethog.DLV
37.0.10367

Trend Micro House Call
TROJ_GAMETHI.FQK
7.2.74

Trend Micro
TROJ_GAMETHI.FQK
10.465.15

Vba32 AntiVirus
BScope.Trojan.SvcHorse.01643
3.12.20.2

VIPRE Antivirus
Worm.Win32.Taterf.b
16650

File size:
84.5 KB (86,528 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Windows\System32\nmdfgds0.dll

File PE Metadata
Compilation timestamp:
4/24/2009 7:23:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2600E

Entry point:
23, C1, C1, D0, 71, 1B, C0, 32, C0, 57, 8B, C0, 5F, 74, 08, A5, 12, BB, 5C, BF, 32, BF, 52, 52, 2B, C0, 52, 8B, DB, 5A, 74, 0F, 59, 2B, 84, BD, 43, 0B, 80, B3, 52, 21, B1, B7, 47, 20, E1, 51, 1B, C1, 51, 8B, C9, 59, EB, 08, FF, 4C, E0, 1A, E5, 6C, E4, 14, E8, 1A, 00, 00, 00, 8B, C5, 66, 2B, C0, 56, 8B, D2, 5E, 74, 0F, A1, 27, D3, 82, BB, 07, D7, 8C, AA, 2D, E6, 88, BF, 2C, B6, A9, 8E, 26, 2B, 37, B8, 19, 48, A1, 6D, 33, C0, 53, 8B, F6, 5B, 74, 04, 4B, 2A, B8, 06, 5A, C1, D0, 62, 1B, C1, B9, 86, 29, 0F, 07...
 
[+]

Code size:
4 KB (4,096 bytes)

Remove nmdfgds0.dll - Powered by Reason Core Security