GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-05-27 13:23:06 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000069 TOSHIBA_ rev.MS2O 931,51GB Running: qnbfdpk7.exe; Driver: C:\Users\Filipp\AppData\Local\Temp\kfwdipog.sys ---- Threads - GMER 2.2 ---- Thread C:\Windows\SysWOW64\svchost.exe [2764:4048] 0000000000499cfc Thread C:\Windows\SysWOW64\svchost.exe [2764:6052] 0000000000499cfc Thread C:\Windows\SysWOW64\svchost.exe [2764:3760] 0000000000499cfc Thread C:\Windows\SysWOW64\svchost.exe [2764:3704] 0000000000499cfc Thread C:\Windows\SysWOW64\svchost.exe [2764:1716] 0000000000499cfc ---- Processes - GMER 2.2 ---- Library c:\programdata\package cache\{e01cb7f1-3e88-4450-1764-b3cc1e205c4a}v10.1.14393.795\installers\30daf459e79c5d26366654b1b482e87.cab:dp (*** suspicious ***) @ C:\Windows\SysWOW64\svchost.exe [2764](2017-05-24 10:21:48) 0000000010000000 ---- EOF - GMER 2.2 ----