GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-12-20 12:41:39 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000035 Crucial_CT250MX200SSD1 rev.MU01 232.89GB Running: trxe1w71.exe; Driver: C:\Users\Dominik\AppData\Local\Temp\kfadrfob.sys ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [1460:6580] fffff960021b4060 ---- Processes - GMER 2.1 ---- Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\avengine.dll.45ae02d18ac3aa41355b6f543c132321 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000070410000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\intctrl.kdl.0000000000099e00-01d13abe7d909962-01d13abffedabfdb (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000070340000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\uds.dll.000000000006b1b8-01d13abe7eed5111-01d0b1495b864700 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000070250000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\kavbase.kdl.4722a84528427396818ce6bb2de1be66 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 00000000701b0000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\klavemu.kdl.76b04999dade2e08b49145958bb0ab62 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006f9f0000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\kjim.kdl.8fe5f980a56c945b1e9be93387e43132 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006e240000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\mark.kdl.15506d2ea280e6b29b1e4810742f6b50 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006e0c0000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\qscan.kdl.88af17c775c5528d5d15ffd1272aaa32 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006df90000 Library c:\programdata\kaspersky lab\avp15.0.2\data\wlengine.dll (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006db50000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\sys_critical_obj.dll.0000000000023600-01d13abe7ebc4453-01d13abecc0a4d8d (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006d290000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\rar_win_x86.ppl.f5afd87cb4043fa9d801dafeb6f19723 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006d110000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\arkmon.kdl.7368e1cee522b4a4529448c1752ade57 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006d0c0000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\kavsys.kdl.78d57427e0b324a5881e888c06ac11a6 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006d010000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\swmon.kdl.000000000001b200-01d13abe7e65b0f1-01d13ac03c67b039 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006cc30000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\swmon_drv.kdl.0000000000024200-01d13abe7e9bba46-01d13ac03cc79a99 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 000000006cbc0000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\vlns.kdl.50b550767fe2caad4d144452d53b2d78 (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000058950000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\pbs.kdl.eefcc4c76375abb2b40e8e5c00c7eccf (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 00000000587f0000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\klavasyswatch.dll.0000000000127800-01d13abe7d988439-01d13abecb381f9e (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000058310000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\heurap.dll.7aaa0a24800a0898e1e21547cd09831d (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000058100000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\pdm.kdl.0000000000077300-01d13abe7e202279-01d13ac01b65008a (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000058050000 Library C:\ProgramData\Kaspersky Lab\AVP15.0.2\Bases\Cache\bsshlp2.kdl.4db1f3203905b0722dbfbaea1b5ef48c (*** suspicious ***) @ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [1940] (FILE NOT FOUND) 0000000057fd0000 Process C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe (*** suspicious ***) @ C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe [6816](2015-12-18 08:40:50) 0000000000fc0000 Library C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll (*** suspicious ***) @ C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe [6816](2015-12-18 08:40:50) 0000000070bf0000 Library C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll (*** suspicious ***) @ C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe [6816](2015-12-18 08:40:50) 0000000069500000 ---- EOF - GMER 2.1 ----