GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2016-04-09 18:51:15 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD502HJ rev.1AJ100E4 465,76GB Running: jhnmqgsg.exe; Driver: C:\Users\Komputer\AppData\Local\Temp\kwxdykob.sys ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [596:648] fffff96108f24060 ---- Processes - GMER 2.1 ---- Process C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (*** suspicious ***) @ C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe [4368](2016-03-27 14:55:49) 0000000000130000 Library C:\ProgramData\Quotenamron\MedNix.dll (*** suspicious ***) @ C:\Program Files (x86)\Mozilla Firefox\firefox.exe [1540](2016-04-07 14:50:36) 00000000704d0000 Library C:\Users\Komputer\AppData\Roaming\Mozilla\Firefox\Profiles\xrb7ty4d.default\extensions\chmfox@zhuoqiang.me\lib\WINNT_x86-msvc\libchmfox.dll (*** suspicious ***) @ C:\Program Files (x86)\Mozilla Firefox\firefox.exe [1540](2016-03-29 17:02:27) 000000006bff0000 ---- EOF - GMER 2.1 ----