Hello, I seem to have some malware that randomly starts up internet explorer processes (two of them) in the background and then proceeds to connect to multiple IPs/urls with small bits of traffic. I ran wireshark to capture this traffic and analyze it a bit but all I could see were that it mostly consisted of HTTP, and the traffic itself included things like images. I ran RogueKiller which spots the two processes and kills them on the prescan as "[Proc.Injected]" and shows the path to iexplore.exe, but it shows two items as follows, one in uppercase and one in lower: C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\IEXPLORE.exe As soon as RougeKiller kills these two the traffic to random sites stops, again all this is in the background, nothing ever pops up on screen and I do not use the IE browser. But tools like windows resource monitor or GlassWire show these connections. I have run various products and none of them find any malware (MB included), but the processes still start up the next time I reboot, after some random amount of time it seems. So not sure what this is, so I followed instructions here and ran FRST64 and have attached the two files generated. Thank you FRST.txt Addition.txt