Do you have ComboFix installed?
Jay
seCURE Connexion Consultant
seCURE Connexion Consultant
A forum for reverse engineering, OS internals and malware analysis
DragonMaster Jay wrote:Just to make a quick comment...it sounds somewhat like the Black Internet Bootkit.That's what I was thinking about with the symptoms of invisable music /ads and iexplore.exe running even if the user has not actually started IE, See the GMER log in the Bootkit thread, shows iexplore.exe running.
DragonMaster Jay wrote:Do you have ComboFix installed?Yes. You think I should stop wasting time and just run it?
name viradd virsiz rawdsiz ntrpy md5This is Virtual Address, Virtual Size, Raw Data Size, Entropy.