I'm working on my friends computer that became infected with a few trojans after his grandaughter was on msn. He is running winme and is using selective startup in the system config. In the config utility he only has loadpowerprofile and systemtray checked. When I do a ctrl/alt/del , instead of it showing explorer and system tray, it shows Rundll32 only. I have run avg and microtrend system clean, a host of spyware, and removed manually what was imbedded. I've read that some trojans will copy themselves as Rundll32 and that it how it avoids the antivirus scans. When the computer was connected to the web it was constantly loading lexplore(that's Lexplore but with a lower case L). When it's disconnected from the internet,it only shows the Rundll32. Does anyone have any experience with this? I've read that it adds a line to the original windows Rundll32 in the registry . Thanks for any help that you can offer.