Ok, how about this on the same subject as to how it works! I have Norton internet security and sometimes I get a notification indicating that it (norton) has blocked an attempted connection or something like that against the subseven trojan? Once again, I thought in order to use that program the server.exe had to be emailed to the victim. That's all I want to know, man! How are they doing this??? I appreciate the response by the way..