that is exactly what it is doing, it is bound into winlogon.exe and is making connections to that Ip:69.20.20.161 and whenever I delete or do anything it is finding its way back in through winlogon.exe and that rundll32.exe file. nasty crap