Hello everyone! It's been quite a while since my last post here. Anyway, I got this problem here. Some time ago I was infected by a troyan. I knew it because my firewall showed a strange connection. A program (winsock.exe) tries to connect to a certain adress. I cleaned all the links to this program in the registry(never had it before) and deleted it itself and blocked it with firewall. But it kept coming back. On windows startup it runs some 'kernel1' and afterwards 'kernel_1' and that brings all the things back to the way they were. Although if I sit on 'ctrl+alt+del' during a windows loadup I can just close those processes, but that is kinda exausting, I got tired of that. I know my computer like myself also the registry-I cleaned it up, but it keeps coming back. Perhaps it wrote itself in rundll32? Does anyone have any ideas on how to trace the way this sucker installs himself all over again?