no way the boss would allow that to happen. so far i mentioned disallowing .com .pif and other extentions that the worm uses but he's not to keen on doin it, i explained users have no reason to be sending those but he sais just wait for the scanner to pick 'em up eventually, which i dont know if it will happen soon since its been happenin since last week, so im kinda stuck on the blocking part. thats why im just tryin to figure out how in the hell i can get netshield to see those virus's. i've posted for help in the mcafee forum but no one has replied. well thanks for all the help im not sure if theres anything you guys can do or suggest. if you have anymore advice pleeeeaaaasssee send my way. i swear im gonna kill the author of that virus. it doesnt help that he released the source code either for more to come. congrats on your soon to come 1000th post vorlin. thanks to everyone.