so I went to microsofts update page and they wanted me to down load some software to be able to update. I have sp1 so I decided not to do it. Then I run an anti-trojan software soon after and it finds an alternate data stream and my system.ini file had been rewritten. The time of the rewrite coincided with the visit to ms update page. So when the anti-trojan software found the alternate data stream linked to the system.ini file I deleted the stream and the host. I had a copy of the original system.ini file. I noticed that a lot of numbers had been added to the file since I went to ms site. I restored it to its original content. So anybody know just why ms changed my system.ini file and created an alternate data stream? To see if the site actually did it, I went back with the restored system.ini file in place and just went to the site but didn't (purposly) download anything. And yup the changed was made again, and the stream was back. So I fixed everything again.... So what do you all think?... I know they want to catch software hacks but, geez.... and what is an alternate data stream anyway?