Nasty thing was on my parents computer when I visited them the last couple days. I was looking in Trojancheck 5 and saw a funny DLL running.. they had big problems with their Norton and had no AV running do I grabbed the free AVG and found Badtrans.. AVG healed one file and that was it... I looked up Badtrans at Sophos and found that it drops a password stealing trojan, but I could find no trojans with TDS-3 or Trojancheck. I did find the file that the Sophos description said this trojan logs keytstroke information to in WIN/System and deleted it. This finally brings me to my 2 questions 1. When AVG healed the fine (I guess win.init) did that clear up the trojan as well? 2. The file that keystrokes were logged to (and I deleted) ... was it created by the trojan and I did a good thing or was it a system file that gets altered and I did a bad thing?