I experienced an attack by win32 /Rbot trojan 'javaws.exe' infection. Warned by NOD32 of attempt to infect and offered quarantine and submit for analysis. Did not prevent the infected file running. This virus prevented internet communication and also disabled NOD32 on demand and in-depth scanner. I had to end the process in Task Manager before I could run NOD32 scanner which then found virus and offered deletion option. 2 infections arrived 18 seconds apart - Win32/Rbot trojan followed by Win32/Qhost.1 trojan. 'javasw.exe' made 3 attempts to change the registry but Spybot Search and Destroy allowed me to deny the changes. (Qhost may have created files in System32 folder called QTFont.qfn and QTFont.for, but have not checked these out yet) Now, when I reboot the computer it launches 2 versions of "javaw.exe" which leaves 2 copies of the Java Application Cache Viewer running on my desktop. I have not located the source of the command to launch these - not in any Startup folder. I have checked the Registry for incidences of javaw.exe but only found in what look like valid Java spots. I have Java installed to run the ATO programme ECI. I also found files called QFont.for which I have removed from Windoes\System32 folder.