Same problem as jon2367 I'm having the exact same problems as Jon. The machines have updated virus definitions and I have tried the safe mode solution. Norton alternates between w32.rontokbro@mm and w32.rontokbro.b@mm and deletes the payload quickly, however it continues to drop its load unless I disconnect the machine from the network. I am a net admin (as it appears Jon is) and I am looking for a way to trace the source. Any ideas? I have all the guest accounts turned off so I'm not sure what account is being used to create the files. Any takers on a solution?