Steve, checking to see whether the user is in the admin or domain admin group is invalid, b/c a normal user would not be allowed to run the admin script your trying to run thereby foregoing the effort.

It seems as though this process has been moved to running the script from a DC. If that is the case, then rather than checking the process, would it not be feasible to place the decryption algorithm in a folder and assign the everyone(G) execute rights only? This would eliminate the need for a dll or ocx, however, I guess this method may be suspect to eavesdropping as mentioned above...
_________________________
-Jim

...the sort of general malaise that only the genius possess and the insane lament.