It was worth a shot. You could download pslist from sysinternals and use that to list the process id, and then use their pskill to kill it.
usr_crtl.dll wont unregister and fag.exe is not in the process list.
Any idea how this got on your computer?
Norton is fully patched to current as is windows update.
Did you try housecall.antivirus.com?Current versions of adaware, spybot (search & Destroy) or norton found any trace of the trojan. Even when pointed directly at that directory. Anything else that recgnises this?
Paul Schmehl (pauls@utdallas.edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html