The reason you fond nothing on that .exe....
is that they randomize the name on install.
Also, the random name also keeps track of the other random names it installs and runs.
2-6 exes typically run to be watchdogs so they can be "kept running".
Assuming 6 versions running hidden...
1 watches to make sure 2,3,4,5,6 are running.
2 watches to make sure 1,3,4,5,6 are running.
3 watches to make sure 1,2,4,5,6 are running.
4 watches to make sure 1,2,3,5,6 are running.
5 watches to make sure 1,2,3,4,6 are running.
6 watches to make sure 1,2,3,4,5 are running.
You have to kill all of them at once.
Good luck. I'll bet there are some latent ones that will start up at a later date. Lobbed in on some CLSID.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
PGP key: 1024D/B524687C 2003-08-05
Fingerprint: E1D3 E3D7 5850 957E FED0 2B3A ED66 6971 B524 687C
Alternate Fingerprint: 09F9 1102 9D74 E35B D841 56C5 6356 88C0