This section provides some notes on malware pp10.exe and ld12.exe registered as startup programs together with the Antivirus System PRO infection.
More notes on what I did to remove Antivirus System PRO and related malicious programs.
13. Looking at the folder, C:\WINDOWS\. sysguard.exe is not there. But
there are several strange files created. See the picture below:
14. Looking at running processes in the Task Manager, pp10.exe and ld12.exe are currently running.
End both of them with Task Manager.
15. Deleting all 5 files listed below from C:\WINDOWS:
Name Size Type Date Modified
pp10.exe 15KB Application 7/4/2009 10:26 AM
934fdfg34jgif23 1KB File 7/4/2009 10:26 AM
0101120101464649.dat 1KB DAT File 7/4/2009 10:25 AM
010112010146118114.dat 1KB DAT File 7/4/2009 10:25 AM
ld12.exe 28KB Application 7/4/2009 10:24 AM
16. Running HijackThis and got 2 extra O4 (Enumeration of suspicious autoloading Registry entries) lines in the log file: