Ok that seems to have removed the files, I cannot see them anymore.
Was the Cyberdefender detection a false reading then, or is there something harmless somewhere in the system with that name?
report:-
ComboFix 12-03-10.02 - Owner 12/03/2012 16:22:04.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1498 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\AVG2012
c:\documents and settings\All Users\Application Data\AVG2012\fet\407c36d17c36c208.dat
c:\documents and settings\Owner\Application Data\AVG2012
c:\documents and settings\Owner\Application Data\AVG2012\cfgall\userawacs.cfg
c:\documents and settings\Owner\Application Data\AVG2012\cfgall\usergui.cfg
c:\program files\AVG
c:\program files\AVG\AVG10\js.dat
c:\program files\AVG\AVG10\mfacz.lns
c:\program files\AVG\AVG10\mfada.lns
c:\program files\AVG\AVG10\mfaes.lns
c:\program files\AVG\AVG10\mfafr.lns
c:\program files\AVG\AVG10\mfage.lns
c:\program files\AVG\AVG10\mfahu.lns
c:\program files\AVG\AVG10\mfaid.lns
c:\program files\AVG\AVG10\mfain.lns
c:\program files\AVG\AVG10\mfait.lns
c:\program files\AVG\AVG10\mfajp.lns
c:\program files\AVG\AVG10\mfako.lns
c:\program files\AVG\AVG10\mfams.lns
c:\program files\AVG\AVG10\mfanl.lns
c:\program files\AVG\AVG10\mfapb.lns
c:\program files\AVG\AVG10\mfapl.lns
c:\program files\AVG\AVG10\mfapt.lns
c:\program files\AVG\AVG10\mfaru.lns
c:\program files\AVG\AVG10\mfasc.lns
c:\program files\AVG\AVG10\mfask.lns
c:\program files\AVG\AVG10\mfasp.lns
c:\program files\AVG\AVG10\mfatr.lns
c:\program files\AVG\AVG10\mfavera.txt
c:\program files\AVG\AVG10\mfazh.lns
c:\program files\AVG\AVG10\mfazt.lns
c:\program files\AVG\AVG2012\awacs\dav\component\content.dat
c:\program files\AVG\AVG2012\awacs\dav\component\image.bmp
c:\program files\AVG\AVG2012\awacs\dav\sign.bin
c:\program files\AVG\AVG2012\awacs\fas\component\content.dat
c:\program files\AVG\AVG2012\awacs\fas\component\image.bmp
c:\program files\AVG\AVG2012\awacs\fas\sign.bin
c:\program files\AVG\AVG2012\awacs\obx\component\content.dat
c:\program files\AVG\AVG2012\awacs\obx\component\image.bmp
c:\program files\AVG\AVG2012\awacs\obx\sign.bin
c:\program files\AVG\AVG2012\awacs\pct\component\content.dat
c:\program files\AVG\AVG2012\awacs\pct\component\image.bmp
c:\program files\AVG\AVG2012\awacs\pct\sign.bin
c:\program files\AVG\AVG2012\awacs\rules.cat
c:\program files\AVG\AVG2012\awacs\rules.js
c:\program files\AVG\AVG2012\awacs\speedtest\component\content.dat
c:\program files\AVG\AVG2012\awacs\speedtest\component\speedtest.bmp
c:\program files\AVG\AVG2012\awacs\speedtest\sign.bin
c:\program files\AVG\AVG2012\awacs\techbuddy\component\content.dat
c:\program files\AVG\AVG2012\awacs\techbuddy\component\techbuddy.mht
c:\program files\AVG\AVG2012\awacs\techbuddy\sign.bin
.
.
((((((((((((((((((((((((( Files Created from 2012-02-12 to 2012-03-12 )))))))))))))))))))))))))))))))
.
.
2012-03-09 19:48 . 2012-03-09 19:48 ——– d—–w- c:\documents and settings\Administrator
2012-02-28 15:40 . 2012-02-28 15:40 ——– d—–w- c:\documents and settings\Owner\Application Data\PeaZip
2012-02-26 22:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2012-02-26 22:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-24 18:01 . 2011-05-18 12:25 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-12 16:53 . 2006-02-28 12:00 1859968 —-a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2006-02-28 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2006-02-28 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2006-02-28 12:00 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-29_21.49.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-03-10 20:06 . 2012-03-10 20:06 16384 c:\windows\Temp\Perflib_Perfdata_670.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 11:58 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
.
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"POP Peeper"="c:\program files\POP Peeper\POPPeeper.exe" [2011-11-16 1613824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-13 88209]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-07-21 1155122]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [03/05/2004 16:26 80384]
S4 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [01/10/2010 15:25 4064]
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: {{5D40A133-FB02-4405-BE17-A3FC8749DF4E} - c:\program files\FreshDevices\FreshDownload\fd.exe
TCP: DhcpNameServer = 192.168.1.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-03-12 16:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2012-03-12 16:34:10
ComboFix-quarantined-files.txt 2012-03-12 16:33
ComboFix2.txt 2012-03-01 18:38
ComboFix3.txt 2012-02-29 21:55
.
Pre-Run: 100,615,675,904 bytes free
Post-Run: 100,636,790,784 bytes free
.
- - End Of File - - 482F90FE02F3EB831B2565AEFFC43635