:OTL
SRV - (SoftwareUpd) -- C:\Users\Anna\AppData\Local\SoftwareUpdater\Softwa reUpdService.exe (SoftwareUpdService)
SRV - (PowerOffer Service) -- C:\Users\Anna\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\Anna\AppData\Local\ServUpdater\ServiceUpd .exe (ServiceUpd)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\emoticoons-toolbar@emoticoons.com: C:\Users\Public\Documents\Emoticoons\emoticoons-toolbar@emoticoons.com [2012/05/26 23.21.19 | 000,000,000 | ---D | M]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{3a539854-6a70-11db-887c-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{9E2CAAF8-4E6C-4FEC-A73A-C1E345331B16}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{FAB2DED7-A12D-491A-80EF-9DCB4E51D459}: NameServer = 176.31.229.24,176.31.229.25
[2012/12/22 13.39.24 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/12/22 12.13.59 | 000,000,000 | ---D | C] -- C:\Qoobox
@Alternate Data Stream - 76 bytes -> C:\Users\Anna\Documents\Updater5:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Anna\Documents\National-Treasure.2.Il.Mistero.Delle.Pagine.Perdute.2007.iT ALiAN.TELESYNC.XviD.CD2-SiLENT.avi:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Anna\Documents\National-Treasure.2.Il.Mistero.Delle.Pagine.Perdute.2007.iT ALiAN.TELESYNC.XviD.CD1-SiLENT.avi:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Anna\Documents\Gadget Google personali:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Anna\Documents\1899126704.jpg:Roxio EMC Stream
@Alternate Data Stream - 64 bytes -> C:\Users\Anna\Documents\National-Treasure.2.Il.Mistero.Delle.Pagine.Perdute.2007.iT ALiAN.TELESYNC.XviD.CD2-SiLENT.avi:TOC.WMV
:Files
ipconfig /flushdns /c
:commands
[purity]
[Reboot]