:Services
:OTL
[2013/10/15 19:03:07 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{AE2BE12A-1C10-4A8D-9BB4-59A5767EC937}
[2013/10/14 19:17:47 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{072761EB-DC9F-4C93-BB0F-B18028C65FB2}
[2013/10/13 16:06:49 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{AA92B5E2-DEB5-4663-950E-F8B41AC469E0}
[2013/10/12 21:12:52 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{40765683-2013-40F3-B64D-EBE6658A8CFE}
[2013/10/11 16:37:09 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{57EE98AB-1480-4075-A0F6-F394C93CE45D}
[2013/10/10 18:23:54 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{5CEDD1F4-D11D-4610-B1CE-6F0EC73307BD}
[2013/10/09 21:42:46 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{F94E2F0A-F2E6-4CF1-8F32-532A0ABDA740}
[2013/10/08 20:03:22 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{69CA6D99-6704-4BE4-9BD6-9B6E96ED545A}
[2013/10/07 18:39:56 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{6274E686-5D61-4B46-87FA-D2E5D1649304}
[2013/10/06 22:04:39 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{4F7E4025-FDCE-4E73-BBA3-211553566F69}
[2013/10/04 21:45:41 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{9E73BC06-E3A1-4308-9606-1BA1797D92CE}
[2013/10/01 21:43:07 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{A0415910-EE73-4B61-8890-049CE1B5BC4F}
[2013/09/30 19:23:43 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{B3F38E2F-61A8-4641-9675-72C9C87F5E2E}
[2013/09/29 17:38:18 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{46AE973A-D8D5-442F-BAC2-0B50198A29B5}
[2013/09/28 13:58:54 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{F5B512A0-080B-4D59-9E39-24B0934D7444}
[2013/09/27 17:09:23 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{AAA5AD37-AD2A-4F8F-A43B-0A6A8EAEA5B7}
[2013/09/26 21:45:06 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{BBAB14BE-5F53-4AAE-8819-1E1CA1B97E20}
[2013/09/25 20:02:58 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{E7F11B73-F994-4D7E-824C-D6D38B33C2BA}
[2013/09/24 22:15:22 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{E216344C-53BA-4434-B3C0-351766D0A8F8}
[2013/09/23 19:01:00 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{3410FAC1-A772-4562-9A4F-17D40DBF2E6E}
[2013/09/22 20:45:34 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{E297080A-AFEA-4D03-8D14-93FA9BBE542D}
[2013/09/21 19:54:18 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{A3268A0F-A3C0-4D71-8497-020DF6C1850B}
[2013/09/20 14:52:41 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\{697F6BEC-58BF-43EB-A6EC-6D1720DE4A62}
[2013/10/16 18:29:58 | 095,025,368 | ---- | M] () -- C:\ProgramData\dw2j6bnd.pff
[2013/10/16 18:28:02 | 000,000,000 | ---- | M] () -- C:\ProgramData\dw2j6bnd.ctrl
[2013/10/15 19:52:06 | 000,001,049 | ---- | M] () -- C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dw2j6bnd.lnk
[2013/10/15 19:52:06 | 000,001,049 | ---- | C] () -- C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dw2j6bnd.lnk
[2013/10/15 19:52:06 | 000,000,000 | ---- | C] () -- C:\ProgramData\dw2j6bnd.ctrl
[2013/10/15 19:52:05 | 095,025,368 | ---- | C] () -- C:\ProgramData\dw2j6bnd.pff
[2011/05/19 17:57:26 | 000,001,940 | ---- | C] () -- C:\Users\John\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:0B9176C0
:Reg
:Commands
[purity]
[emptytemp]
[Reboot]