:OTL
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OC&...archTerms}
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.asp...=CT2776682
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OC&...archTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OC&...archTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OC&...archTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OC&...archTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OC&...archTerms}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTe...fba6299a64
[2013/02/08 10:18:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jake\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2013/02/08 10:18:02 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\Jake\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\torntv@torntv.com.xpi
[2013/01/10 10:10:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/01/10 10:05:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2013/01/10 10:05:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
CHR - homepage: http://www.delta-search.com/?affID=11977...fba6299a64
CHR - Extension: No name found = C:\Users\Jake\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Jake\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Jake\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: No name found = C:\Users\Jake\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: No name found = C:\Users\Jake\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.5.0.11422_0\
CHR - Extension: No name found = C:\Users\Jake\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
:Files
C:\Users\Jake\AppData\Roaming\Ybneu
C:\Users\Jake\AppData\Roaming\Miepxi
C:\Users\Jake\AppData\Roaming\Luyxky
C:\Users\Jake\AppData\Roaming\Axof
C:\ProgramData\Babylon
C:\Windows\SysWow64\searchplugins
C:\Users\Jake\AppData\Roaming\Qymy
C:\Users\Jake\AppData\Roaming\Hefel
C:\ProgramData\FullRemove.exe
C:\Users\Jake\AppData\Local\10435a4b-d052-45f0-b5db-96aede485c70.crx
C:\Users\Jake\AppData\Roaming\wklnhst.dat
C:\Users\Jake\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Jake\AppData\Roaming\room_v3.dat
C:\Users\Jake\AppData\Roaming\UserTile.png
C:\ProgramData\LauncherAccess.dt
c:\Users\Jake\AppData\Roaming\wklnhst.dat
C:\Users\Jake\AppData\Local\Jdogag.dat
C:\Users\Jake\AppData\Local\Kfakit.bin
C:\$Recycle.Bin\S-1-5-18\$5f6e5e2c6241a5a94a20ebcf4439c338\@
C:\$Recycle.Bin\S-1-5-18\$5f6e5e2c6241a5a94a20ebcf4439c338\L
C:\$Recycle.Bin\S-1-5-18\$5f6e5e2c6241a5a94a20ebcf4439c338\U
C:\Windows\assembly\Desktop.ini
C:\$Recycle.Bin\S-1-5-18\
C:\Users\Jake\AppData\Roaming\Ybneu
C:\ProgramData\Temp:AB689DEA
C:\ProgramData\Temp:5D7E5A8F
C:\ProgramData\Temp:4D066AD2
C:\ProgramData\Temp:93DE1838
C:\ProgramData\Temp:E1F04E8D
C:\ProgramData\Temp:1D32EC29
C:\ProgramData\Temp:0B9176C0
C:\ProgramData\Temp:E3C56885
C:\ProgramData\Temp:ABE89FFE
C:\ProgramData\Temp:4CF61E54
C:\ProgramData\Temp:D06A4C76
:commands
[emptytemp]
[reboot]