:OTL
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382901588&from=cor&uid=WDCXWD5000AAKS-22V1A0_WD-WCAWF535717957179&q={searchTerms}
O2 - BHO: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
[2013/11/08 16:51:56 | 000,001,406 | ---- | M] () -- C:\Windows\tasks\weDownload Manager Pro-updater.job
[2013/11/08 16:51:53 | 000,002,038 | ---- | M] () -- C:\Windows\tasks\weDownload Manager Pro-chromeinstaller.job
[2013/11/08 16:51:52 | 000,001,308 | ---- | M] () -- C:\Windows\tasks\weDownload Manager Pro-codedownloader.job
[2013/11/08 16:51:52 | 000,001,208 | ---- | M] () -- C:\Windows\tasks\weDownload Manager Pro-enabler.job
:Files
C:\Program Files (x86)\weDownload Manager Pro
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]