:OTL
IE - HKU\S-1-5-21-535872200-2807451337-2880032468-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = astroburn-search.com
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=302398&p="
[2011-08-28 21:18:08 | 000,002,071 | ---- | M] () -- C:\Users\Dariusz Bizacki\AppData\Roaming\Mozilla\Firefox\Profiles\d9o7gx3v.default\searchplugins\absearch-search.xml
O4 - HKU\S-1-5-21-535872200-2807451337-2880032468-1000..\Run: [] File not found
O8 - Extra context menu item: 使用快车3下载 - C:\Users\Dariusz Bizacki\AppData\Roaming\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: 使用快车3下载全部链接 - C:\Users\Dariusz Bizacki\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()
O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} -
http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?PL File not found
O15 - HKU\S-1-5-21-535872200-2807451337-2880032468-1000\..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
:Files
C:\Windows\System32\secustat.dat
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"=-
:Commands
[clearallrestorepoints]
[emptytemp]