OTL Extras logfile created on: 27/02/2013 13:40:53 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\laurent\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy 1,99 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 63,35% Memory free 3,98 Gb Paging File | 3,29 Gb Available in Paging File | 82,54% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,69 Gb Total Space | 77,26 Gb Free Space | 69,17% Space Free | Partition Type: NTFS Drive D: | 111,43 Gb Total Space | 98,41 Gb Free Space | 88,32% Space Free | Partition Type: NTFS Computer Name: LAURENT-PC | User Name: laurent | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2270173921-2274148607-741466337-1001\SOFTWARE\Classes\] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- Reg Error: Key error. https [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00994411-F181-44DA-9674-E2CA8248363D}" = rport=139 | protocol=6 | dir=out | app=system | "{15E39C14-9D61-4370-B1C8-A459E325960F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{2F81085A-877D-47D8-BD4E-FF16FC76159A}" = rport=138 | protocol=17 | dir=out | app=system | "{37529948-F283-451E-B5AD-784AB49CB973}" = lport=139 | protocol=6 | dir=in | app=system | "{41D10739-D345-4EED-A553-6FB9C871649A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{49278609-99D8-43B0-8407-88D84FBA393D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{4F1C356D-AF05-459A-8ED3-D411DA8BEB9E}" = lport=10243 | protocol=6 | dir=in | app=system | "{5B7CF83A-6CC0-402E-9D79-FA7D270A9A14}" = lport=48113 | protocol=6 | dir=in | name=maconfig_tcp | "{5E3AE836-4A86-4F3E-A3CB-C91874377E99}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{68686507-DC8D-4D90-A4AC-AC26D544B8EB}" = rport=10243 | protocol=6 | dir=out | app=system | "{6BAFE175-F1A8-4DAA-81BA-84F5CA039E59}" = lport=48113 | protocol=17 | dir=in | name=maconfig_udp | "{6D9370E2-D947-438F-8C69-F443C7B3E4B3}" = lport=2869 | protocol=6 | dir=in | app=system | "{83473B87-5E1E-42AD-A8DB-559303400A77}" = rport=445 | protocol=6 | dir=out | app=system | "{8C499FBD-2657-4E58-B304-7CCDA913887F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{90671377-9DE5-4061-BB56-5E131DCC3609}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{93EA8459-AC60-4EAE-9028-5E36C716B0C8}" = lport=137 | protocol=17 | dir=in | app=system | "{98E8EF47-6287-4322-AF9D-ABF6C7BCF277}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A283EA40-5DE9-46BB-87F0-4D9AC4912382}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{A3772BC0-A31C-43D7-8CA7-6EA68587BC19}" = lport=138 | protocol=17 | dir=in | app=system | "{A5C361D8-F44B-4726-A5B1-6E35D58E4E13}" = lport=445 | protocol=6 | dir=in | app=system | "{B2841AA2-5718-4D58-B106-658627C48C15}" = lport=2869 | protocol=6 | dir=in | app=system | "{D062AFEB-EAD2-4CE5-9775-16DC31BA9282}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{DCB1DE52-AAD1-4554-B0CF-F12162046184}" = rport=137 | protocol=17 | dir=out | app=system | "{EAA9DCAE-8FEA-4D85-9ADA-1B5E6A894224}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{F844C698-8F5D-41AA-9FE1-E7EA8E644A78}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{08136F59-7C39-4C3F-927E-7E844BAAE093}" = protocol=6 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{133802B5-E829-4357-B8A6-95161A656A27}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{1550A074-7241-4447-A9FD-88CB87722B80}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{21E7EAB1-FEFC-4AFB-AF9F-3BDF35C55578}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{23AAC2CE-9C9E-493A-AEFF-FB03AE2A2AA0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{253AAF5E-ECE1-4E42-8534-F5F3F5806CAF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{254C9EBE-E413-4BB5-BB51-A66CC53F7CF4}" = protocol=6 | dir=out | app=system | "{2FE61FEE-FE8A-4AAB-BFF7-244E199E16E1}" = protocol=17 | dir=in | app=c:\users\laurent\appdata\local\temp\7zs9e12.tmp\symnrt.exe | "{31FA9C43-35DF-4D01-BFFD-AE95969FD4CC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{36B27051-E2D6-4605-8694-55DB14E6AD42}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{3CD4CB31-AA5E-47C1-9A82-B42129340620}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{504B0537-CDD6-415A-A95D-5E28513DB5C1}" = protocol=6 | dir=in | app=c:\windows\system32\msiexec.exe | "{5305E5EF-662A-475E-9A48-C5882B910DF6}" = protocol=17 | dir=in | app=c:\windows\system32\msiexec.exe | "{62B4CE29-1C26-4E12-937F-0788DC25F4D4}" = protocol=17 | dir=in | app=c:\program files\ma-config.com\maconfservice.exe | "{76FB4F1E-7EE3-4744-96E6-6DB683925CDD}" = protocol=6 | dir=in | app=c:\program files\ma-config.com\maconfservice.exe | "{7DD0D3F3-069E-4CB8-B760-4BE61AC3A4FA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8AC3CC11-B7BF-443F-BE56-3BE8F6CFC2B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8B89294A-E237-408F-A9E1-E1586918C451}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{91608543-79A8-4563-BA39-AB43ED996888}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{9415BBEB-5100-4B8D-B66B-E5B70CCE2524}" = protocol=17 | dir=in | app=c:\program files\sweetim\communicator\sweetpacksupdatemanager.exe | "{97783D06-F40C-4DE7-AD28-6C602F59A896}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{A52AFD94-A001-410B-BCE1-4443C367530F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{B0466D59-8106-4E45-86CB-8575526EDE75}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{C5CC1A37-538E-4423-A5AC-9D1F338E1227}" = protocol=6 | dir=in | app=c:\users\laurent\appdata\local\temp\7zs249f.tmp\symnrt.exe | "{C9FC3F42-4BC5-4DDD-8118-7B03EBB8C626}" = protocol=17 | dir=in | app=c:\users\laurent\appdata\local\temp\7zs249f.tmp\symnrt.exe | "{E01F6568-B8B6-429B-B3D3-067458FFE7B3}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{E2ECF62A-3134-456C-A3AD-CD1C6A55E378}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E36116DC-28F4-4D15-9B66-963EF856DAD5}" = protocol=6 | dir=in | app=c:\users\laurent\appdata\local\temp\7zs9e12.tmp\symnrt.exe | "{EF5851C8-B567-40FC-A73A-4DC38B209AAF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{05653DE1-6567-40C6-B930-39D399B64369}" = OpenOffice.org 3.3 "{0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}" = Microsoft .NET Framework 4 Client Profile FRA Language Pack "{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR "{18754BA4-4F0C-4E6E-888B-9496AFA05F43}" = Ma-Config.com "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22 "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 37 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel "{AA047D7C-5E7C-4878-B75C-77589151B563}" = Acer Crystal Eye webcam "{AC76BA86-7AD7-1036-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Français "{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9 "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars "{CD95F661-A5C4-44F5-A6AA-ECDD91C240D6}" = WinZip 17.0 "{EA5F34F3-3911-B4DB-63CA-1E44B2AB13A1}" = Adobe Download Assistant "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "CCleaner" = CCleaner "com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant "HDMI" = Intel(R) Graphics Media Accelerator Driver "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100 "McAfee Security Scan" = McAfee Security Scan Plus "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile FRA Language Pack" = Module linguistique Microsoft .NET Framework 4 Client Profile FRA "Mon Carnet d'Adresses_is1" = Mon Carnet d'Adresses "Mozilla Firefox 19.0 (x86 fr)" = Mozilla Firefox 19.0 (x86 fr) "MozillaMaintenanceService" = Mozilla Maintenance Service "TVWiz" = Intel(R) TV Wizard "WBFS Manager 3.0" = WBFS Manager 3.0 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 28/01/2013 12:25:54 | Computer Name = laurent-PC | Source = System Restore | ID = 8193 Description = Error - 28/01/2013 12:25:55 | Computer Name = laurent-PC | Source = VSS | ID = 12289 Description = Error - 28/01/2013 15:30:00 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 28/01/2013 15:30:00 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 10030 Error - 28/01/2013 15:30:00 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 10030 Error - 28/01/2013 17:34:09 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 28/01/2013 17:34:09 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 7459562 Error - 28/01/2013 17:34:09 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 7459562 Error - 29/01/2013 01:45:41 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second Error - 29/01/2013 01:45:41 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 21616965 Error - 29/01/2013 01:45:41 | Computer Name = laurent-PC | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 21616965 [ System Events ] Error - 17/02/2012 15:25:15 | Computer Name = laurent-PC | Source = ACPI | ID = 327693 Description =  : le contrôleur embarqué n’a pas répondu dans le délai imparti. Cette erreur peut indiquer que le matériel ou le microprogramme du contrôleur embarqué présente une erreur ou que le BIOS accède au contrôleur embarqué de manière incorrecte. Contactez le fabricant de votre ordinateur afin de savoir si un BIOS mis à niveau est disponible. Dans certains cas, cette erreur peut provoquer un fonctionnement incorrect de l’application. Error - 22/02/2012 07:52:29 | Computer Name = laurent-PC | Source = DCOM | ID = 10010 Description = Error - 23/02/2012 13:43:45 | Computer Name = laurent-PC | Source = EventLog | ID = 6008 Description = L’arrêt système précédant à 15:39:41 le ?23/?02/?2012 n’était pas prévu. Error - 29/02/2012 08:40:17 | Computer Name = laurent-PC | Source = EventLog | ID = 6008 Description = L’arrêt système précédant à 22:26:09 le ?28/?02/?2012 n’était pas prévu. Error - 02/03/2012 08:06:17 | Computer Name = laurent-PC | Source = DCOM | ID = 10010 Description = Error - 30/03/2012 13:29:59 | Computer Name = laurent-PC | Source = EventLog | ID = 6008 Description = L’arrêt système précédant à 10:30:03 le ?30/?03/?2012 n’était pas prévu. Error - 15/04/2012 04:53:14 | Computer Name = laurent-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Échec de l’installation : l’installation de la mise à jour suivante a échoue avec l’erreur 0x800f020b : SAMSUNG Electronics Co., Ltd. - Other hardware - SAMSUNG Mobile USB Composite Device. Error - 17/04/2012 10:57:07 | Computer Name = laurent-PC | Source = DCOM | ID = 10010 Description = Error - 17/04/2012 10:57:46 | Computer Name = laurent-PC | Source = DCOM | ID = 10010 Description = Error - 17/04/2012 11:01:57 | Computer Name = laurent-PC | Source = Microsoft-Windows-Application-Experience | ID = 205 Description = Le service de l’Assistant Compatibilité des programmes n’a pas pu effectuer la phase 2 de l’initialisation. < End of report >