Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Getting Hard Disk Error, wondering if virus


  • This topic is locked This topic is locked
11 replies to this topic

#1 heatherjoy83

heatherjoy83

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:33 PM

Posted 01 January 2014 - 02:27 PM

After starting up my computer and getting signed into Windows, I get a popup that states: "Windows detected a hard disk problem. Back up your files immediately to prevent information loss, and then contact the computer manufacturer to determine if you need to repair or replace the disk." It then gives me options to "Start the backup process" or "Ask me again later."

 

My Toshiba HDD/SDD Alert reads: "Your HDD has the SMART Predict Failure function which monitors the HDD operating status. Your HDD is experienccing a problem and SMART monitoring software predicts that the HDD will fail. Toshiba strongly recommends you create a back-up for your HDD data. THen contact an authorized service provider in order to chekc your drive and purchase a new replacement drive if necessary. Do you wish to start Windows Complete PC backup now?"

 

All my files are backed up on an external hd. I have been getting this alert for a few months. In the last month, I decided to wipe my hard drive and restore it back to original. I used the backup discs that I had created when I first got my laptop. After doing this, I still get the error message. Maybe the HD really does have a problem. Any help would be greatly appreciated. Thanks!!

 

I pasted the DDS log below and attached the attach.txt file as the posting instructions stated.

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7600.17267
Run by Heather at 12:07:57 on 2014-01-01
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.3891.2014 [GMT -6:00]
.
AV: Norton Internet Security *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe
C:\Program Files (x86)\TOSHIBA\ToshibaRegistration\TaisRegistPinger.exe
C:\windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe
C:\windows\system32\DFDWiz.exe
C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\17.5.0.127\InstStub.exe
C:\windows\Explorer.EXE
C:\windows\system32\Dwm.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\igfxext.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
C:\Program Files\TOSHIBA\HDMICtrlMan\HCMSoundChanger.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosBulletinBoard.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSSDAlert.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\windows\SysWow64\Macromed\Flash\FlashUtil10e.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
uDefault_Page_URL = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\CoIEPlg.dll
BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\IPSBHO.dll
BHO: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\CoIEPlg.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRunOnce: [FlashPlayerUpdate] C:\windows\SysWow64\Macromed\Flash\FlashUtil10e.exe
mRun: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
mRun: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [TRCMan] C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe
mRun: [TSleepSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" UNATTENDED
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{E4E0B096-C2C6-4AD8-BC64-3E2AC465A3F8} : DHCPNameServer = 192.168.0.1
SSODL: WebCheck - <orphaned>
x64-BHO: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [ThpSrv] C:\windows\System32\thpsrv /logon
x64-Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
x64-Run: [HSON] C:\Program Files (x86)\TOSHIBA\TBS\HSON.exe
x64-Run: [SmoothView] C:\Program Files (x86)\Toshiba\SmoothView\SmoothView.exe
x64-Run: [00TCrdMain] C:\Program Files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
x64-Run: [Teco] "C:\Program Files (x86)\TOSHIBA\TECO\Teco.exe" /r
x64-Run: [TosWaitSrv] C:\Program Files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
x64-Run: [SmartFaceVWatcher] C:\Program Files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
x64-Run: [HDMICtrlMan] C:\Program Files (x86)\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
x64-Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
x64-Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
x64-Run: [TosNC] C:\Program Files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
x64-Run: [TosReelTimeMonitor] C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\windows\System32\drivers\thpdrv.sys [2009-6-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\windows\System32\drivers\Thpevm.sys [2009-6-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\System32\drivers\tos_sps64.sys [2013-12-12 482384]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe [2013-12-12 126392]
R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2013-12-12 103792]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2013-12-12 126392]
R2 taisregispinger;taisregispinger;C:\Program Files (x86)\TOSHIBA\ToshibaRegistration\TaisRegistPinger.exe [2010-5-6 297344]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-4-6 258928]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2013-12-12 2320920]
R3 HECIx64;Intel® Management Engine Interface;C:\windows\System32\drivers\HECIx64.sys [2013-12-12 56344]
R3 Impcd;Impcd;C:\windows\System32\drivers\Impcd.sys [2010-2-26 158976]
R3 IntcDAud;Intel® Display Audio;C:\windows\System32\drivers\IntcDAud.sys [2010-2-3 271872]
R3 PGEffect;Pangu effect driver;C:\windows\System32\drivers\PGEffect.sys [2013-12-12 35008]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2013-12-12 330856]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\windows\System32\drivers\rtl8192se.sys [2013-12-12 1103904]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2013-12-12 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-2-23 835952]
S3 acpials;ALS Sensor Filter;C:\windows\System32\drivers\acpials.sys [2009-7-14 9728]
S3 JMCR;JMCR;C:\windows\System32\drivers\jmcr.sys [2010-5-18 164464]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2010-5-6 332272]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2013-12-14 1255736]
.
=============== Created Last 30 ================
.
2014-01-01 17:47:21 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A97EDCA-2EEC-42E5-82C7-0753C72817DF}\offreg.dll
2014-01-01 06:07:17 -------- d-----w- C:\Users\Heather\AppData\Local\Tific
2014-01-01 06:07:10 -------- d-----w- C:\Users\Heather\AppData\Roaming\Tific
2014-01-01 05:35:46 10315576 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0A97EDCA-2EEC-42E5-82C7-0753C72817DF}\mpengine.dll
2013-12-15 03:39:53 99328 ----a-w- C:\windows\System32\drivers\usbccgp.sys
2013-12-15 03:39:53 52224 ----a-w- C:\windows\System32\drivers\usbehci.sys
2013-12-15 03:39:53 343040 ----a-w- C:\windows\System32\drivers\usbhub.sys
2013-12-15 03:39:53 324608 ----a-w- C:\windows\System32\drivers\usbport.sys
2013-12-15 03:39:52 7936 ----a-w- C:\windows\System32\drivers\usbd.sys
2013-12-15 03:39:52 30720 ----a-w- C:\windows\System32\drivers\usbuhci.sys
2013-12-15 03:39:52 25600 ----a-w- C:\windows\System32\drivers\usbohci.sys
2013-12-15 03:38:57 2566144 ----a-w- C:\windows\System32\esent.dll
2013-12-15 03:38:57 1686016 ----a-w- C:\windows\SysWow64\esent.dll
2013-12-15 03:38:57 166272 ----a-w- C:\windows\System32\drivers\nvstor.sys
2013-12-15 03:38:57 148352 ----a-w- C:\windows\System32\drivers\nvraid.sys
2013-12-15 03:38:57 107904 ----a-w- C:\windows\System32\drivers\amdsata.sys
2013-12-15 03:38:56 96768 ----a-w- C:\windows\System32\fsutil.exe
2013-12-15 03:38:56 410496 ----a-w- C:\windows\System32\drivers\iaStorV.sys
2013-12-15 03:38:56 27008 ----a-w- C:\windows\System32\drivers\amdxata.sys
2013-12-15 03:38:56 187264 ----a-w- C:\windows\System32\drivers\storport.sys
2013-12-15 03:38:55 74240 ----a-w- C:\windows\SysWow64\fsutil.exe
2013-12-15 03:33:39 10285968 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-12-15 03:30:21 -------- d-----w- C:\windows\SysWow64\Wat
2013-12-15 03:30:18 -------- d-----w- C:\windows\System32\Wat
2013-12-13 11:49:10 -------- d-----w- C:\Users\Heather\AppData\Local\TOSHIBA_Corporation
2013-12-13 08:24:08 367104 ----a-w- C:\windows\System32\wcncsvc.dll
2013-12-13 08:24:08 276992 ----a-w- C:\windows\SysWow64\wcncsvc.dll
2013-12-13 07:59:32 2560 ----a-w- C:\windows\System32\drivers\en-US\wdf01000.sys.mui
2013-12-13 07:59:31 9728 ----a-w- C:\windows\System32\Wdfres.dll
2013-12-13 07:59:31 785512 ----a-w- C:\windows\System32\drivers\Wdf01000.sys
2013-12-13 07:59:31 54376 ----a-w- C:\windows\System32\drivers\WdfLdr.sys
2013-12-13 07:48:09 99176 ----a-w- C:\windows\SysWow64\PresentationHostProxy.dll
2013-12-13 07:48:09 49472 ----a-w- C:\windows\SysWow64\netfxperf.dll
2013-12-13 07:48:09 320352 ----a-w- C:\windows\System32\PresentationHost.exe
2013-12-13 07:48:09 297808 ----a-w- C:\windows\SysWow64\mscoree.dll
2013-12-13 07:48:09 295264 ----a-w- C:\windows\SysWow64\PresentationHost.exe
2013-12-13 07:48:09 1130824 ----a-w- C:\windows\SysWow64\dfshim.dll
2013-12-13 07:48:09 109912 ----a-w- C:\windows\System32\PresentationHostProxy.dll
2013-12-13 07:48:08 48960 ----a-w- C:\windows\System32\netfxperf.dll
2013-12-13 07:48:08 444752 ----a-w- C:\windows\System32\mscoree.dll
2013-12-13 07:48:08 1942856 ----a-w- C:\windows\System32\dfshim.dll
2013-12-13 07:32:06 46080 ----a-w- C:\windows\System32\atmlib.dll
2013-12-13 07:32:06 34304 ----a-w- C:\windows\SysWow64\atmlib.dll
2013-12-13 07:32:05 367616 ----a-w- C:\windows\System32\atmfd.dll
2013-12-13 07:32:05 295424 ----a-w- C:\windows\SysWow64\atmfd.dll
2013-12-13 07:29:04 87040 ----a-w- C:\windows\System32\drivers\WUDFPf.sys
2013-12-13 07:29:04 198656 ----a-w- C:\windows\System32\drivers\WUDFRd.sys
2013-12-13 07:29:01 84992 ----a-w- C:\windows\System32\WUDFSvc.dll
2013-12-13 07:29:01 194048 ----a-w- C:\windows\System32\WUDFPlatform.dll
2013-12-13 07:28:57 45056 ----a-w- C:\windows\System32\WUDFCoinstaller.dll
2013-12-13 07:28:56 744448 ----a-w- C:\windows\System32\WUDFx.dll
2013-12-13 07:28:56 229888 ----a-w- C:\windows\System32\WUDFHost.exe
2013-12-13 07:17:31 -------- d-----w- C:\windows\System32\MRT
2013-12-13 07:15:00 80896 ----a-w- C:\windows\System32\imagehlp.dll
2013-12-13 07:15:00 22896 ----a-w- C:\windows\System32\drivers\fs_rec.sys
2013-12-13 07:14:59 158720 ----a-w- C:\windows\SysWow64\imagehlp.dll
2013-12-13 07:14:56 5120 ----a-w- C:\windows\SysWow64\wmi.dll
2013-12-13 07:14:56 5120 ----a-w- C:\windows\System32\wmi.dll
2013-12-13 07:07:52 243712 ----a-w- C:\windows\System32\drivers\ks.sys
2013-12-13 07:07:52 184832 ----a-w- C:\windows\System32\drivers\usbvideo.sys
2013-12-13 07:00:37 3138048 ----a-w- C:\windows\System32\mstscax.dll
2013-12-13 07:00:35 2691072 ----a-w- C:\windows\SysWow64\mstscax.dll
2013-12-13 07:00:33 44032 ----a-w- C:\windows\System32\tsgqec.dll
2013-12-13 07:00:33 158208 ----a-w- C:\windows\System32\aaclient.dll
2013-12-13 07:00:33 131072 ----a-w- C:\windows\SysWow64\aaclient.dll
2013-12-13 07:00:32 36864 ----a-w- C:\windows\SysWow64\tsgqec.dll
2013-12-13 06:59:43 340992 ----a-w- C:\windows\System32\schannel.dll
2013-12-13 06:59:43 225280 ----a-w- C:\windows\SysWow64\schannel.dll
2013-12-13 06:59:43 1446912 ----a-w- C:\windows\System32\lsasrv.dll
2013-12-13 06:59:42 459216 ----a-w- C:\windows\System32\drivers\cng.sys
2013-12-13 06:59:42 152432 ----a-w- C:\windows\System32\drivers\ksecpkg.sys
2013-12-13 06:59:41 95088 ----a-w- C:\windows\System32\drivers\ksecdd.sys
2013-12-13 06:59:40 96768 ----a-w- C:\windows\SysWow64\sspicli.dll
2013-12-13 06:59:40 31232 ----a-w- C:\windows\System32\lsass.exe
2013-12-13 06:59:40 28672 ----a-w- C:\windows\System32\sspisrv.dll
2013-12-13 06:59:40 28160 ----a-w- C:\windows\System32\secur32.dll
2013-12-13 06:59:40 22016 ----a-w- C:\windows\SysWow64\secur32.dll
2013-12-13 06:59:40 136192 ----a-w- C:\windows\System32\sspicli.dll
2013-12-13 06:56:58 552960 ----a-w- C:\windows\System32\msdri.dll
2013-12-13 06:56:00 424960 ----a-w- C:\windows\System32\KernelBase.dll
2013-12-13 06:51:50 204800 ----a-w- C:\windows\System32\drivers\rdpwd.sys
2013-12-13 05:54:50 142336 ----a-w- C:\windows\System32\poqexec.exe
2013-12-13 05:54:50 123904 ----a-w- C:\windows\SysWow64\poqexec.exe
2013-12-13 05:54:46 1395712 ----a-w- C:\windows\System32\mfc42.dll
2013-12-13 05:54:46 1359872 ----a-w- C:\windows\System32\mfc42u.dll
2013-12-13 05:54:45 1164288 ----a-w- C:\windows\SysWow64\mfc42u.dll
2013-12-13 05:54:45 1137664 ----a-w- C:\windows\SysWow64\mfc42.dll
2013-12-13 05:54:42 307200 ----a-w- C:\windows\System32\ncrypt.dll
2013-12-13 05:54:42 219136 ----a-w- C:\windows\SysWow64\ncrypt.dll
2013-12-13 05:54:22 509952 ----a-w- C:\windows\System32\ntshrui.dll
2013-12-13 05:54:22 442880 ----a-w- C:\windows\SysWow64\ntshrui.dll
2013-12-13 05:54:18 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2013-12-13 05:54:17 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2013-12-13 05:54:05 1653096 ----a-w- C:\windows\System32\drivers\ntfs.sys
2013-12-13 05:53:48 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2013-12-13 05:53:48 2048 ----a-w- C:\windows\System32\tzres.dll
2013-12-13 05:52:39 395776 ----a-w- C:\windows\System32\webio.dll
2013-12-13 05:52:38 314368 ----a-w- C:\windows\SysWow64\webio.dll
2013-12-13 05:52:33 714752 ----a-w- C:\windows\System32\kerberos.dll
2013-12-13 05:52:33 541184 ----a-w- C:\windows\SysWow64\kerberos.dll
2013-12-13 05:52:26 961024 ----a-w- C:\windows\System32\CPFilters.dll
2013-12-13 05:52:25 642048 ----a-w- C:\windows\SysWow64\CPFilters.dll
2013-12-13 05:52:24 850432 ----a-w- C:\windows\SysWow64\sbe.dll
2013-12-13 05:52:24 259072 ----a-w- C:\windows\System32\mpg2splt.ax
2013-12-13 05:52:24 199680 ----a-w- C:\windows\SysWow64\mpg2splt.ax
2013-12-13 05:52:24 1118720 ----a-w- C:\windows\System32\sbe.dll
2013-12-13 05:52:19 172544 ----a-w- C:\windows\SysWow64\wintrust.dll
2013-12-13 05:52:18 220160 ----a-w- C:\windows\System32\wintrust.dll
2013-12-13 05:50:52 264192 ----a-w- C:\windows\System32\upnp.dll
2013-12-13 05:49:55 1114624 ----a-w- C:\windows\System32\schedsvc.dll
2013-12-13 05:48:58 516096 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-12-13 05:47:59 82944 ----a-w- C:\windows\SysWow64\iccvid.dll
2013-12-13 05:46:52 95744 ----a-w- C:\windows\System32\synceng.dll
2013-12-13 05:46:52 78336 ----a-w- C:\windows\SysWow64\synceng.dll
2013-12-13 05:46:26 603976 ----a-w- C:\windows\System32\winload.exe
2013-12-13 05:46:25 640896 ----a-w- C:\windows\System32\winload.efi
2013-12-13 05:46:25 518160 ----a-w- C:\windows\System32\winresume.exe
2013-12-13 05:46:24 556928 ----a-w- C:\windows\System32\winresume.efi
2013-12-13 05:46:24 20352 ----a-w- C:\windows\System32\kdusb.dll
2013-12-13 05:46:24 19328 ----a-w- C:\windows\System32\kd1394.dll
2013-12-13 05:46:24 17792 ----a-w- C:\windows\System32\kdcom.dll
2013-12-13 05:45:32 609792 ----a-w- C:\windows\System32\vbscript.dll
2013-12-13 05:45:32 428032 ----a-w- C:\windows\SysWow64\vbscript.dll
2013-12-13 05:45:26 3213824 ----a-w- C:\windows\System32\msi.dll
2013-12-13 05:45:25 2342400 ----a-w- C:\windows\SysWow64\msi.dll
2013-12-13 05:45:23 954752 ----a-w- C:\windows\SysWow64\mfc40.dll
2013-12-13 05:45:22 954288 ----a-w- C:\windows\SysWow64\mfc40u.dll
2013-12-13 05:45:18 1034240 ----a-w- C:\windows\SysWow64\mstsc.exe
2013-12-13 05:45:17 1097216 ----a-w- C:\windows\System32\mstsc.exe
2013-12-13 05:45:05 75632 ----a-w- C:\windows\System32\drivers\partmgr.sys
2013-12-13 05:42:59 58880 ----a-w- C:\windows\System32\browcli.dll
2013-12-13 05:42:58 41472 ----a-w- C:\windows\SysWow64\browcli.dll
2013-12-13 05:42:45 223752 ----a-w- C:\windows\System32\drivers\fvevol.sys
2013-12-13 05:42:04 723456 ----a-w- C:\windows\System32\EncDec.dll
2013-12-13 05:42:03 534528 ----a-w- C:\windows\SysWow64\EncDec.dll
2013-12-13 05:09:02 1739160 ----a-w- C:\windows\System32\ntdll.dll
2013-12-13 05:09:02 1292592 ----a-w- C:\windows\SysWow64\ntdll.dll
2013-12-13 05:06:02 861184 ----a-w- C:\windows\System32\oleaut32.dll
2013-12-13 05:06:02 571904 ----a-w- C:\windows\SysWow64\oleaut32.dll
2013-12-13 05:06:02 331776 ----a-w- C:\windows\System32\oleacc.dll
2013-12-13 05:06:02 233472 ----a-w- C:\windows\SysWow64\oleacc.dll
2013-12-13 04:53:47 236032 ----a-w- C:\windows\System32\srvsvc.dll
2013-12-13 04:53:45 9728 ----a-w- C:\windows\SysWow64\sscore.dll
2013-12-13 04:53:29 267936 ------w- C:\windows\System32\MpSigStub.exe
2013-12-13 04:52:57 826368 ----a-w- C:\windows\SysWow64\rdpcore.dll
2013-12-13 04:52:57 1031680 ----a-w- C:\windows\System32\rdpcore.dll
2013-12-13 04:52:56 23552 ----a-w- C:\windows\System32\drivers\tdtcp.sys
2013-12-13 04:50:59 1462784 ----a-w- C:\windows\System32\crypt32.dll
2013-12-13 04:50:58 1157632 ----a-w- C:\windows\SysWow64\crypt32.dll
2013-12-13 04:50:57 182272 ----a-w- C:\windows\System32\cryptsvc.dll
2013-12-13 04:50:57 140288 ----a-w- C:\windows\System32\cryptnet.dll
2013-12-13 04:50:57 139264 ----a-w- C:\windows\SysWow64\cryptsvc.dll
2013-12-13 04:50:57 103936 ----a-w- C:\windows\SysWow64\cryptnet.dll
2013-12-13 04:50:24 77312 ----a-w- C:\windows\System32\packager.dll
2013-12-13 04:50:24 67072 ----a-w- C:\windows\SysWow64\packager.dll
2013-12-13 04:25:04 -------- d-----w- C:\Users\Heather\AppData\Local\Google
2013-12-12 13:16:40 -------- d-----w- C:\windows\System32\drivers\NortonPCCheckupx64\0200030.0C6
2013-12-12 13:16:40 -------- d-----w- C:\windows\System32\drivers\NortonPCCheckupx64
2013-12-12 13:16:40 -------- d-----w- C:\Program Files\Norton PC Checkup
2013-12-12 13:16:40 -------- d-----w- C:\Program Files (x86)\Norton PC Checkup
2013-12-12 13:15:15 -------- d-----w- C:\Program Files (x86)\Toshiba Online Backup
2013-12-12 13:14:55 -------- d--h--w- C:\windows\msdownld.tmp
2013-12-12 13:13:39 -------- d-----w- C:\Program Files\Intuit
2013-12-12 13:13:39 -------- d-----w- C:\Program Files (x86)\TOSHIBA Corporation
2013-12-12 13:13:39 -------- d-----w- C:\Program Files (x86)\Intuit
2013-12-12 13:04:34 -------- d-----w- C:\Program Files (x86)\TOSHIBA Games
2013-12-12 13:04:33 -------- d-----w- C:\ProgramData\WildTangent
2013-12-12 12:58:53 615040 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\cchpx64.sys
2013-12-12 12:58:53 504880 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\srtsp64.sys
2013-12-12 12:58:53 451120 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\symtdiv.sys
2013-12-12 12:58:53 433200 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\SymDS64.sys
2013-12-12 12:58:53 32304 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\srtspx64.sys
2013-12-12 12:58:53 221232 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\SymEFA64.sys
2013-12-12 12:58:53 148528 ----a-r- C:\windows\System32\drivers\NISx64\1105000.07F\Ironx64.sys
2013-12-12 12:58:35 -------- d-----w- C:\windows\System32\drivers\NISx64\1105000.07F
2013-12-12 12:58:35 -------- d-----w- C:\windows\System32\drivers\NISx64
2013-12-12 12:58:32 -------- d-----w- C:\ProgramData\Norton
2013-12-12 12:58:32 -------- d-----w- C:\Program Files (x86)\Norton Internet Security
2013-12-12 12:56:48 -------- d-----w- C:\ProgramData\NortonInstaller
2013-12-12 12:56:48 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2013-12-12 12:54:35 482384 ----a-w- C:\windows\System32\drivers\tos_sps64.sys
2013-12-12 12:54:34 4178264 ----a-w- C:\windows\SysWow64\D3DX9_41.dll
2013-12-12 12:53:51 2622464 ----a-w- C:\windows\System32\wucltux.dll
2013-12-12 12:52:22 99840 ----a-w- C:\windows\System32\wudriver.dll
2013-12-12 12:52:12 -------- d-----w- C:\Program Files\Common Files\TOSHIBA Shared
2013-12-12 12:52:12 -------- d-----w- C:\Program Files (x86)\Common Files\TOSHIBA Shared
2013-12-12 12:51:54 -------- d-----w- C:\Users\Heather\AppData\Local\VirtualStore
2013-12-12 12:50:26 36864 ----a-w- C:\windows\System32\wuapp.exe
2013-12-12 12:50:26 186752 ----a-w- C:\windows\System32\wuwebv.dll
2013-12-12 12:48:45 35008 ----a-w- C:\windows\System32\drivers\PGEffect.sys
2013-12-12 12:48:41 13 --sh--r- C:\windows\System32\drivers\fbd.sys
2013-12-12 12:47:47 -------- d-----w- C:\Users\Heather\AppData\Roaming\WinBatch
2013-12-12 12:36:01 24576 ----a-w- C:\windows\SysWow64\TSCI.dll
2013-12-12 12:36:01 24576 ----a-w- C:\windows\SysWow64\THCI.dll
2013-12-12 12:33:28 -------- d-----w- C:\Program Files (x86)\Common Files\Ulead Systems
2013-12-12 12:33:26 -------- d-----w- C:\Program Files (x86)\Corel
2013-12-12 12:27:02 -------- d-----w- C:\Program Files\Synaptics
2013-12-12 12:25:40 612352 ----a-w- C:\windows\System32\drivers\rtl819xp.sys
2013-12-12 12:25:39 932384 ----a-w- C:\windows\System32\drivers\rtl8192ce.sys
2013-12-12 12:25:39 451072 ------w- C:\windows\SysWow64\ISSRemoveSP.exe
2013-12-12 12:25:39 450048 ----a-w- C:\windows\System32\drivers\rtl8187B.sys
2013-12-12 12:25:39 442368 ----a-w- C:\windows\System32\drivers\rtl8187Se.sys
2013-12-12 12:25:39 1103904 ----a-w- C:\windows\System32\drivers\rtl8192se.sys
2013-12-12 12:25:39 -------- d-----w- C:\Program Files (x86)\Realtek WLAN Driver
2013-12-12 12:23:51 74272 ----a-w- C:\windows\System32\RtNicProp64.dll
2013-12-12 12:23:51 330856 ----a-w- C:\windows\System32\drivers\Rt64win7.sys
2013-12-12 12:23:51 107552 ----a-w- C:\windows\System32\RTNUninst64.dll
2013-12-12 12:22:36 -------- d-----w- C:\Program Files (x86)\JMicron
2013-12-12 12:21:43 -------- d-----w- C:\windows\SysWow64\SDA
2013-12-12 12:12:27 538136 ----a-w- C:\windows\System32\drivers\iaStor.sys
2013-12-12 12:08:43 -------- d-----w- C:\Intel
2013-12-12 12:08:14 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2013-12-12 12:08:08 56344 ----a-w- C:\windows\System32\drivers\HECIx64.sys
2013-12-12 12:07:05 -------- d-----w- C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
.
==================== Find3M  ====================
.
.
============= FINISH: 12:08:52.95 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,600 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:33 PM

Posted 06 January 2014 - 02:30 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/519251 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 heatherjoy83

heatherjoy83
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:33 PM

Posted 06 January 2014 - 02:38 PM

Hello. I still need help. All information is in my original post. My log file is posted above. I have not been on my computer since then so that information is still up-to-date. I do have the Windows Recovery DVD that I created when I purchased my laptop. I have already wiped my hard drive once and am still getting the error message.

 

Thank you for your help.

- Heather



#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,385 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:33 PM

Posted 08 January 2014 - 09:53 AM

Greetings Heather and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far, I know it has been a long wait. We are swamped :( .

It appears your issue would be more appropriately handled in the Internal Hardware Forum but since you have been waiting so long how about you and I take a quick peek at it and see if we can sort it out. Please do this for me.

===================================================

GSmartControl for Windows

-------------------
  • Download GSmartControl for Windows and save it to your desktop
  • Unzip the folder to your desktop
  • Double click gsmartcontrol.exe
  • Allow the program to search for and list your hard drive(s)
  • Double click your drive
  • Go to the PERFORM TESTS tab
  • Make sure that the TEST TYPE is set to SHORT SELF-TEST
  • Click the EXECUTE button
  • After the test completes, click the VIEW OUTPUT button and copy and paste the contents in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • GsmartControl results

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 heatherjoy83

heatherjoy83
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:33 PM

Posted 08 January 2014 - 07:16 PM

Hi Gary,

 

I appreciate your assistance. Below are the GSmartControl results.

 

- Heather

 

smartctl 5.43 2012-06-30 r3573 [i686-w64-mingw32-win7(64)] (sf-5.43-1)
Copyright © 2002-12 by Bruce Allen, http://smartmontools.sourceforge.net

=== START OF INFORMATION SECTION ===
Model Family:     Toshiba 2.5" HDD MK..65GSX
Device Model:     TOSHIBA MK5065GSX
Serial Number:    50JGC23UT
LU WWN Device Id: 5 000039 283a8667d
Firmware Version: GJ003M
User Capacity:    500,107,862,016 bytes [500 GB]
Sector Size:      512 bytes logical/physical
Device is:        In smartctl database [for details use: -P show]
ATA Version is:   8
ATA Standard is:  Exact ATA specification draft version not indicated
Local Time is:    Wed Jan 08 18:14:56 2014 CST
SMART support is: Available - device has SMART capability.
SMART support is: Enabled

=== START OF READ SMART DATA SECTION ===
SMART overall-health self-assessment test result: FAILED!
Drive failure expected in less than 24 hours. SAVE ALL DATA.
See vendor-specific Attribute list for failed Attributes.

General SMART Values:
Offline data collection status:  (0x00) Offline data collection activity
     was never started.
     Auto Offline Data Collection: Disabled.
Self-test execution status:      (   0) The previous self-test routine completed
     without error or no self-test has ever
     been run.
Total time to complete Offline
data collection:   (  120) seconds.
Offline data collection
capabilities:     (0x5b) SMART execute Offline immediate.
     Auto Offline data collection on/off support.
     Suspend Offline collection upon new
     command.
     Offline surface scan supported.
     Self-test supported.
     No Conveyance Self-test supported.
     Selective Self-test supported.
SMART capabilities:            (0x0003) Saves SMART data before entering
     power-saving mode.
     Supports SMART auto save timer.
Error logging capability:        (0x01) Error logging supported.
     General Purpose Logging supported.
Short self-test routine
recommended polling time:   (   2) minutes.
Extended self-test routine
recommended polling time:   ( 168) minutes.
SCT capabilities:         (0x003d) SCT Status supported.
     SCT Error Recovery Control supported.
     SCT Feature Control supported.
     SCT Data Table supported.

SMART Attributes Data Structure revision number: 16
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME          FLAG     VALUE WORST THRESH TYPE      UPDATED  WHEN_FAILED RAW_VALUE
  1 Raw_Read_Error_Rate     0x000b   100   100   011    Pre-fail  Always       -       0
  2 Throughput_Performance  0x0005   100   100   005    Pre-fail  Offline      -       0
  3 Spin_Up_Time            0x0027   100   100   039    Pre-fail  Always       -       1967
  4 Start_Stop_Count        0x0032   100   100   050    Old_age   Always       -       2973
  5 Reallocated_Sector_Ct   0x0033   001   001   051    Pre-fail  Always   FAILING_NOW 2047
  7 Seek_Error_Rate         0x000b   100   100   011    Pre-fail  Always       -       0
  8 Seek_Time_Performance   0x0005   100   100   005    Pre-fail  Offline      -       0
  9 Power_On_Hours          0x0032   074   074   050    Old_age   Always       -       10418
 10 Spin_Retry_Count        0x0033   159   100   051    Pre-fail  Always       -       0
 12 Power_Cycle_Count       0x0032   100   100   050    Old_age   Always       -       2957
191 G-Sense_Error_Rate      0x0032   100   100   050    Old_age   Always       -       35
192 Power-Off_Retract_Count 0x0032   100   100   050    Old_age   Always       -       328007709
193 Load_Cycle_Count        0x0032   082   082   050    Old_age   Always       -       181154
194 Temperature_Celsius     0x0022   100   100   034    Old_age   Always       -       22 (Min/Max 15/53)
196 Reallocated_Event_Count 0x0032   100   100   050    Old_age   Always       -       407
197 Current_Pending_Sector  0x0032   100   100   050    Old_age   Always       -       0
198 Offline_Uncorrectable   0x0030   100   100   048    Old_age   Offline      -       0
199 UDMA_CRC_Error_Count    0x0032   200   200   050    Old_age   Always       -       0
220 Disk_Shift              0x0002   100   100   002    Old_age   Always       -       8240
222 Loaded_Hours            0x0032   085   085   050    Old_age   Always       -       6267
223 Load_Retry_Count        0x0032   100   100   050    Old_age   Always       -       0
224 Load_Friction           0x0022   100   100   034    Old_age   Always       -       0
226 Load-in_Time            0x0026   100   100   038    Old_age   Always       -       244
240 Head_Flying_Hours       0x0001   100   100   001    Pre-fail  Offline      -       0

SMART Error Log Version: 1
ATA Error Count: 56 (device log contains only the most recent five errors)
 CR = Command Register [HEX]
 FR = Features Register [HEX]
 SC = Sector Count Register [HEX]
 SN = Sector Number Register [HEX]
 CL = Cylinder Low Register [HEX]
 CH = Cylinder High Register [HEX]
 DH = Device/Head Register [HEX]
 DC = Device Command Register [HEX]
 ER = Error register [HEX]
 ST = Status register [HEX]
Powered_Up_Time is measured from power on, and printed as
DDd+hh:mm:SS.sss where DD=days, hh=hours, mm=minutes,
SS=sec, and sss=millisec. It "wraps" after 49.710 days.

Error 56 occurred at disk power-on lifetime: 8363 hours (348 days + 11 hours)
  When the command that caused the error occurred, the device was active or idle.

  After command completion occurred, registers were:
  ER ST SC SN CL CH DH
  -- -- -- -- -- -- --
  40 41 5a fa 4a 39 60  Error: UNC at LBA = 0x00394afa = 3754746

  Commands leading to the command that caused the error were:
  CR FR SC SN CL CH DH DC   Powered_Up_Time  Command/Feature_Name
  -- -- -- -- -- -- -- --  ----------------  --------------------
  60 80 58 f8 4a 39 40 00      00:15:34.386  READ FPDMA QUEUED
  61 08 50 a0 58 5c 40 00      00:15:34.379  WRITE FPDMA QUEUED
  61 12 48 2e c6 5d 40 00      00:15:34.369  WRITE FPDMA QUEUED
  61 01 40 20 36 3b 40 00      00:15:34.352  WRITE FPDMA QUEUED
  61 08 38 00 cf 8a 40 00      00:15:34.273  WRITE FPDMA QUEUED

Error 55 occurred at disk power-on lifetime: 8363 hours (348 days + 11 hours)
  When the command that caused the error occurred, the device was active or idle.

  After command completion occurred, registers were:
  ER ST SC SN CL CH DH
  -- -- -- -- -- -- --
  40 41 22 fa 4a 39 60  Error: UNC at LBA = 0x00394afa = 3754746

  Commands leading to the command that caused the error were:
  CR FR SC SN CL CH DH DC   Powered_Up_Time  Command/Feature_Name
  -- -- -- -- -- -- -- --  ----------------  --------------------
  60 80 20 f8 4a 39 40 00      00:15:30.107  READ FPDMA QUEUED
  61 08 18 08 5f 90 40 00      00:15:30.097  WRITE FPDMA QUEUED
  61 08 10 18 cf 8a 40 00      00:15:30.017  WRITE FPDMA QUEUED
  60 40 08 28 41 48 40 00      00:15:30.011  READ FPDMA QUEUED
  61 12 00 1c c6 5d 40 00      00:15:29.947  WRITE FPDMA QUEUED

Error 54 occurred at disk power-on lifetime: 8363 hours (348 days + 11 hours)
  When the command that caused the error occurred, the device was active or idle.

  After command completion occurred, registers were:
  ER ST SC SN CL CH DH
  -- -- -- -- -- -- --
  40 41 f2 fa 4a 39 60  Error: UNC at LBA = 0x00394afa = 3754746

  Commands leading to the command that caused the error were:
  CR FR SC SN CL CH DH DC   Powered_Up_Time  Command/Feature_Name
  -- -- -- -- -- -- -- --  ----------------  --------------------
  60 80 f0 f8 4a 39 40 00      00:15:25.857  READ FPDMA QUEUED
  61 10 e8 a8 de 8a 40 00      00:15:25.842  WRITE FPDMA QUEUED
  61 0f e0 98 58 5c 40 00      00:15:25.750  WRITE FPDMA QUEUED
  60 40 d8 e8 40 48 40 00      00:15:25.692  READ FPDMA QUEUED
  2f 00 01 10 00 00 40 00      00:15:25.691  READ LOG EXT

Error 53 occurred at disk power-on lifetime: 8363 hours (348 days + 11 hours)
  When the command that caused the error occurred, the device was active or idle.

  After command completion occurred, registers were:
  ER ST SC SN CL CH DH
  -- -- -- -- -- -- --
  40 41 ca fa 4a 39 60  Error: UNC at LBA = 0x00394afa = 3754746

  Commands leading to the command that caused the error were:
  CR FR SC SN CL CH DH DC   Powered_Up_Time  Command/Feature_Name
  -- -- -- -- -- -- -- --  ----------------  --------------------
  60 80 c8 f8 4a 39 40 00      00:15:21.604  READ FPDMA QUEUED
  60 40 c0 a8 45 48 40 00      00:15:21.547  READ FPDMA QUEUED
  2f 00 01 10 00 00 40 00      00:15:21.546  READ LOG EXT
  60 80 b0 f8 4a 39 40 00      00:15:17.453  READ FPDMA QUEUED
  61 06 a8 98 58 5c 40 00      00:15:17.391  WRITE FPDMA QUEUED

Error 52 occurred at disk power-on lifetime: 8363 hours (348 days + 11 hours)
  When the command that caused the error occurred, the device was active or idle.

  After command completion occurred, registers were:
  ER ST SC SN CL CH DH
  -- -- -- -- -- -- --
  40 41 b2 fa 4a 39 60  Error: UNC at LBA = 0x00394afa = 3754746

  Commands leading to the command that caused the error were:
  CR FR SC SN CL CH DH DC   Powered_Up_Time  Command/Feature_Name
  -- -- -- -- -- -- -- --  ----------------  --------------------
  60 80 b0 f8 4a 39 40 00      00:15:17.453  READ FPDMA QUEUED
  61 06 a8 98 58 5c 40 00      00:15:17.391  WRITE FPDMA QUEUED
  2f 00 01 10 00 00 40 00      00:15:17.391  READ LOG EXT
  60 80 98 f8 4a 39 40 00      00:15:13.247  READ FPDMA QUEUED
  2f 00 01 10 00 00 40 00      00:15:13.246  READ LOG EXT

SMART Self-test log structure revision number 1
Num  Test_Description    Status                  Remaining  LifeTime(hours)  LBA_of_first_error
# 1  Short offline       Completed: unknown failure    90%     10418         0

SMART Selective self-test log data structure revision number 1
 SPAN  MIN_LBA  MAX_LBA  CURRENT_TEST_STATUS
    1        0        0  Not_testing
    2        0        0  Not_testing
    3        0        0  Not_testing
    4        0        0  Not_testing
    5        0        0  Not_testing
Selective self-test flags (0x0):
  After scanning selected spans, do NOT read-scan remainder of disk.
If Selective self-test is pending on power-up, resume after 0 minute delay.



#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,385 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:33 PM

Posted 08 January 2014 - 07:47 PM

Thanks for running the program which confirms your hard drive is failing:
 

SMART overall-health self-assessment test result: FAILED!

 

You need to replace your hard drive as soon as possible.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 heatherjoy83

heatherjoy83
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:33 PM

Posted 08 January 2014 - 09:37 PM

Hi Gary,

Thanks for the assessment. So it is an actual hard drive failure versus being a virus that wrongly gives the failure alert?

#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,385 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:33 PM

Posted 08 January 2014 - 10:33 PM

Yes, that is correct.  The program we ran is not designed to address malware issues at all, only the condition of your hard drive.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,385 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:33 PM

Posted 10 January 2014 - 01:08 PM

Greetings,

Do you have any other questions or concerns I might be able to assist you with?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 heatherjoy83

heatherjoy83
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:33 PM

Posted 10 January 2014 - 10:43 PM

Not at this time. Thank you very much for your help.



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,385 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:33 PM

Posted 10 January 2014 - 10:57 PM

You are welcome.  Sorry I didn't have better news for you.  Since you are doing OK I am going to close this topic.  Feel free to send me a Personal Message if you need further assistance with this issue.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,385 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:33 PM

Posted 10 January 2014 - 11:04 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users