Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

wispthis.exe - Bad Image Error - Possible KNCTR Virus??


  • Please log in to reply
25 replies to this topic

#1 hYlAnDeR~TFC

hYlAnDeR~TFC

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 28 June 2016 - 07:59 PM

My computer takes approximately 20 minutes to boot up into normal Windows 7 mode. Every single task that is clicked takes a very very long time to activate. Every program is very very slow, close to inoperable.  Inside the Window Box error on the desktop stated that C:\Windows\system32\d3d8thk.dll is not an operable program... etc etc.  I ran Malware bytes AV yesterday in safe mode, it did not find anything.  Yesterday I was able to go into safe mode with networking, but today I cannot connect to the internet in safe mode. I am posting this help message on another computer in the household.  I am unable to look at photos through the windows image viewer. This problem just came on suddenly. I have not ran any Windows updates in the past few days. I attempted to run the free version of Avast in normal boot mode, but after 5 hours it was only at 4 percent and so I shut it down. I attempted to run Avast in safe mode, but it will not run.  When I was able to do some searching on the internet in safe mode, there was some information I found that led me to believe that the symptoms I have on my computer are a result of a virus or spyware. I am not certain, but I am unable to isolate what exactly happened and I am unable to repair this on my own.  Some websites mention that to correct my problem may be as simple as removing the associated wisptis.exe from the registry since it has to do with tablets and other hand held touch screen devices which I do not use. However, I am skeptical and very uncertain to remove files and/or lines from the registries.

 

So, whatever help anyone can offer me to get my computer back to being virus free and running well again would be greatly appreciated.


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,614 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:43 PM

Posted 28 June 2016 - 09:10 PM

Use your working computer to download following tools and USB flash drive to trnsfer them to bad computer.

 

p22002970.gif Download Security Check from here or here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run

p22002970.gif Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


p22002970.gif Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size
  • List Restore Points

Click Go and post the result.

p22002970.gif Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
NOTE. If you already have MBAM 2.0 installed scroll down.

  • Double-click mb3-setup-1878.1878-3.4.5.2467.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:

    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.

  • Click Finish.
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.



If you already have MBAM 2.0 installed:

  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.


How to get logs:
(Export log to save as txt)


  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Attach that saved log to your next reply.



(Copy to clipboard for pasting into forum replies or tickets)

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.


p22002970.gifDownload 51a5f31352b88-icon_MBAR.pngMalwarebytes Anti-Rootkit (MBAR) to your desktop.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Double click on downloaded file. OK self extracting prompt.
  • MBAR will start. Click "Next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder located on your Desktop and paste the content of the following files in your next reply:
  • "mbar-log-{date} (xx-xx-xx).txt"
  • "system-log.txt"


NOTE. If you see This version requires you to completely exit the Anti Malware application message right click on the Malwarebytes Anti-Malware icon in the system tray and click on Exit.

p22002970.gif Please download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.


If normal mode still doesn't work, run the tool from safe mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.

NOTE Do NOT wrap your logs in "quote" or "code" brackets.
Do NOT use spoilers.
Do NOT edit your reply to post additional logs. Create new reply. I'll not get any email notifications about edits so I won't know you posted something new.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 28 June 2016 - 10:00 PM

Do you want me to install and run these programs in Safe Mode?  If I try to install and run these in normal mode, this will take a very long time to complete.

 

Thanks


Sorry for the lines through the letters in my last reply. I don't know how that happened.


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#4 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,614 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:43 PM

Posted 28 June 2016 - 10:14 PM

You can run them from safe mode if needed.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#5 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 28 June 2016 - 10:26 PM

Ok thanks.  I will try to get these logs posted as soon as I can.  I really do appreciate your help and patience.


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#6 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 28 June 2016 - 11:44 PM

I was not able to update any of the programs after installing them due to the fact I have no network access. So I just ran them as is.  Additionally, when I ran the Malwarebytes Anti Rootkit program, I encountered a probable rootkit activity detected warning popup. I took a screen shot of it if you need me to upload for your review. I opted for the no option so that I could begin the scan. Other than that, I ran all the programs in Safe Mode.  I tried to do the scans in Normal mode, but it was wayyyyyyy to slow and I no longer have access to the internet even in normal mode any more either.  Below are the logs.

 

 

Here ya go:

 

 

 

 

Security Check Log:

 

 

 

 Results of screen317's Security Check version 1.014 --- 12/23/15 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
 Windows Firewall Enabled! 
avast! Antivirus  
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 SpywareBlaster 5.5   
 Secunia PSI (3.0.0.10004)  
 Java 8 Update 77 
 Java version 32-bit out of Date!
 Adobe Flash Player 22.0.0.192 
 Mozilla Firefox (46.0.1)
````````Process Check: objlist.exe by Laurent```````` 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

 

 

 

 

 

Farbar Scan Log

 

 

 

 

 

Farbar Service Scanner Version: 27-01-2016
Ran by William (administrator) on 28-06-2016 at 20:17:47
Running from "C:\Users\William\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Network
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is unreachable
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo.com returned error: Other errors

Windows Firewall:
=============

Firewall Disabled Policy:
==================

System Restore:
============
SDRSVC Service is not running. Checking service configuration:
The start type of SDRSVC service is OK.
The ImagePath of SDRSVC service is OK.
The ServiceDll of SDRSVC service is OK.

VSS Service is not running. Checking service configuration:
The start type of VSS service is OK.
The ImagePath of VSS service is OK.

System Restore Policy:
========================

Action Center:
============

wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.

Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.

BITS Service is not running. Checking service configuration:
The start type of BITS service is OK.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.

EventSystem Service is not running. Checking service configuration:
The start type of EventSystem service is OK.
The ImagePath of EventSystem service is OK.
The ServiceDll of EventSystem service is OK.

Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============

Other Services:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed

**** End of log ****

 

 

 

 

 

 

 

 

 

 

Mini Tool Box Log

 

 

 

MiniToolBox by Farbar  Version: 17-06-2016
Ran by William (administrator) on 28-06-2016 at 20:20:51
Running from "C:\Users\William\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Model: Z68AP-D3 Manufacturer: Gigabyte Technology Co., Ltd.
Boot Mode: Network
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

========================= Hosts content: =================================
========================= IP Configuration: ================================

The following helper DLL cannot be loaded: WLANCFG.DLL.

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled

popd
# End of IPv4 configuration

 

Windows IP Configuration

   Host Name . . . . . . . . . . . . : William-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  UnKnown
Address:  127.0.0.1

Ping request could not find host google.com. Please check the name and try again.
Server:  UnKnown
Address:  127.0.0.1

Ping request could not find host yahoo.com. Please check the name and try again.

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
  1...........................Software Loopback Interface 1
 12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    306 ::1/128                  On-link
  1    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/28/2016 07:55:34 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2016 05:40:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2016 05:35:54 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2016 05:20:35 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service) (User: )
Description: The index cannot be initialized.

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.

Context: Windows Application

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:44 PM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
 Element not found.  (HRESULT : 0x80070490) (0x80070490)

Error: (06/27/2016 07:00:57 PM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.JetPropStore> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

System errors:
=============
Error: (06/28/2016 08:21:09 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:21:06 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:21:04 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:21:01 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:20:58 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:20:55 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:19:52 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:19:49 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:19:47 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (06/28/2016 08:19:44 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Microsoft Office Sessions:
=========================
Error: (06/28/2016 07:55:34 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2016 05:40:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2016 05:35:54 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/28/2016 05:20:35 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service)(User: )
Description:
Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
The catalog is corrupt

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service)(User: )
Description:
Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:47 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (06/27/2016 07:02:44 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application, SystemIndex Catalog

Details:
 Element not found.  (HRESULT : 0x80070490) (0x80070490)
Search.TripoliIndexer

Error: (06/27/2016 07:00:57 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
Search.JetPropStore

CodeIntegrity Errors:
===================================
  Date: 2013-05-21 19:08:04.338
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-21 12:42:21.070
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-21 10:16:50.904
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 13:13:03.705
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 12:09:05.171
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 11:44:50.098
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 11:05:56.918
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 10:11:40.711
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 10:06:21.059
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-20 08:27:06.745
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system.

=========================== Installed Programs ============================

@BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.12 - GIGABYTE)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20045 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 22.0.0.192 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.192 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AutoGreen B10.1021.1 (HKLM-x32\...\{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) Hidden
AutoGreen B10.1021.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE)
Avast Free Antivirus (HKLM-x32\...\avast) (Version: 11.1.2253 - AVAST Software)
AVS Video Converter 8 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 8.4.1.540 - Online Media Technologies Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 1942 (HKLM-x32\...\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}) (Version:  - )
Battlefield 1942: Secret Weapons of WWII (HKLM-x32\...\{B73B4A99-4173-4747-BBEC-0F05E966F9D2}) (Version:  - )
Battlefield 1942: The Road To Rome (HKLM-x32\...\{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}) (Version:  - )
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlefield 4 Premium (HKLM-x32\...\Battlefield 4 Premium) (Version:  - GameStop)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.7.2.45672 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.7.1 - EA Digital Illusions CE AB)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty - United Offensive (HKLM-x32\...\{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty - United Offensive (HKLM-x32\...\InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision)
Call of Duty (HKLM-x32\...\Call of Duty) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
Corel PaintShop Pro X5 (HKLM-x32\...\_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.0.0.183 - Corel Corporation)
Corel PaintShop Pro X5 (HKLM-x32\...\{15180A90-1FC0-47E4-A150-3AECEF07B3B6}) (Version: 15.0.0.183 - Corel Corporation) Hidden
CPUID HWMonitor Pro 1.15 (HKLM\...\CPUID HWMonitorPro_is1) (Version:  - )
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DES 2.0 (HKLM-x32\...\{675F86A8-E093-4002-87D5-915CC2C45571}) (Version: 1.00.0000 - Gigabyte)
DH Lore Invasion (HKLM-x32\...\DH Lore Invasion) (Version:  - )
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC)
DriverAgent by eSupport.com (HKLM\...\DriverAgent.exe) (Version:  - )
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
e-Sword (HKLM-x32\...\{118071AB-6572-4FAD-A1FD-67264C994350}) (Version: 10.01.0000 - Rick Meyers)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.104 - Etron Technology) Hidden
FaceFilter Studio 2 (HKLM-x32\...\{F59205C8-E5FB-43F5-AAB2-16C1760D4F59}) (Version: 2.0 - Reallusion)
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 3.21.2.1 - Futuremark Corporation)
HAWKEN (HKLM-x32\...\Steam App 271290) (Version:  - Adhesive Games)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
ICA (HKLM-x32\...\{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}) (Version: 15.0.0.183 - Corel Corporation) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2418 - Intel Corporation)
IPM_PSP_COM (HKLM-x32\...\{154B0B16-ABCD-4A06-B0B7-8146B7A89B25}) (Version: 15.0.0.183 - Corel Corporation) Hidden
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KeyScrambler (HKLM-x32\...\KeyScrambler) (Version: 3.1.0.0 - QFX Software Corporation)
K-Lite Codec Pack 9.9.5 (64-bit) (HKLM\...\KLiteCodecPack64_is1) (Version: 9.9.5 - )
K-Lite Codec Packages (HKCU\...\K-Lite Codec Packages) (Version:  - )
Linksys EasyLink Advisor (HKLM\...\{7FE3214C-283E-40C6-A8D5-CB773110090C}) (Version: 3.0.8122.29 - Linksys, Cisco System.) Hidden
Linksys EasyLink Advisor (HKLM-x32\...\InstallShield_{7FE3214C-283E-40C6-A8D5-CB773110090C}) (Version:  - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MechWarrior 3 (HKLM-x32\...\MechWarrior 3) (Version:  - )
MechWarrior Black Knight (HKLM-x32\...\MechWarrior Black Knight) (Version:  - )
MechWarrior Online (HKCU\...\{74d11f91-05cc-44f6-8e49-94fe7f33c79b}) (Version: 1.2.0.0 - Piranha Games Inc.)
MechWarrior Online (HKLM-x32\...\{F8511A0F-D91D-4E3D-A59C-3CA8FB8EAFE8}) (Version: 1.2.0.0 - Piranha Games Inc.) Hidden
MechWarrior Vengeance (HKLM-x32\...\MechWarrior Vengeance) (Version:  - )
Medal of Honor Allied Assault (HKLM-x32\...\{0DEA94ED-915A-4834-A87E-388D012C8E02}) (Version:  - )
Medal of Honor Allied Assault™ Breakthrough (HKLM-x32\...\{823A68CC-3049-4A6B-8F63-7DC85E4BB1C9}) (Version:  - )
Medal of Honor Allied Assault™ Spearhead (HKLM-x32\...\{7914BE1E-F186-4790-B8F4-9F63C52A41C1}) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla)
Mumble 1.2.4 (HKLM-x32\...\{E0955568-4353-4C85-8988-285A8C0F5E87}) (Version: 1.2.4 - Thorvald Natvig)
Nik Color Efex Pro 3.0 (HKLM-x32\...\_{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}) (Version: 1.0.0.53 - Corel Corporation)
Nik Color Efex Pro 3.0 (HKLM-x32\...\{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}) (Version: 1.00.0000 - Corel Corporation) Hidden
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
ON_OFF Charge B11.0110.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Origin (HKLM-x32\...\Origin) (Version: 9.1.3.2636 - Electronic Arts, Inc.)
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
PSPPContent (HKLM-x32\...\{1522E36C-3739-41E4-8CD3-A4AFEA70086A}) (Version: 15.0.0.183 - Corel Corporation) Hidden
PSPPHelp (HKLM-x32\...\{153DD765-C8C6-4893-8CEF-D965351D82EC}) (Version: 15.0.0.183 - Corel Corporation) Hidden
PSPPro64 (HKLM\...\{1551A29F-B1B0-43CA-90B5-E6E5186F683E}) (Version: 15.0.0.183 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Pure Networks Platform (HKLM-x32\...\{9C1EED58-1790-45C4-ADBC-5D45FCA7292E}) (Version: 10.1.8116.1 - Pure Networks) Hidden
qBittorrent 3.1.12 (HKLM-x32\...\qBittorrent) (Version: 3.1.12 - The qBittorrent project)
Razer Surround (HKLM-x32\...\Razer Surround) (Version: 1.05.10 - Razer Inc.)
Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.18.23036 - Razer Inc.)
RealDownloader (HKLM-x32\...\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}) (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.46.531.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6423 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Revo Uninstaller Pro 2.5.8 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 2.5.8 - VS Revo Group, Ltd.)
SafeZone Stable 1.48.2066.44 (HKLM-x32\...\SafeZone 1.48.2066.44) (Version: 1.48.2066.44 - Avast Software) Hidden
Secunia PSI (3.0.0.10004) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.10004 - Secunia)
Setup (HKLM-x32\...\{15002A1B-C1E7-4E91-A3EC-5502BF924A32}) (Version: 15.0.0.183 - Corel Corporation) Hidden
Smart 6 B11.0824.1 (HKLM-x32\...\{3B35725F-C623-4A1E-B5CC-99C0868679E3}) (Version: 1.00.0000 - GIGABYTE)
Speccy (HKLM\...\Speccy) (Version: 1.18 - Piriform)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
SS Install (HKCU\...\SS Install) (Version:  - )
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1148 - SUPERAntiSpyware.com)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts)
Ultimate Creative Collection (X5) (HKLM-x32\...\_{AE4364BD-ED09-4D94-8DA2-315C10A57CD1}) (Version: 1.0.0.50 - Corel Corporation)
Ultimate Creative Collection (X5) (HKLM-x32\...\{AE4364BD-ED09-4D94-8DA2-315C10A57CD1}) (Version: 1.00.0000 - Corel Corporation) Hidden
Universal AntiCheat 3 v1.073 (HKLM-x32\...\{99BEB67F-B288-44F5-8B2A-23F5A52FA1AE}_is1) (Version:  - DExUS)
VC 9.0 Runtime (HKLM-x32\...\{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}) (Version: 1.0.0 - Check Point Software Technologies Ltd) Hidden
VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden
WebEx Support Manager for Internet Explorer (HKLM-x32\...\{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}) (Version: 6.5.47 - WebEx Communications Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 5.21 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Wondershare Dr.Fone for Android(Build 6.0.3.26) (HKLM-x32\...\{1DB91A95-C548-4BA5-9D4C-18C7DEAAC39F}_is1) (Version: 6.0.3.26 - Wondershare Software Co.,Ltd.)
World of Tanks (HKCU\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812na}_is1) (Version:  - Wargaming.net)
WOT for Internet Explorer (HKLM\...\{C0DA129B-1E45-494D-A362-5CD0109C306B}) (Version: 11.11.7.0 - WOT Services Oy)
Yahoo Search Set (HKLM-x32\...\Yahoo! SearchSet) (Version:  - Yahoo Inc.)

========================= Devices: ================================

Name: aswVmm
Description: aswVmm
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswVmm
Device ID: ROOT\LEGACY_ASWVMM\0000
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Realtek PCIe GBE Family Controller
Description: Realtek PCIe GBE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: RTL8167
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&6AE81F7&0&00E2
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Device ID: ROOT\LEGACY_SPLDR\0000
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: aswRvrt
Description: aswRvrt
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswRvrt
Device ID: ROOT\LEGACY_ASWRVRT\0000
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

========================= Memory info: ===================================

Percentage of memory in use: 7%
Total physical RAM: 16301.12 MB
Available physical RAM: 15057.79 MB
Total Virtual: 32600.42 MB
Available Virtual: 31334.71 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:931.41 GB) (Free:442.96 GB) NTFS
3 Drive e: () (Removable) (Total:14.89 GB) (Free:14.87 GB) FAT32

========================= Users: ========================================

User accounts for \\WILLIAM-PC

Administrator            Guest                    William                 

========================= Restore Points ==================================

**** End of log ****

 

 

 

 

 

 

 

 

 

 

 

Malwarebytes Log

 

 

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/28/2016
Scan Time: 8:23 PM
Logfile: MBAM.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.06.27.07
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: William

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 322066
Time Elapsed: 28 min, 36 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

 

 

 

 

 

 

 

Malwarebytes Anti Rootkit log

 

 

 

 

 

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2014.11.18.05
  rootkit: v2014.11.12.01

Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 11.0.9600.18349
William :: WILLIAM-PC [administrator]

6/28/2016 9:04:43 PM
mbar-log-2016-06-28 (21-04-43).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 344249
Time elapsed: 16 minute(s), 4 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

 

 

 

 

 

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.0.9600.18349

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 3.392000 GHz
Memory total: 17092960256, free: 15449231360

=======================================

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.0.9600.18349

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 3.392000 GHz
Memory total: 17092960256, free: 15550623744

No address found
=======================================
Initializing...
------------ Kernel report ------------
     06/28/2016 21:04:37
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\System32\Drivers\EtronXHCI.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\EtronHub3.sys
\SystemRoot\System32\Drivers\USBD.SYS
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\framebuf.dll
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\rzendpt.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\drivers\keyscrambler.sys
\SystemRoot\system32\drivers\aswKbd.sys
\SystemRoot\system32\DRIVERS\rzudd.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\System32\Drivers\fastfat.SYS
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\msvcrt.dll
\Windows\System32\nsi.dll
\Windows\System32\clbcatq.dll
\Windows\System32\sechost.dll
\Windows\System32\gdi32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\imm32.dll
\Windows\System32\ole32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\urlmon.dll
\Windows\System32\imagehlp.dll
\Windows\System32\msctf.dll
\Windows\System32\psapi.dll
\Windows\System32\iertutil.dll
\Windows\System32\user32.dll
\Windows\System32\lpk.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\normaliz.dll
\Windows\System32\comdlg32.dll
\Windows\System32\advapi32.dll
\Windows\System32\difxapi.dll
\Windows\System32\usp10.dll
\Windows\System32\wininet.dll
\Windows\System32\setupapi.dll
\Windows\System32\kernel32.dll
\Windows\System32\oleaut32.dll
\Windows\System32\shell32.dll
\Windows\System32\userenv.dll
\Windows\System32\crypt32.dll
\Windows\System32\comctl32.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\msasn1.dll
\Windows\System32\profapi.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2014.11.18.05
  rootkit: v2014.11.12.01

<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: D4286C4F

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition is bootable
    Partition file system is NTFS

    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 1953314816
    Partition is not bootable
    Partition file system is NTFS

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 843F88A3

Partition information:

    Partition 0 type is Other (0xc)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 32  Numsec = 31266784
    Partition is not bootable
    Partition file system is FAT32

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 16008609792 bytes
Sector size: 512 bytes

Done!
Scan finished
=======================================

Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-1-206848-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-0-32-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished

 

 

 

 

 

 

 

Rkill Log

 

 

 

 

 

 

Rkill 2.8.4 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 06/28/2016 09:22:55 PM in x64 mode. (Safe Mode)
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * COM+ Event System (EventSystem) is not Running.
   Startup Type set to: Automatic

 * Security Center (wscsvc) is not Running.
   Startup Type set to: Automatic (Delayed Start)

 * Windows Update (wuauserv) is not Running.
   Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

 * C:\Windows\System32\d3d8thk.dll : 12,288 : 07/13/2009 06:40 PM : d41d8cd98f00b204e9800998ecf8427e [NoSig]
 +-> C:\Windows\SysWOW64\d3d8thk.dll : 11,264 : 07/13/2009 06:15 PM : 77b1471a490b53b24efe136f09f76550 [Pos Repl]
 +-> C:\Windows\winsxs\amd64_microsoft-windows-directx-direct3d9_31bf3856ad364e35_6.1.7601.17514_none_207372147765c03a\d3d8thk.dll : 12,288 : 07/13/2009 06:40 PM : d41d8cd98f00b204e9800998ecf8427e [Pos Repl]
 +-> C:\Windows\winsxs\x86_microsoft-windows-directx-direct3d9_31bf3856ad364e35_6.1.7601.17514_none_c454d690bf084f04\d3d8thk.dll : 11,264 : 07/13/2009 06:15 PM : 77b1471a490b53b24efe136f09f76550 [Pos Repl]

Checking HOSTS File:

 * No issues found.

Program finished at: 06/28/2016 09:25:48 PM
Execution time: 0 hours(s), 2 minute(s), and 52 seconds(s)


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,614 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:43 PM

Posted 29 June 2016 - 08:23 PM

I don't think we're dealing here with an infection.

d3d8thk.dll is actually a legit file belonging to DirectX.

 

But...

 

In your Event Viewer I can see a whole bunch of these errors:

 

Error: (06/28/2016 08:21:09 PM) (Source: Disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

 

You may have Hard drive problem.

 

Click Start button and in "Start search" type:
cmd
Hold CTRL and SHIFT buttons and press Enter.
Command prompt window will open.
Paste this in:
chkdsk /r (<------watch for "space")
Press Enter.
Chkdsk will run.
Reboot.
Download ListChkdskResult.exe (by SleepyDude) from the link below:
https://dl.dropboxusercontent.com/u/12354842/My%20Tools/ListChkdskResult.exe
Double click on it to run it. It will take a few seconds to scan, then it will open a Notepad window with the log. Copy and paste the contents of this into your next post
 


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#8 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 29 June 2016 - 09:45 PM

chkdsk /r will not run from the C: prompt 

 

the message states that it cannot run because the volume is in use by another process. would you like to schedule this volume to the be check the next time the system restarts? (y/n).


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#9 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 29 June 2016 - 09:59 PM

chkdsk works from the c: prompt.  i am running that now. 


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#10 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 29 June 2016 - 10:22 PM

here is the chkdsk scan log:

 

 

 

 

Microsoft Windows [Version 6.1.7601]
Copywright  C  etc etc

C:\Users\William>chkdsk
The type of the file system is NTFS.
The volume is in use by another process. Chkdsk
might report errors when no corruption is present.

Warning! F parameter not specified.
running CHKDSK in read-only mode.

CHKDSK is verifying files <sate 1 of 3>...
347904 file records processed.
File verification completed.
2235 large file records processed.
0 bad file records processed.
0 EA records processed.
65 reparse records processed.
CHKDSK is verifying indexes <stage 2 of 3>...
29 percent complete. <379494 of 441250 index etries processed>
Index entry ProcessManager.log.08 in index $130 of file 237168 is incorrect.
Index entry PROCES~1.08 in index $130 of file 237168 is incorrect.
441250 index entries processed.
Index verification completed.

Errors found. CHKDSK cannot continue in read-only mode.

 

 

 

 

I am running a scheduled chkdsk from reboot now. I will have to wait and see what happens next.

 

I will try to run the ListChkdskResult.exe file if the scan completes. If it does not complete. I will still try to run it and post the results in my next post.

 

Thanks again for your patience.


Edited by hYlAnDeR~TFC, 29 June 2016 - 10:28 PM.

hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#11 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,614 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:43 PM

Posted 29 June 2016 - 10:54 PM

I'd also recommend....

 

Run hard drive diagnostics: http://www.bleepingcomputer.com/forums/topic28744.html/page__view__findpost__p__160520
Make sure, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: http://www.imgburn.com/ to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here: http://storage.toshiba.com/storage-services-support/warranty-support/software-utilities#diagnostic

Note : If you do not know how to set your computer to boot from CD follow the steps here


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#12 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 29 June 2016 - 11:53 PM

The chkdsk is still running and probably will not finish before I go to sleep tonight.  It is at around 298660 of 347888 files checked so far.  There are many many lines stating that "windows replaced bad clusters in various file #'s.  I will have to resume posting the chkdsk scan log until tomorrow.

 

If this ends up NOT being a virus issue and is in fact a possible or probable Hard Drive failure, depending whether or not the chkdsk repairs the hard drive or not, would you recommend that I start backing up my data in safe mode to a portable hard drive? I have most of my junk backed up, but there is still some data that I would like to save that I have not done in a few months.  

 

Also, the file that you stated is legit, "d3d8thk.dll".  Can we try to delete this from the registry? I would need your assistance to do so. I have read that this file causes many problems similar to what I am experiencing. Or, is it possible that this is simply coincidental in lieu of my potential hard drive problem?

 

As I am finishing typing this post, chkdsk just started stage 5 of 5 of the file verification process. 

 

I will check in with you tomorrow evening.

 

Thanks again for your help.


Edited by hYlAnDeR~TFC, 30 June 2016 - 12:00 AM.

hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#13 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 30 June 2016 - 06:00 AM

Here is the log from the LstChkDskResult program you first recommended that I run:

 

By the way, the computer runs a lot faster now, almost normal, but no windows photo viewer available, and still no internet/network access.

 

 

 

 

 

ListChkdskResult by SleepyDude v0.1.7 Beta | 21-09-2013

------< Log generate on 6/30/2016 3:43:12 AM >------
Category: 0
Computer Name: William-PC
Event Code: 1001
Record Number: 113083
Source Name: Microsoft-Windows-Wininit
Time Written: 06-30-2016 @ 06:02:01
Event Type: Information
User:
Message:

Checking file system on C:
The type of the file system is NTFS.

A disk check has been scheduled.
Windows will now check the disk.                        

CHKDSK is verifying files (stage 1 of 5)...
  347904 file records processed.                                        

File verification completed.
  2235 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 5)...
Unable to locate the file name attribute of index entry ProcessManager.log.08
of index $I30 with parent 0x39e70 in file 0x4fb1.
Deleting index entry ProcessManager.log.08 in index $I30 of file 237168.
Unable to locate the file name attribute of index entry PROCES~1.08
of index $I30 with parent 0x39e70 in file 0x4fb1.
Deleting index entry PROCES~1.08 in index $I30 of file 237168.
  441252 index entries processed.                                       

Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
  1 unindexed files scanned.                                       

CHKDSK is recovering remaining unindexed files.
  1 unindexed files recovered.                                     

CHKDSK is verifying security descriptors (stage 3 of 5)...
  347904 file SDs/SIDs processed.                                       

Cleaning up 52 unused index entries from index $SII of file 0x9.
Cleaning up 52 unused index entries from index $SDH of file 0x9.
Cleaning up 52 unused security descriptors.
Security descriptor verification completed.
  46675 data files processed.                                          

CHKDSK is verifying Usn Journal...
  10312616 USN bytes processed.                                           

Usn Journal verification completed.
CHKDSK is verifying file data (stage 4 of 5)...
Read failure with status 0xc000009c at offset 0x88309b0000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x88309bc000 for 0x1000 bytes.
Windows replaced bad clusters in file 13709
of name \PROGRA~3\Razer\INGAME~2\logs\WILLIA~1.LOG.
Read failure with status 0xc000009c at offset 0x16317000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x16317000 for 0x1000 bytes.
Windows replaced bad clusters in file 13751
of name \PROGRA~3\Linksys\Lela\Lela.log.9.
Read failure with status 0xc000009c at offset 0x282000 for 0x6000 bytes.
Read failure with status 0xc000009c at offset 0x282000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x283000 for 0x5000 bytes.
Read failure with status 0xc000009c at offset 0x283000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x284000 for 0x4000 bytes.
Read failure with status 0xc000009c at offset 0x284000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x285000 for 0x3000 bytes.
Read failure with status 0xc000009c at offset 0x285000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x286000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0x286000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x287000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x287000 for 0x1000 bytes.
Windows replaced bad clusters in file 23752
of name \Windows\winsxs\AM4693~1.175\bitsperf.dll.
Read failure with status 0xc000009c at offset 0x27f000 for 0x3000 bytes.
Read failure with status 0xc000009c at offset 0x27f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x280000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0x280000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x281000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x281000 for 0x1000 bytes.
Windows replaced bad clusters in file 24260
of name \Windows\winsxs\AMF71C~1.175\d3d8thk.dll.
Read failure with status 0xc000009c at offset 0x27c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x27c000 for 0x1000 bytes.
Windows replaced bad clusters in file 35343
of name \Users\Public\Desktop\smart6.lnk.
Read failure with status 0xc000009c at offset 0x27e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x27e000 for 0x1000 bytes.
Windows replaced bad clusters in file 35790
of name \Windows\APPCOM~1\APPRAI~1\Gated\gated.ini.
Read failure with status 0xc000009c at offset 0x28a000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0x28a000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x28b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x28b000 for 0x1000 bytes.
Windows replaced bad clusters in file 38541
of name \Windows\winsxs\X8D893~1.163\wlanutil.dll.
Read failure with status 0xc000009c at offset 0xcd782d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd782d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd782e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd782e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd782f000 for 0xf000 bytes.
Read failure with status 0xc000009c at offset 0xcd782f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7830000 for 0xe000 bytes.
Read failure with status 0xc000009c at offset 0xcd7830000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7831000 for 0xd000 bytes.
Read failure with status 0xc000009c at offset 0xcd7831000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7832000 for 0xc000 bytes.
Read failure with status 0xc000009c at offset 0xcd7832000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7833000 for 0xb000 bytes.
Read failure with status 0xc000009c at offset 0xcd7833000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7834000 for 0xa000 bytes.
Read failure with status 0xc000009c at offset 0xcd7834000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7835000 for 0x9000 bytes.
Read failure with status 0xc000009c at offset 0xcd7835000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7836000 for 0x8000 bytes.
Read failure with status 0xc000009c at offset 0xcd7836000 for 0x1000 bytes.
Windows replaced bad clusters in file 109301
of name \PROGRA~1\DYNAMI~1\STARSI~1\skins\APOC_vtk.bmp.
Read failure with status 0xc000009c at offset 0xcd801a000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd801f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8020000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8021000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8022000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8024000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8025000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8025000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8026000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8026000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8027000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8027000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8028000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8028000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8029000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8029000 for 0x1000 bytes.
Windows replaced bad clusters in file 115524
of name \Windows\winsxs\MSIL_S~1.216\SYSTEM~1.DLL.
Read failure with status 0xc000009c at offset 0xcd7b42000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b50000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b50000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b51000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b51000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b52000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b52000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b53000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b53000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b54000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b54000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b55000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b55000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b56000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b56000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b57000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b57000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b58000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b58000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b59000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b59000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b5a000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b5a000 for 0x1000 bytes.
Windows replaced bad clusters in file 140219
of name \PROGRA~2\EA GAMES\MOHAA\mainta\sound\AMB_ST~1\AMDAE6~1.MP3.
Read failure with status 0xc000009c at offset 0xcd79c4000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c4000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c5000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c5000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c6000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c6000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c7000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c7000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c8000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c8000 for 0x1000 bytes.
Windows replaced bad clusters in file 155603
of name \Windows\System32\GFFE49~1.RES.
Read failure with status 0xc000009c at offset 0xcd7698000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7698000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7699000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7699000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769a000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769a000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769c000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a0000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a0000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a1000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a1000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a2000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a2000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a3000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a3000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a4000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a4000 for 0x1000 bytes.
Windows replaced bad clusters in file 161634
of name \MECHWA~1\War Temp\OLDHAR~1\7YROLD~1\URLCOMP\Stats\vid174\IMAGE0~1.JPG.
Read failure with status 0xc000009c at offset 0x4093d4b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4093d57000 for 0x1000 bytes.
Windows replaced bad clusters in file 174636
of name \PROGRA~3\Linksys\Lela\Lela.log.6.
Read failure with status 0xc000009c at offset 0xce1105000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xce110d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xce110e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xce1110000 for 0x1000 bytes.
Windows replaced bad clusters in file 194588
of name \PROGRA~2\COMMON~1\Adobe\PDFL\10.9\Fonts\ADOBEA~1.OTF.
Read failure with status 0xc000009c at offset 0xcd7504000 for 0x6000 bytes.
Read failure with status 0xc000009c at offset 0xcd7505000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7506000 for 0x4000 bytes.
Read failure with status 0xc000009c at offset 0xcd7506000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7507000 for 0x3000 bytes.
Read failure with status 0xc000009c at offset 0xcd7507000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7508000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0xcd7508000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7509000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7509000 for 0x1000 bytes.
Windows replaced bad clusters in file 201919
of name \PROGRA~2\Adobe\ADOBEP~1\Legal\uk_UA\license.html.
Read failure with status 0xc000009c at offset 0xcef988000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcef988000 for 0x1000 bytes.
Windows replaced bad clusters in file 222988
of name \PROGRA~3\Razer\INGAME~2\logs\WILLIA~1.01.
Read failure with status 0xc000009c at offset 0x3979000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x397e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x397f000 for 0xf000 bytes.
Read failure with status 0xc000009c at offset 0x397f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3980000 for 0xe000 bytes.
Read failure with status 0xc000009c at offset 0x3980000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3981000 for 0xd000 bytes.
Read failure with status 0xc000009c at offset 0x3981000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3982000 for 0xc000 bytes.
Read failure with status 0xc000009c at offset 0x3982000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3983000 for 0xb000 bytes.
Read failure with status 0xc000009c at offset 0x3983000 for 0x1000 bytes.
Windows replaced bad clusters in file 224497
of name \Users\William\AppData\LocalLow\MICROS~1\CRYPTN~1\Content\1C1B62~1.
Read failure with status 0xc000009c at offset 0xcd79ac000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79bb000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79bc000 for 0x6000 bytes.
Read failure with status 0xc000009c at offset 0xcd79bc000 for 0x1000 bytes.
Read failure with status 0xc00000
-----------------------------------------------------------------------
Category: 0
Computer Name: William-PC
Event Code: 26213
Record Number: 113067
Source Name: Chkdsk
Time Written: 06-30-2016 @ 03:01:30
Event Type: Information
User:
Message: Chkdsk was executed in read-only mode.  A volume snapshot was not used. Extra errors and warnings may be reported as the volume may have changed during the chkdsk run. 

Checking file system on C:
The type of the file system is NTFS.
The volume is in use by another process. Chkdsk
might report errors when no corruption is present.

WARNING!  F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
  347904 file records processed.                                        

File verification completed.
  2235 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 3)...
Unable to locate the file name attribute of index entry ProcessManager.log.08
of index $I30 with parent 0x39e70 in file 0x4fb1.

Index entry ProcessManager.log.08 in index $I30 of file 237168 is incorrect.
Unable to locate the file name attribute of index entry PROCES~1.08
of index $I30 with parent 0x39e70 in file 0x4fb1.
Index entry PROCES~1.08 in index $I30 of file 237168 is incorrect.
  441250 index entries processed.                                       

Index verification completed.

Errors found.  CHKDSK cannot continue in read-only mode.

-----------------------------------------------------------------------
Category: 0
Computer Name: William-PC
Event Code: 1001
Record Number: 112785
Source Name: Microsoft-Windows-Wininit
Time Written: 06-27-2016 @ 21:47:51
Event Type: Information
User:
Message:

Checking file system on C:
The type of the file system is NTFS.

One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.                        

CHKDSK is verifying files (stage 1 of 3)...
The attribute of type 0x80 and instance tag 0x0 in file 0x652e
has allocated length of 0x4fd000 instead of 0x501000.
Deleted corrupt attribute list entry
with type code 128 in file 25902.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x14000000008acc.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 35532.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x24f00000001edad.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 126381.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x345000000032dcd.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 208333.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x16d00000003b95a.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 244058.
Unable to locate attribute with instance tag 0x0 and segment
reference 0xa400000003bd0a.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 245002.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x1e700000004467e.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 280190.
Deleted corrupt attribute list entry
with type code 128 in file 59063.
Unable to find child frs 0x41a4e with sequence number 0x101.
The attribute of type 0x80 and instance tag 0x0 in file 0xe6b7
has allocated length of 0x501000 instead of 0x45e000.
Deleted corrupt attribute list entry
with type code 128 in file 59063.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x12400000002e387.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 189319.
Unable to locate attribute with instance tag 0x0 and segment
reference 0xdc000000031d62.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 204130.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x289000000037327.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 226087.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x4714e with sequence number 0x91.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x4773f with sequence number 0x125.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x3c0b9 with sequence number 0x133.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x494a8 with sequence number 0x107.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x494c7 with sequence number 0xf3.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x4951a with sequence number 0x150.
  347904 file records processed.                                        

File verification completed.
  2231 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 3)...
Unable to locate the file name attribute of index entry 0000000000014D68
of index $I30 with parent 0x1e in file 0x4b01f.
Deleting index entry 0000000000014D68 in index $I30 of file 30.
The file reference 0x37300000003ca1c of index entry mt4pmh8x.0.cs of index $I30
with parent 0x206 is not the same as 0x38200000003ca1c.
Deleting index entry mt4pmh8x.0.cs in index $I30 of file 518.
The file reference 0x7e00000003e7e3 of index entry mt4pmh8x.cmdline of index $I30
with parent 0x206 is not the same as 0x8700000003e7e3.
Deleting index entry mt4pmh8x.cmdline in index $I30 of file 518.
The file reference 0x27200000003cb3c of index entry mt4pmh8x.dll of index $I30
with parent 0x206 is not the same as 0x28300000003cb3c.
Deleting index entry mt4pmh8x.dll in index $I30 of file 518.
The file reference 0xbc0000000416e8 of index entry mt4pmh8x.err of index $I30
with parent 0x206 is not the same as 0xbe0000000416e8.
Deleting index entry mt4pmh8x.err in index $I30 of file 518.
The file reference 0x17f0000000416df of index entry mt4pmh8x.out of index $I30
with parent 0x206 is not the same as 0x18c0000000416df.
Deleting index entry mt4pmh8x.out in index $I30 of file 518.
The file reference 0x2d600000003ca02 of index entry mt4pmh8x.tmp of index $I30
with parent 0x206 is not the same as 0x2f100000003ca02.
Deleting index entry mt4pmh8x.tmp in index $I30 of file 518.
The file reference 0x7e00000003e7e3 of index entry MT4PMH~1.CMD of index $I30
with parent 0x206 is not the same as 0x8700000003e7e3.
Deleting index entry MT4PMH~1.CMD in index $I30 of file 518.
The file reference 0x37300000003ca1c of index entry MT4PMH~1.CS of index $I30
with parent 0x206 is not the same as 0x38200000003ca1c.
Deleting index entry MT4PMH~1.CS in index $I30 of file 518.
The file reference 0x1830000000446bf of index entry JavaJRE_8u91_32-bit_PSIonlySPS.exe of index $I30
with parent 0x8acb is not the same as 0x1840000000446bf.
Deleting index entry JavaJRE_8u91_32-bit_PSIonlySPS.exe in index $I30 of file 35531.
The file reference 0x1830000000446bf of index entry JAVAJR~1.EXE of index $I30
with parent 0x8acb is not the same as 0x1840000000446bf.
Deleting index entry JAVAJR~1.EXE in index $I30 of file 35531.
The file reference 0x25400000004454d of index entry download_queued of index $I30
with parent 0x15e68 is not the same as 0x25500000004454d.
Deleting index entry download_queued in index $I30 of file 89704.
The file reference 0x25400000004454d of index entry DOWNLO~1 of index $I30
with parent 0x15e68 is not the same as 0x25500000004454d.
Deleting index entry DOWNLO~1 in index $I30 of file 89704.
The file reference 0x23100000004462c of index entry download_queued of index $I30
with parent 0x17c57 is not the same as 0x23200000004462c.
Deleting index entry download_queued in index $I30 of file 97367.
The file reference 0x23100000004462c of index entry DOWNLO~1 of index $I30
with parent 0x17c57 is not the same as 0x23200000004462c.
Deleting index entry DOWNLO~1 in index $I30 of file 97367.
  441404 index entries processed.                                       

Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
Recovering orphaned file BA9A7A~1.LOG (227149) into directory file 305133.
Recovering orphaned file battle.net-launcher-20160627T213335.563315.log (227149) into directory file 305133.
Recovering orphaned file ENTRY_~2 (246331) into directory file 58585.
Recovering orphaned file entry_loud (246331) into directory file 58585.
Recovering orphaned file entry (248322) into directory file 58585.
Recovering orphaned file 7-ZIP_~1.EXE (248348) into directory file 89704.
Recovering orphaned file 7-Zip_16.00_32-bit_SPS.exe (248348) into directory file 89704.
Recovering orphaned file approved (267999) into directory file 58585.
Recovering orphaned file DOWNLO~1 (268008) into directory file 89704.
Recovering orphaned file downloading (268008) into directory file 89704.
Recovering orphaned file DOWNLO~2 (268878) into directory file 89704.
Recovering orphaned file downloaded (268878) into directory file 89704.
Recovering orphaned file ENTRY_~1 (277847) into directory file 89704.
Recovering orphaned file entry_silent (277847) into directory file 89704.
Recovering orphaned file {33758~1 (278655) into directory file 3248.
Recovering orphaned file {33758a2f-e39b-4f97-9aeb-4bdf364be4a1} (278655) into directory file 3248.
Recovering orphaned file ENTRY_~2 (279885) into directory file 89704.
Recovering orphaned file entry_loud (279885) into directory file 89704.
Recovering orphaned file DOWNLO~1 (280108) into directory file 97367.
Recovering orphaned file downloading (280108) into directory file 97367.
Recovering orphaned file entry (280170) into directory file 89704.
Recovering orphaned file approved (280255) into directory file 89704.
Recovering orphaned file iTunes_12.3.2_32-bit_SPS.exe (286703) into directory file 35531.
Recovering orphaned file ITUNES~1.EXE (286703) into directory file 35531.
Recovering orphaned file AGB455~1.LOG (290423) into directory file 1606.
Recovering orphaned file Agent-20160627T213426.722402.log (290423) into directory file 1606.
Recovering orphaned file SC55AF~1 (290776) into directory file 518.
Recovering orphaned file scoped_dir932_31632 (290776) into directory file 518.
  18 unindexed files scanned.                                       

CHKDSK is recovering remaining unindexed files.
  2 unindexed files recovered.                                     

CHKDSK is verifying security descriptors (stage 3 of 3)...
Deleting an index entry with Id 8114 from index $SII of file 9.
Deleting an index entry with Id 8114 from index $SDH of file 9.
Replacing invalid security id with default security id for file 248348.
  347904 file SDs/SIDs processed.                                       

Cleaning up 11 unused index entries from index $SII of file 9.
Cleaning up 11 unused index entries from index $SDH of file 9.
Cleaning up 11 unused security descriptors.
Security descriptor verification completed.
Inserting data attribute into file 25902.
Inserting data attribute into file 59063.
Inserting data attribute into file 286703.
  46754 data files processed.                                          

CHKDSK is verifying Usn Journal...
The USN Journal length 0x705bd9ab0 in file 0xe5a7 is less the
largest USN encountered, 0x705c1b8d0, plus eight in file 0x45fef.
Repairing Usn Journal $J data stream.
Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.

 976657407 KB total disk space.
 658062784 KB in 290690 files.
    161248 KB in 46754 indexes.
       188 KB in bad sectors.
    445787 KB in use by the system.
     65536 KB occupied by the log file.
 317987400 KB available on disk.

      4096 bytes in each allocation unit.
 244164351 total allocation units on disk.
  79496850 allocation units available on disk.

Internal Info:
00 4f 05 00 2e 26 05 00 9e 2b 09 00 00 00 00 00  .O...&...+......
7f 28 00 00 41 00 00 00 00 00 00 00 00 00 00 00  .(..A...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................

Windows has finished checking your disk.
Please wait while your computer restarts.

-----------------------------------------------------------------------
Category: 0
Computer Name: William-PC
Event Code: 1001
Record Number: 112757
Source Name: Microsoft-Windows-Wininit
Time Written: 06-27-2016 @ 21:31:59
Event Type: Information
User:
Message:

Checking file system on C:
The type of the file system is NTFS.

One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.                        

CHKDSK is verifying files (stage 1 of 3)...
  347904 file records processed.                                        

File verification completed.
  2246 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 3)...
The multi-sector header signature for VCN 0x0 of index $I30
in file 0xeb93 is incorrect.
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
The multi-sector header signature for VCN 0x1 of index $I30
in file 0xeb93 is incorrect.
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
Correcting error in index $I30 for file 60307.
The index bitmap $I30 in file 0xeb93 is incorrect.
Correcting error in index $I30 for file 60307.
The down pointer of current index entry with length 0xa8 is invalid.
94 fe 00 00 00 00 03 00 a8 00 8e 00 01 00 00 00  ................
93 eb 00 00 00 00 02 00 f2 eb bf 2e eb f8 cc 01  ................
27 3b 72 70 eb f8 cc 01 27 3b 72 70 eb f8 cc 01  ';rp....';rp....
27 3b 72 70 eb f8 cc 01 00 00 00 00 00 00 00 00  ';rp............
00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00  ................
26 01 7b 00 37 00 46 00 45 00 33 00 32 00 31 00  &.{.7.F.E.3.2.1.
34 00 43 00 2d 00 32 00 38 00 33 00 45 00 2d 00  4.C.-.2.8.3.E.-.
34 00 30 00 43 00 36 00 2d 00 41 00 38 00 44 00  4.0.C.6.-.A.8.D.
35 00 2d 00 43 00 42 00 37 00 37 00 33 00 31 00  5.-.C.B.7.7.3.1.
31 00 30 00 30 00 39 00 30 00 43 00 7d 00 00 00  1.0.0.9.0.C.}...
ff ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00  ................
18 00 00 00 03 00 00 00 ff ff ff ff ff ff ff ff  ................
Sorting index $I30 in file 60307.
  441396 index entries processed.                                       

Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
Recovering orphaned file {C75FA~1 (22078) into directory file 60307.
Recovering orphaned file {C75FAD21-EC08-42F3-92D6-C9C0AB355345} (22078) into directory file 60307.
Recovering orphaned file {B2DC3~1 (22978) into directory file 60307.
Recovering orphaned file {B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83} (22978) into directory file 60307.
Recovering orphaned file {3B357~1 (23370) into directory file 60307.
Recovering orphaned file {3B35725F-C623-4A1E-B5CC-99C0868679E3} (23370) into directory file 60307.
Recovering orphaned file {F132A~1 (60308) into directory file 60307.
Recovering orphaned file {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} (60308) into directory file 60307.
Recovering orphaned file {40FEF~1 (60513) into directory file 60307.
Recovering orphaned file {40FEF622-6E0F-46B6-824B-A40C178FD4CD} (60513) into directory file 60307.
Recovering orphaned file {8833F~1 (60568) into directory file 60307.
Recovering orphaned file {8833FFB6-5B0C-4764-81AA-06DFEED9A476} (60568) into directory file 60307.
Recovering orphaned file {675F8~1 (60639) into directory file 60307.
Recovering orphaned file {675F86A8-E093-4002-87D5-915CC2C45571} (60639) into directory file 60307.
Recovering orphaned file {3DECD~1 (61481) into directory file 60307.
Recovering orphaned file {3DECD372-76A1-4483-BF10-B547790A3261} (61481) into directory file 60307.
Recovering orphaned file {823A6~1 (64413) into directory file 60307.
Recovering orphaned file {823A68CC-3049-4A6B-8F63-7DC85E4BB1C9} (64413) into directory file 60307.
Recovering orphaned file {0DEA9~1 (64570) into directory file 60307.
Recovering orphaned file {0DEA94ED-915A-4834-A87E-388D012C8E02} (64570) into directory file 60307.
Recovering orphaned file {7FE32~1 (65172) into directory file 60307.
Recovering orphaned file {698D7~1 (131745) into directory file 60307.
Recovering orphaned file {698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65} (131745) into directory file 60307.
Recovering orphaned file {D057A~1 (131970) into directory file 60307.
Recovering orphaned file {D057AA08-8CBF-42E3-9EAB-23B8FED1C279} (131970) into directory file 60307.
Recovering orphaned file {B73B4~1 (131971) into directory file 60307.
Recovering orphaned file {B73B4A99-4173-4747-BBEC-0F05E966F9D2} (131971) into directory file 60307.
Recovering orphaned file {A662E~1 (134847) into directory file 60307.
Recovering orphaned file {A662E280-64A8-4CF5-8407-13D0808602B3} (134847) into directory file 60307.
Recovering orphaned file {7914B~1 (138000) into directory file 60307.
Recovering orphaned file {7914BE1E-F186-4790-B8F4-9F63C52A41C1} (138000) into directory file 60307.
Recovering orphaned file {BEE64~1 (181485) into directory file 60307.
Recovering orphaned file {BEE64C14-BEF1-4610-8A68-A16EAA47B882} (181485) into directory file 60307.
  18 unindexed files scanned.                                       

Recovering orphaned file {F5920~1 (261082) into directory file 60307.
Recovering orphaned file {F59205C8-E5FB-43F5-AAB2-16C1760D4F59} (261082) into directory file 60307.
  0 unindexed files recovered.                                     

CHKDSK is verifying security descriptors (stage 3 of 3)...
  347904 file SDs/SIDs processed.                                       

CHKDSK is compacting the security descriptor stream
Cleaning up 6099 unused security descriptors.
  46747 data files processed.                                          

CHKDSK is verifying Usn Journal...
Read failure with status 0xc000009c at offset 0x1d2645d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646c000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d68000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6a000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6c000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d8d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d90000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d91000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d91000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85468000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85490000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e85494000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85495000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e85495000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85496000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e85496000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e854a7000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e854af000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830940000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x883094e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x883094f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x883094f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830950000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830950000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830951000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830956000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830957000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830957000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830958000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830962000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830963000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830963000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830964000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830964000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053638000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053641000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053642000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053642000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053643000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053643000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053644000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053644000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053645000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053645000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x5200b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x5200e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x5200f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x5200f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f8f9000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f903000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f904000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f904000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f915000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f915000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f916000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f916000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f917000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f917000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f918000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f925000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f926000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f926000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f947000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f950000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f951000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f951000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f952000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f952000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f953000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f953000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f954000 for 0xf000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f954000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4094774000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4094780000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4094781000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4094781000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4094782000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4094782000 for 0x1000 bytes.
  36838856 USN bytes processed.                                           

Usn Journal verification completed.
Adding 45 bad clusters to the Bad Clusters File.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.

 976657407 KB total disk space.
 658328852 KB in 290779 files.
    161276 KB in 46750 indexes.
       188 KB in bad sectors.
    481811 KB in use by the system.
     65536 KB occupied by the log file.
 317685280 KB available on disk.

      4096 bytes in each allocation unit.
 244164351 total allocation units on disk.
  79421320 allocation units available on disk.

Internal Info:
00 4f 05 00 82 26 05 00 f2 2b 09 00 00 00 00 00  .O...&...+......
7f 28 00 00 41 00 00 00 00 00 00 00 00 00 00 00  .(..A...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................

Windows has finished checking your disk.
Please wait while your computer restarts.

-----------------------------------------------------------------------
ListChkdskResult by SleepyDude v0.1.7 Beta | 21-09-2013

------< Log generate on 6/30/2016 3:43:12 AM >------
Category: 0
Computer Name: William-PC
Event Code: 1001
Record Number: 113083
Source Name: Microsoft-Windows-Wininit
Time Written: 06-30-2016 @ 06:02:01
Event Type: Information
User:
Message:

Checking file system on C:
The type of the file system is NTFS.

A disk check has been scheduled.
Windows will now check the disk.                        

CHKDSK is verifying files (stage 1 of 5)...
  347904 file records processed.                                        

File verification completed.
  2235 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 5)...
Unable to locate the file name attribute of index entry ProcessManager.log.08
of index $I30 with parent 0x39e70 in file 0x4fb1.
Deleting index entry ProcessManager.log.08 in index $I30 of file 237168.
Unable to locate the file name attribute of index entry PROCES~1.08
of index $I30 with parent 0x39e70 in file 0x4fb1.
Deleting index entry PROCES~1.08 in index $I30 of file 237168.
  441252 index entries processed.                                       

Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
  1 unindexed files scanned.                                       

CHKDSK is recovering remaining unindexed files.
  1 unindexed files recovered.                                     

CHKDSK is verifying security descriptors (stage 3 of 5)...
  347904 file SDs/SIDs processed.                                       

Cleaning up 52 unused index entries from index $SII of file 0x9.
Cleaning up 52 unused index entries from index $SDH of file 0x9.
Cleaning up 52 unused security descriptors.
Security descriptor verification completed.
  46675 data files processed.                                          

CHKDSK is verifying Usn Journal...
  10312616 USN bytes processed.                                           

Usn Journal verification completed.
CHKDSK is verifying file data (stage 4 of 5)...
Read failure with status 0xc000009c at offset 0x88309b0000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x88309bc000 for 0x1000 bytes.
Windows replaced bad clusters in file 13709
of name \PROGRA~3\Razer\INGAME~2\logs\WILLIA~1.LOG.
Read failure with status 0xc000009c at offset 0x16317000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x16317000 for 0x1000 bytes.
Windows replaced bad clusters in file 13751
of name \PROGRA~3\Linksys\Lela\Lela.log.9.
Read failure with status 0xc000009c at offset 0x282000 for 0x6000 bytes.
Read failure with status 0xc000009c at offset 0x282000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x283000 for 0x5000 bytes.
Read failure with status 0xc000009c at offset 0x283000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x284000 for 0x4000 bytes.
Read failure with status 0xc000009c at offset 0x284000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x285000 for 0x3000 bytes.
Read failure with status 0xc000009c at offset 0x285000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x286000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0x286000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x287000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x287000 for 0x1000 bytes.
Windows replaced bad clusters in file 23752
of name \Windows\winsxs\AM4693~1.175\bitsperf.dll.
Read failure with status 0xc000009c at offset 0x27f000 for 0x3000 bytes.
Read failure with status 0xc000009c at offset 0x27f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x280000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0x280000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x281000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x281000 for 0x1000 bytes.
Windows replaced bad clusters in file 24260
of name \Windows\winsxs\AMF71C~1.175\d3d8thk.dll.
Read failure with status 0xc000009c at offset 0x27c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x27c000 for 0x1000 bytes.
Windows replaced bad clusters in file 35343
of name \Users\Public\Desktop\smart6.lnk.
Read failure with status 0xc000009c at offset 0x27e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x27e000 for 0x1000 bytes.
Windows replaced bad clusters in file 35790
of name \Windows\APPCOM~1\APPRAI~1\Gated\gated.ini.
Read failure with status 0xc000009c at offset 0x28a000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0x28a000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x28b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x28b000 for 0x1000 bytes.
Windows replaced bad clusters in file 38541
of name \Windows\winsxs\X8D893~1.163\wlanutil.dll.
Read failure with status 0xc000009c at offset 0xcd782d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd782d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd782e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd782e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd782f000 for 0xf000 bytes.
Read failure with status 0xc000009c at offset 0xcd782f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7830000 for 0xe000 bytes.
Read failure with status 0xc000009c at offset 0xcd7830000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7831000 for 0xd000 bytes.
Read failure with status 0xc000009c at offset 0xcd7831000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7832000 for 0xc000 bytes.
Read failure with status 0xc000009c at offset 0xcd7832000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7833000 for 0xb000 bytes.
Read failure with status 0xc000009c at offset 0xcd7833000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7834000 for 0xa000 bytes.
Read failure with status 0xc000009c at offset 0xcd7834000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7835000 for 0x9000 bytes.
Read failure with status 0xc000009c at offset 0xcd7835000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7836000 for 0x8000 bytes.
Read failure with status 0xc000009c at offset 0xcd7836000 for 0x1000 bytes.
Windows replaced bad clusters in file 109301
of name \PROGRA~1\DYNAMI~1\STARSI~1\skins\APOC_vtk.bmp.
Read failure with status 0xc000009c at offset 0xcd801a000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd801f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8020000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8021000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8022000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8024000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8025000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8025000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8026000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8026000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8027000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8027000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8028000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8028000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd8029000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd8029000 for 0x1000 bytes.
Windows replaced bad clusters in file 115524
of name \Windows\winsxs\MSIL_S~1.216\SYSTEM~1.DLL.
Read failure with status 0xc000009c at offset 0xcd7b42000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b4f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b50000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b50000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b51000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b51000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b52000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b52000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b53000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b53000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b54000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b54000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b55000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b55000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b56000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b56000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b57000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b57000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b58000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b58000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b59000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b59000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b5a000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7b5a000 for 0x1000 bytes.
Windows replaced bad clusters in file 140219
of name \PROGRA~2\EA GAMES\MOHAA\mainta\sound\AMB_ST~1\AMDAE6~1.MP3.
Read failure with status 0xc000009c at offset 0xcd79c4000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c4000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c5000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c5000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c6000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c6000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c7000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c7000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c8000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79c8000 for 0x1000 bytes.
Windows replaced bad clusters in file 155603
of name \Windows\System32\GFFE49~1.RES.
Read failure with status 0xc000009c at offset 0xcd7698000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7698000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7699000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd7699000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769a000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769a000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769c000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd769f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd769f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a0000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a0000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a1000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a1000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a2000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a2000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a3000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a3000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a4000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd76a4000 for 0x1000 bytes.
Windows replaced bad clusters in file 161634
of name \MECHWA~1\War Temp\OLDHAR~1\7YROLD~1\URLCOMP\Stats\vid174\IMAGE0~1.JPG.
Read failure with status 0xc000009c at offset 0x4093d4b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4093d57000 for 0x1000 bytes.
Windows replaced bad clusters in file 174636
of name \PROGRA~3\Linksys\Lela\Lela.log.6.
Read failure with status 0xc000009c at offset 0xce1105000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xce110d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xce110e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xce1110000 for 0x1000 bytes.
Windows replaced bad clusters in file 194588
of name \PROGRA~2\COMMON~1\Adobe\PDFL\10.9\Fonts\ADOBEA~1.OTF.
Read failure with status 0xc000009c at offset 0xcd7504000 for 0x6000 bytes.
Read failure with status 0xc000009c at offset 0xcd7505000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7506000 for 0x4000 bytes.
Read failure with status 0xc000009c at offset 0xcd7506000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7507000 for 0x3000 bytes.
Read failure with status 0xc000009c at offset 0xcd7507000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7508000 for 0x2000 bytes.
Read failure with status 0xc000009c at offset 0xcd7508000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7509000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd7509000 for 0x1000 bytes.
Windows replaced bad clusters in file 201919
of name \PROGRA~2\Adobe\ADOBEP~1\Legal\uk_UA\license.html.
Read failure with status 0xc000009c at offset 0xcef988000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcef988000 for 0x1000 bytes.
Windows replaced bad clusters in file 222988
of name \PROGRA~3\Razer\INGAME~2\logs\WILLIA~1.01.
Read failure with status 0xc000009c at offset 0x3979000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x397e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x397f000 for 0xf000 bytes.
Read failure with status 0xc000009c at offset 0x397f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3980000 for 0xe000 bytes.
Read failure with status 0xc000009c at offset 0x3980000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3981000 for 0xd000 bytes.
Read failure with status 0xc000009c at offset 0x3981000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3982000 for 0xc000 bytes.
Read failure with status 0xc000009c at offset 0x3982000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3983000 for 0xb000 bytes.
Read failure with status 0xc000009c at offset 0x3983000 for 0x1000 bytes.
Windows replaced bad clusters in file 224497
of name \Users\William\AppData\LocalLow\MICROS~1\CRYPTN~1\Content\1C1B62~1.
Read failure with status 0xc000009c at offset 0xcd79ac000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0xcd79bb000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0xcd79bc000 for 0x6000 bytes.
Read failure with status 0xc000009c at offset 0xcd79bc000 for 0x1000 bytes.
Read failure with status 0xc00000
-----------------------------------------------------------------------
Category: 0
Computer Name: William-PC
Event Code: 26213
Record Number: 113067
Source Name: Chkdsk
Time Written: 06-30-2016 @ 03:01:30
Event Type: Information
User:
Message: Chkdsk was executed in read-only mode.  A volume snapshot was not used. Extra errors and warnings may be reported as the volume may have changed during the chkdsk run. 

Checking file system on C:
The type of the file system is NTFS.
The volume is in use by another process. Chkdsk
might report errors when no corruption is present.

WARNING!  F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
  347904 file records processed.                                        

File verification completed.
  2235 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 3)...
Unable to locate the file name attribute of index entry ProcessManager.log.08
of index $I30 with parent 0x39e70 in file 0x4fb1.

Index entry ProcessManager.log.08 in index $I30 of file 237168 is incorrect.
Unable to locate the file name attribute of index entry PROCES~1.08
of index $I30 with parent 0x39e70 in file 0x4fb1.
Index entry PROCES~1.08 in index $I30 of file 237168 is incorrect.
  441250 index entries processed.                                       

Index verification completed.

Errors found.  CHKDSK cannot continue in read-only mode.

-----------------------------------------------------------------------
Category: 0
Computer Name: William-PC
Event Code: 1001
Record Number: 112785
Source Name: Microsoft-Windows-Wininit
Time Written: 06-27-2016 @ 21:47:51
Event Type: Information
User:
Message:

Checking file system on C:
The type of the file system is NTFS.

One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.                        

CHKDSK is verifying files (stage 1 of 3)...
The attribute of type 0x80 and instance tag 0x0 in file 0x652e
has allocated length of 0x4fd000 instead of 0x501000.
Deleted corrupt attribute list entry
with type code 128 in file 25902.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x14000000008acc.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 35532.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x24f00000001edad.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 126381.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x345000000032dcd.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 208333.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x16d00000003b95a.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 244058.
Unable to locate attribute with instance tag 0x0 and segment
reference 0xa400000003bd0a.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 245002.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x1e700000004467e.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 280190.
Deleted corrupt attribute list entry
with type code 128 in file 59063.
Unable to find child frs 0x41a4e with sequence number 0x101.
The attribute of type 0x80 and instance tag 0x0 in file 0xe6b7
has allocated length of 0x501000 instead of 0x45e000.
Deleted corrupt attribute list entry
with type code 128 in file 59063.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x12400000002e387.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 189319.
Unable to locate attribute with instance tag 0x0 and segment
reference 0xdc000000031d62.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 204130.
Unable to locate attribute with instance tag 0x0 and segment
reference 0x289000000037327.  The expected attribute type is 0x80.
Deleting corrupt attribute record (128, "")
from file record segment 226087.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x4714e with sequence number 0x91.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x4773f with sequence number 0x125.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x3c0b9 with sequence number 0x133.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x494a8 with sequence number 0x107.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x494c7 with sequence number 0xf3.
Deleted corrupt attribute list entry
with type code 128 in file 286703.
Unable to find child frs 0x4951a with sequence number 0x150.
  347904 file records processed.                                        

File verification completed.
  2231 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 3)...
Unable to locate the file name attribute of index entry 0000000000014D68
of index $I30 with parent 0x1e in file 0x4b01f.
Deleting index entry 0000000000014D68 in index $I30 of file 30.
The file reference 0x37300000003ca1c of index entry mt4pmh8x.0.cs of index $I30
with parent 0x206 is not the same as 0x38200000003ca1c.
Deleting index entry mt4pmh8x.0.cs in index $I30 of file 518.
The file reference 0x7e00000003e7e3 of index entry mt4pmh8x.cmdline of index $I30
with parent 0x206 is not the same as 0x8700000003e7e3.
Deleting index entry mt4pmh8x.cmdline in index $I30 of file 518.
The file reference 0x27200000003cb3c of index entry mt4pmh8x.dll of index $I30
with parent 0x206 is not the same as 0x28300000003cb3c.
Deleting index entry mt4pmh8x.dll in index $I30 of file 518.
The file reference 0xbc0000000416e8 of index entry mt4pmh8x.err of index $I30
with parent 0x206 is not the same as 0xbe0000000416e8.
Deleting index entry mt4pmh8x.err in index $I30 of file 518.
The file reference 0x17f0000000416df of index entry mt4pmh8x.out of index $I30
with parent 0x206 is not the same as 0x18c0000000416df.
Deleting index entry mt4pmh8x.out in index $I30 of file 518.
The file reference 0x2d600000003ca02 of index entry mt4pmh8x.tmp of index $I30
with parent 0x206 is not the same as 0x2f100000003ca02.
Deleting index entry mt4pmh8x.tmp in index $I30 of file 518.
The file reference 0x7e00000003e7e3 of index entry MT4PMH~1.CMD of index $I30
with parent 0x206 is not the same as 0x8700000003e7e3.
Deleting index entry MT4PMH~1.CMD in index $I30 of file 518.
The file reference 0x37300000003ca1c of index entry MT4PMH~1.CS of index $I30
with parent 0x206 is not the same as 0x38200000003ca1c.
Deleting index entry MT4PMH~1.CS in index $I30 of file 518.
The file reference 0x1830000000446bf of index entry JavaJRE_8u91_32-bit_PSIonlySPS.exe of index $I30
with parent 0x8acb is not the same as 0x1840000000446bf.
Deleting index entry JavaJRE_8u91_32-bit_PSIonlySPS.exe in index $I30 of file 35531.
The file reference 0x1830000000446bf of index entry JAVAJR~1.EXE of index $I30
with parent 0x8acb is not the same as 0x1840000000446bf.
Deleting index entry JAVAJR~1.EXE in index $I30 of file 35531.
The file reference 0x25400000004454d of index entry download_queued of index $I30
with parent 0x15e68 is not the same as 0x25500000004454d.
Deleting index entry download_queued in index $I30 of file 89704.
The file reference 0x25400000004454d of index entry DOWNLO~1 of index $I30
with parent 0x15e68 is not the same as 0x25500000004454d.
Deleting index entry DOWNLO~1 in index $I30 of file 89704.
The file reference 0x23100000004462c of index entry download_queued of index $I30
with parent 0x17c57 is not the same as 0x23200000004462c.
Deleting index entry download_queued in index $I30 of file 97367.
The file reference 0x23100000004462c of index entry DOWNLO~1 of index $I30
with parent 0x17c57 is not the same as 0x23200000004462c.
Deleting index entry DOWNLO~1 in index $I30 of file 97367.
  441404 index entries processed.                                       

Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
Recovering orphaned file BA9A7A~1.LOG (227149) into directory file 305133.
Recovering orphaned file battle.net-launcher-20160627T213335.563315.log (227149) into directory file 305133.
Recovering orphaned file ENTRY_~2 (246331) into directory file 58585.
Recovering orphaned file entry_loud (246331) into directory file 58585.
Recovering orphaned file entry (248322) into directory file 58585.
Recovering orphaned file 7-ZIP_~1.EXE (248348) into directory file 89704.
Recovering orphaned file 7-Zip_16.00_32-bit_SPS.exe (248348) into directory file 89704.
Recovering orphaned file approved (267999) into directory file 58585.
Recovering orphaned file DOWNLO~1 (268008) into directory file 89704.
Recovering orphaned file downloading (268008) into directory file 89704.
Recovering orphaned file DOWNLO~2 (268878) into directory file 89704.
Recovering orphaned file downloaded (268878) into directory file 89704.
Recovering orphaned file ENTRY_~1 (277847) into directory file 89704.
Recovering orphaned file entry_silent (277847) into directory file 89704.
Recovering orphaned file {33758~1 (278655) into directory file 3248.
Recovering orphaned file {33758a2f-e39b-4f97-9aeb-4bdf364be4a1} (278655) into directory file 3248.
Recovering orphaned file ENTRY_~2 (279885) into directory file 89704.
Recovering orphaned file entry_loud (279885) into directory file 89704.
Recovering orphaned file DOWNLO~1 (280108) into directory file 97367.
Recovering orphaned file downloading (280108) into directory file 97367.
Recovering orphaned file entry (280170) into directory file 89704.
Recovering orphaned file approved (280255) into directory file 89704.
Recovering orphaned file iTunes_12.3.2_32-bit_SPS.exe (286703) into directory file 35531.
Recovering orphaned file ITUNES~1.EXE (286703) into directory file 35531.
Recovering orphaned file AGB455~1.LOG (290423) into directory file 1606.
Recovering orphaned file Agent-20160627T213426.722402.log (290423) into directory file 1606.
Recovering orphaned file SC55AF~1 (290776) into directory file 518.
Recovering orphaned file scoped_dir932_31632 (290776) into directory file 518.
  18 unindexed files scanned.                                       

CHKDSK is recovering remaining unindexed files.
  2 unindexed files recovered.                                     

CHKDSK is verifying security descriptors (stage 3 of 3)...
Deleting an index entry with Id 8114 from index $SII of file 9.
Deleting an index entry with Id 8114 from index $SDH of file 9.
Replacing invalid security id with default security id for file 248348.
  347904 file SDs/SIDs processed.                                       

Cleaning up 11 unused index entries from index $SII of file 9.
Cleaning up 11 unused index entries from index $SDH of file 9.
Cleaning up 11 unused security descriptors.
Security descriptor verification completed.
Inserting data attribute into file 25902.
Inserting data attribute into file 59063.
Inserting data attribute into file 286703.
  46754 data files processed.                                          

CHKDSK is verifying Usn Journal...
The USN Journal length 0x705bd9ab0 in file 0xe5a7 is less the
largest USN encountered, 0x705c1b8d0, plus eight in file 0x45fef.
Repairing Usn Journal $J data stream.
Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.

 976657407 KB total disk space.
 658062784 KB in 290690 files.
    161248 KB in 46754 indexes.
       188 KB in bad sectors.
    445787 KB in use by the system.
     65536 KB occupied by the log file.
 317987400 KB available on disk.

      4096 bytes in each allocation unit.
 244164351 total allocation units on disk.
  79496850 allocation units available on disk.

Internal Info:
00 4f 05 00 2e 26 05 00 9e 2b 09 00 00 00 00 00  .O...&...+......
7f 28 00 00 41 00 00 00 00 00 00 00 00 00 00 00  .(..A...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................

Windows has finished checking your disk.
Please wait while your computer restarts.

-----------------------------------------------------------------------
Category: 0
Computer Name: William-PC
Event Code: 1001
Record Number: 112757
Source Name: Microsoft-Windows-Wininit
Time Written: 06-27-2016 @ 21:31:59
Event Type: Information
User:
Message:

Checking file system on C:
The type of the file system is NTFS.

One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.                        

CHKDSK is verifying files (stage 1 of 3)...
  347904 file records processed.                                        

File verification completed.
  2246 large file records processed.                                  

  0 bad file records processed.                                    

  0 EA records processed.                                          

  65 reparse records processed.                                     

CHKDSK is verifying indexes (stage 2 of 3)...
The multi-sector header signature for VCN 0x0 of index $I30
in file 0xeb93 is incorrect.
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
The multi-sector header signature for VCN 0x1 of index $I30
in file 0xeb93 is incorrect.
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff  ................
Correcting error in index $I30 for file 60307.
The index bitmap $I30 in file 0xeb93 is incorrect.
Correcting error in index $I30 for file 60307.
The down pointer of current index entry with length 0xa8 is invalid.
94 fe 00 00 00 00 03 00 a8 00 8e 00 01 00 00 00  ................
93 eb 00 00 00 00 02 00 f2 eb bf 2e eb f8 cc 01  ................
27 3b 72 70 eb f8 cc 01 27 3b 72 70 eb f8 cc 01  ';rp....';rp....
27 3b 72 70 eb f8 cc 01 00 00 00 00 00 00 00 00  ';rp............
00 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00  ................
26 01 7b 00 37 00 46 00 45 00 33 00 32 00 31 00  &.{.7.F.E.3.2.1.
34 00 43 00 2d 00 32 00 38 00 33 00 45 00 2d 00  4.C.-.2.8.3.E.-.
34 00 30 00 43 00 36 00 2d 00 41 00 38 00 44 00  4.0.C.6.-.A.8.D.
35 00 2d 00 43 00 42 00 37 00 37 00 33 00 31 00  5.-.C.B.7.7.3.1.
31 00 30 00 30 00 39 00 30 00 43 00 7d 00 00 00  1.0.0.9.0.C.}...
ff ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00  ................
18 00 00 00 03 00 00 00 ff ff ff ff ff ff ff ff  ................
Sorting index $I30 in file 60307.
  441396 index entries processed.                                       

Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
Recovering orphaned file {C75FA~1 (22078) into directory file 60307.
Recovering orphaned file {C75FAD21-EC08-42F3-92D6-C9C0AB355345} (22078) into directory file 60307.
Recovering orphaned file {B2DC3~1 (22978) into directory file 60307.
Recovering orphaned file {B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83} (22978) into directory file 60307.
Recovering orphaned file {3B357~1 (23370) into directory file 60307.
Recovering orphaned file {3B35725F-C623-4A1E-B5CC-99C0868679E3} (23370) into directory file 60307.
Recovering orphaned file {F132A~1 (60308) into directory file 60307.
Recovering orphaned file {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} (60308) into directory file 60307.
Recovering orphaned file {40FEF~1 (60513) into directory file 60307.
Recovering orphaned file {40FEF622-6E0F-46B6-824B-A40C178FD4CD} (60513) into directory file 60307.
Recovering orphaned file {8833F~1 (60568) into directory file 60307.
Recovering orphaned file {8833FFB6-5B0C-4764-81AA-06DFEED9A476} (60568) into directory file 60307.
Recovering orphaned file {675F8~1 (60639) into directory file 60307.
Recovering orphaned file {675F86A8-E093-4002-87D5-915CC2C45571} (60639) into directory file 60307.
Recovering orphaned file {3DECD~1 (61481) into directory file 60307.
Recovering orphaned file {3DECD372-76A1-4483-BF10-B547790A3261} (61481) into directory file 60307.
Recovering orphaned file {823A6~1 (64413) into directory file 60307.
Recovering orphaned file {823A68CC-3049-4A6B-8F63-7DC85E4BB1C9} (64413) into directory file 60307.
Recovering orphaned file {0DEA9~1 (64570) into directory file 60307.
Recovering orphaned file {0DEA94ED-915A-4834-A87E-388D012C8E02} (64570) into directory file 60307.
Recovering orphaned file {7FE32~1 (65172) into directory file 60307.
Recovering orphaned file {698D7~1 (131745) into directory file 60307.
Recovering orphaned file {698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65} (131745) into directory file 60307.
Recovering orphaned file {D057A~1 (131970) into directory file 60307.
Recovering orphaned file {D057AA08-8CBF-42E3-9EAB-23B8FED1C279} (131970) into directory file 60307.
Recovering orphaned file {B73B4~1 (131971) into directory file 60307.
Recovering orphaned file {B73B4A99-4173-4747-BBEC-0F05E966F9D2} (131971) into directory file 60307.
Recovering orphaned file {A662E~1 (134847) into directory file 60307.
Recovering orphaned file {A662E280-64A8-4CF5-8407-13D0808602B3} (134847) into directory file 60307.
Recovering orphaned file {7914B~1 (138000) into directory file 60307.
Recovering orphaned file {7914BE1E-F186-4790-B8F4-9F63C52A41C1} (138000) into directory file 60307.
Recovering orphaned file {BEE64~1 (181485) into directory file 60307.
Recovering orphaned file {BEE64C14-BEF1-4610-8A68-A16EAA47B882} (181485) into directory file 60307.
  18 unindexed files scanned.                                       

Recovering orphaned file {F5920~1 (261082) into directory file 60307.
Recovering orphaned file {F59205C8-E5FB-43F5-AAB2-16C1760D4F59} (261082) into directory file 60307.
  0 unindexed files recovered.                                     

CHKDSK is verifying security descriptors (stage 3 of 3)...
  347904 file SDs/SIDs processed.                                       

CHKDSK is compacting the security descriptor stream
Cleaning up 6099 unused security descriptors.
  46747 data files processed.                                          

CHKDSK is verifying Usn Journal...
Read failure with status 0xc000009c at offset 0x1d2645d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646c000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x1d2646d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d68000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6a000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6b000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6c000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d6c000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d8d000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d90000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4500d91000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4500d91000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85468000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546d000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546e000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e8546f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85490000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e85494000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85495000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e85495000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e85496000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e85496000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x7e854a7000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x7e854af000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830940000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x883094e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x883094f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x883094f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830950000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830950000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830951000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830956000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830957000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830957000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830958000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830962000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830963000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830963000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x8830964000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x8830964000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053638000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053641000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053642000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053642000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053643000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053643000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053644000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053644000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x9053645000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x9053645000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x5200b000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x5200e000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x5200f000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x5200f000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f8f9000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f903000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f904000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f904000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f915000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f915000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f916000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f916000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f917000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f917000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f918000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f925000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f926000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f926000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f947000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f950000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f951000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f951000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f952000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f952000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f953000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f953000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f954000 for 0xf000 bytes.
Read failure with status 0xc000009c at offset 0x3f6f954000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4094774000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4094780000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4094781000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4094781000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4094782000 for 0x10000 bytes.
Read failure with status 0xc000009c at offset 0x4094782000 for 0x1000 bytes.
  36838856 USN bytes processed.                                           

Usn Journal verification completed.
Adding 45 bad clusters to the Bad Clusters File.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.

 976657407 KB total disk space.
 658328852 KB in 290779 files.
    161276 KB in 46750 indexes.
       188 KB in bad sectors.
    481811 KB in use by the system.
     65536 KB occupied by the log file.
 317685280 KB available on disk.

      4096 bytes in each allocation unit.
 244164351 total allocation units on disk.
  79421320 allocation units available on disk.

Internal Info:
00 4f 05 00 82 26 05 00 f2 2b 09 00 00 00 00 00  .O...&...+......
7f 28 00 00 41 00 00 00 00 00 00 00 00 00 00 00  .(..A...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................

Windows has finished checking your disk.
Please wait while your computer restarts.

-----------------------------------------------------------------------

 

 

 

 

Be back later tonight. Thanks again or your help and look forward to hearing from you when you get an opportunity to research this log.


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired

#14 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,614 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:43 PM

Posted 30 June 2016 - 10:57 PM

That doesn't look good.

 

chkdsk found a lot of bad clusters causing multiple Read failures.

Bad clusters have a tendency to spread.

In my opinion your hard drive i going down and I strongly suggest you back up your data as soon as possible.

Most likely you need a new drive but to make sure...

 

Run hard drive diagnostics: http://www.bleepingcomputer.com/forums/topic28744.html/page__view__findpost__p__160520
Make sure, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: http://www.imgburn.com/ to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here: http://storage.toshiba.com/storage-services-support/warranty-support/software-utilities#diagnostic

Note : If you do not know how to set your computer to boot from CD follow the steps here


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#15 hYlAnDeR~TFC

hYlAnDeR~TFC
  • Topic Starter

  • Members
  • 257 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 30 June 2016 - 11:09 PM

Well, I ran the Seatools diagnostics and it reported mega failures.  This system at least boots into normal windows mode, however, there are obviously lots of problems and the ever present impending doom.  So, it looks like I will be doing some backing up over the next few days and then purchasing a new hard drive as well. 

 

Before we close this ticket, is there any chance you can help me to get my system back online to the internet?  This would be very helpful for use of my ISP storage as well.  Otherwise, thank you so very much for your help. it is greatly appreciated.


hYlAnDeR~TFC~
[OF/FA] Orion Faction-Retired
Game Squad Fleet Admiral~Retired




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users