UNSOLVED

timothyoliphant1

updated

15 years ago

T

timothyoliphant1

2 Intern

26 Posts

0

1179710

September 5th, 2011 21:00

Is Highly Active Topic

Check Disk (CHKDSK) Detects File System Problem But Doesn't Fix It

Hi, recently I got a Windows System error in the tray menu regarding a corrupted file. The file affected was Firefox's 'prefs.js' file and my computer suggested I run checkdisk. So I ran checkdisk without the F parameter and it detected problems with the file system without specifying what. So I opened My Computer, right click the drive affected(C:) and opened error checking. I ticked both options and agreed to run checkdisk the next time the computer boots. I restart my computer and CHKDSK loads at boot time. After finish scanning, no error seems to appear in the result and computer restarts. And then CHKDSK appears again! Due to keyboard failure as mentioned in my previous thread, I couldn't cancel the scan so I forcefully shutdown my PC by pressing the power button. The next time the scan appears again but my keyboard works this time and I cancel it. It never scans again everytime I boot my computer. Running CHKDSK without the F parameter still gives the error below though. The files affected are always different. Loading and shutting down the computer seems a little sluggish after this problem. Any ideas?

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\User>chkdsk C:
The type of the file system is NTFS.

WARNING!  F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
File verification completed.
CHKDSK is verifying indexes (stage 2 of 3)...
Index verification completed.
CHKDSK is recovering lost files.
Recovering orphaned file WEBAPP~2.SQL (42897) into directory file 20278.
Recovering orphaned file webappsstore.sqlite-journal (42897) into directory file
 20278.
CHKDSK is verifying security descriptors (stage 3 of 3)...
Security descriptor verification completed.
CHKDSK is verifying Usn Journal...
Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

  78124063 KB total disk space.
  40854720 KB in 122049 files.
     48624 KB in 9219 indexes.
         0 KB in bad sectors.
    325671 KB in use by the system.
     65536 KB occupied by the log file.
  36895048 KB available on disk.

      4096 bytes in each allocation unit.
  19531015 total allocation units on disk.
   9223762 allocation units available on disk.

  • timothyoliphant1

    2 Intern

    26 Posts

    29131

    0

    Posted September 6th, 2011 12:00

    That's exactly what I did. I scheduled the scan via the Drive's Tool tab and the scan runs on boot. I ran the scan again without the F parameter after booting just to determine if problem is still there and sure enough it still reports the problem.

  • timothyoliphant1

    2 Intern

    26 Posts

    29133

    0

    Posted September 6th, 2011 12:00

    I don't think it's bad sector or damaged HDD. I did a thorough scan using CHKDSK and HD Tune and it does not report any bad sectors. I always keep a spare back up in another drive though.

  • timothyoliphant1

    2 Intern

    26 Posts

    29203

    0

    Posted September 6th, 2011 13:00

    Those are Firefox related files but that's just one example. Different errors are given everytime a scan is done. So far everything is running fine except for this weird problem.

  • timothyoliphant1

    2 Intern

    26 Posts

    29202

    0

    Posted September 7th, 2011 00:00

    Okay I ran CHKDSK again, in this sequence: Desktop > Safe Mode > Boot > Desktop

    And the results:

    1. Desktop - Windows found problems with the file system. (I did not copy down the full log)

    2. Safe Mode - No errors or problems whatsoever...

    C:\Documents and Settings\User>chkdsk C:
    The type of the file system is NTFS.

    WARNING!  F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    File verification completed.
    CHKDSK is verifying indexes (stage 2 of 3)...
    Index verification completed.
    CHKDSK is verifying security descriptors (stage 3 of 3)...
    Security descriptor verification completed.
    CHKDSK is verifying Usn Journal...
    Usn Journal verification completed.

      78124063 KB total disk space.
      38314232 KB in 122197 files.
         48664 KB in 9253 indexes.
             0 KB in bad sectors.
        325415 KB in use by the system.
         65536 KB occupied by the log file.
      39435752 KB available on disk.

          4096 bytes in each allocation unit.
      19531015 total allocation units on disk.
       9858938 allocation units available on disk.

    3. Boot - I took a picture before it reached 100% for Stage 5 but the result displayed was CLEAN after it automatically restarted the computer and result is displayed:

    Weird thing is Event Viewer seems to say otherwise:

    Event Type:    Information
    Event Source:    Winlogon
    Event Category:    None
    Event ID:    1001
    Date:        9/7/2011
    Time:        2:09:29 PM
    User:        N/A
    Computer:    User
    Description:
    Checking file system on C:
    The type of the file system is NTFS.

    A disk check has been scheduled.
    Windows will now check the disk.                         
    Cleaning up minor inconsistencies on the drive.
    Cleaning up 6 unused index entries from index $SII of file 0x9.
    Cleaning up 6 unused index entries from index $SDH of file 0x9.
    Cleaning up 6 unused security descriptors.
    CHKDSK is verifying Usn Journal...
    Usn Journal verification completed.
    CHKDSK is verifying file data (stage 4 of 5)...
    File data verification completed.
    CHKDSK is verifying free space (stage 5 of 5)...
    Free space verification is complete.

      78124063 KB total disk space.
      38313216 KB in 122199 files.
         48664 KB in 9253 indexes.
             0 KB in bad sectors.
        325415 KB in use by the system.
         65536 KB occupied by the log file.
      39436768 KB available on disk.

          4096 bytes in each allocation unit.
      19531015 total allocation units on disk.
       9859192 allocation units available on disk.

    Internal Info:
    e0 50 02 00 87 01 02 00 2a 0f 03 00 00 00 00 00  .P......*.......
    a1 26 00 00 00 00 00 00 58 04 00 00 00 00 00 00  .&......X.......
    96 d4 58 0a 00 00 00 00 76 71 77 78 00 00 00 00  ..X.....vqwx....
    0e 43 55 0e 00 00 00 00 90 d9 e2 4a 04 00 00 00  .CU........J....
    3c d8 02 1e 02 00 00 00 e4 79 63 0a 07 00 00 00  <........yc.....
    60 89 5e b2 00 00 00 00 b0 3a 07 00 57 dd 01 00  `.^......:..W...
    00 00 00 00 00 00 74 22 09 00 00 00 25 24 00 00  ......t"....%$..

    Windows has finished checking your disk.
    Please wait while your computer restarts.


    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


    4. Desktop - I ran CHKDSK again without the F parameter once desktop is loaded and got the errors again:

    C:\Documents and Settings\User>chkdsk C:
    The type of the file system is NTFS.

    WARNING!  F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    File verification completed.
    CHKDSK is verifying indexes (stage 2 of 3)...
    Index verification completed.
    CHKDSK is verifying security descriptors (stage 3 of 3)...
    Security descriptor verification completed.
    CHKDSK is verifying Usn Journal...
    Usn Journal verification completed.
    Correcting errors in the master file table's (MFT) BITMAP attribute.
    Correcting errors in the Volume Bitmap.
    Windows found problems with the file system.
    Run CHKDSK with the /F (fix) option to correct these.

      78124063 KB total disk space.
      40937180 KB in 122207 files.
         48664 KB in 9254 indexes.
             0 KB in bad sectors.
        325415 KB in use by the system.
         65536 KB occupied by the log file.
      36812804 KB available on disk.

          4096 bytes in each allocation unit.
      19531015 total allocation units on disk.
       9203201 allocation units available on disk.

    I'm puzzled... What could be the real problem or is CHKDSK falsely reporting as discussed here? : http://www.tomshardware.com/forum/79415-45-hard-disk-problem-chkdsk

  • timothyoliphant1

    2 Intern

    26 Posts

    3506

    0

    Posted September 7th, 2011 08:00

    I ran 'fsutil dirty query C:' and it says C: is NOT dirty.

    In the article above, I read that for XP I should install the latest Service Pack which is SP3. I'm on SP2 now. Should I upgrade?

    On another laptop at home, I also encounter such a problem on CHKDSK when running in read-only mode. The laptop is running on XP SP3.

    Why doesn't running CHKDSK in Safe Mode with command prompt detect any errors unlike other modes?

  • timothyoliphant1

    2 Intern

    26 Posts

    3506

    0

    Posted September 7th, 2011 09:00

    Yes I'm aware it's related to the OS. How do I determine the MFT size or number of files? If it does not exceed those numbers, what else could it be?

  • speedstep

    11 Legend

    46969 Posts

    29132

    0

    Posted September 6th, 2011 06:00

    You cannot run CHKDSK in a dos window.   Open a dos window.

    CMD.EXE

    Type CHKDSK /R

    It will ask you if you want to run chkdsk at next reboot.

    Say Yes and Restart.

    The hint is

    WARNING!  F parameter not specified.
    Running CHKDSK in read-only mode.

  • speedstep

    11 Legend

    46969 Posts

    29132

    0

    Posted September 6th, 2011 12:00

    Manually run Chkdsk

    If Autochk does not automatically run, you can manually run the Chkdsk disk scanner. To do this, follow these steps:

      1. Click Start, click Run, type chkdsk /f /r, and then click OK.

      2. At the command prompt, type Y to let the disk scanner run when you restart the computer.

      3. Restart the computer.

      4. Chkdsk will run.

    Keep in Mind that CHKDSK and Scandisk DO NOT REPAIR physical damage or bad sectors on a drive that is out of spares.

    Time to buy a new drive.  You may only have a few days, hours, minutes left.

  • speedstep

    11 Legend

    46969 Posts

    29133

    0

    Posted September 6th, 2011 12:00

    SQL Server orphaned files are not a desktop or Dell Hardware Issue.

  • speedstep

    11 Legend

    46969 Posts

    29202

    0

    Posted September 7th, 2011 06:00

    CHKDSK checks the database of objects IDs and their integrity set up in the operating system; their average size might be 200MB). And the problem is CHKDSK does not show the scan progress of such big index and appears to hang for a period of time, that is normal. You can get more detailed information about operating principles of CHKDSK and 'freeze' reasons of the scan process in the following article on the Microsoft site: An explanation of the new /C and /I Switches that are available to use with Chkdsk.exe .

    Kaspersky Labs antivirus claims to not interfere with chkdsk.

    They recommend chkdsk /I /r /f

    Thismay explain some of the issues: http://support.kaspersky.com/faq/?qid=208279501

    1. click on your start menu and open the run dialog.
    2. type "cmd" and return (note: dont enter quotes)
    3. Next type "fsutil dirty query C:"
    4. If the return message indicates that the volume is dirty go to step 5
    5. Next type "chkdsk C: /f /x"
    6. After that finshes repeat step 3.
    7. If it is no longer dirty then reboot and check again.

    Chkdsk.exe is the command-line interface for the CHKDSK program, which verifies the logical integrity of a file system. If CHKDSK encounters logical inconsistencies in file system data, CHKDSK performs actions that repair the file system data (assuming that the data is not in read-only mode).

    The /C and /I switches are valid only for a drive that is formatted in the NTFS file system. Each of the new switches directs the CHKDSK routine to bypass certain actions that CHKDSK would otherwise take to validate the integrity of NTFS data structures.

    If you run CHKDSK online, the code that actually performs the verification resides in utility DLLs, for example Untfs.dll and Ufat.dll. The verification routines that CHKDSK invokes are the same routines that run when a volume is verified through the Windows Explorer or Disk Management graphical user interface.

    However, if CHKDSK is scheduled to run when the computer restarts, the binary module that contains the verification code is Autochk.exe, a native Windows program. Because Autochk.exe runs early in the computer's startup sequence, Autochk.exe does not have the benefit of virtual memory or of other Win32 services.

    Autochk.exe generates the same kind of text output that the Chkdsk.exe utility DLLs generate. Autochk.exe displays this text output during the startup process and also logs an event in the application event log. The logged event information includes as much of the text output as can fit into the event log's data buffer.

    Because both Autochk.exe and the verification code in the Chkdsk.exe utility DLLs are based on the same source code, the rest of this article uses the term "CHKDSK" to refer generically to either Autochk.exe or Chkdsk.exe. Likewise, because this article concerns only those CHKDSK changes that involve NTFS volumes, any statement that "CHKDSK does such-and-such" means that "CHKDSK does such-and-such when CHKDSK runs on an NTFS volume."

    Note that if you use the /C and /I switches, it is possible for a volume to still be corrupted even after CHKDSK runs. Therefore, it is recommended that you use these switches only if downtime must be kept to a minimum. These switches are intended for situations when you must run CHKDSK on exceptionally large volumes and you require flexibility in managing the downtime that occurs.

    To understand when it might be appropriate to use the /C and /Iswitches, you need a basic understanding of some of the internal NTFS data structures, the kinds of corruption that can take place, what actions CHKDSK takes when it verifies a volume, and what the potential consequences are if you circumvent CHKDSK's usual verification steps.

    Understanding what CHKDSK does

    CHKDSK's activity is divided into three major passes, during which CHKDSK examines all the metadata on the volume, and an optional fourth pass.

    Metadata is "data about data." Metadata is the file system "overhead," so to speak, that keeps track of information about all of the files that are stored on the volume. Metadata includes information about what allocation units make up the data for a given file, what allocation units are free, what allocation units contain bad sectors, and so on. The data that the file contains, on the other hand, is termed "user data." NTFS protects its metadata through the use of a transaction log. User data is not protected in this way.

    Phase 1: Checking files

    During its first pass, CHKDSK displays a message that tells you that CHKDSK is verifying files and also displays the percent of verification that is completed, counting from 0 to 100 percent. During this phase, CHKDSK examines each file record segment in the volume's master file table (MFT).

    A specific file record segment in the MFT uniquely identifies every file and directory on an NTFS volume. The "percent completed" that CHKDSK displays during this phase is the percentage of the MFT that CHKDSK has verified. During this pass, CHKDSK examines each file record segment for internal consistency and builds two bitmaps, one representing the file record segments that are in use and the other representing the clusters on the volume that are in use.

    At the end of this phase, CHKDSK has identified the space that is in use and the space that is available, both within the MFT and on the volume as a whole. NTFS keeps track of this information in bitmaps of its own, which are stored on the disk. CHKDSK compares its results with the bitmaps that NTFS keeps. If there are discrepancies, the discrepancies are noted in the CHKDSK output. For example, if a file record segment that was in use is found to be corrupted, the disk clusters that were associated with that file record segment are marked as "available" in the CHKDSK bitmap but are marked as "in use" in the NTFS bitmap.

    Phase 2: Checking indexes

    During its second pass, CHKDSK displays a message that tells you that CHKDSK is verifying indexes and again displays the percent completed, counting from 0 to 100 percent. During this phase, CHKDSK examines each of the indexes on the volume.

    Indexes are essentially NTFS directories. The "percent completed" that CHKDSK displays during this phase is the percentage of the total number of the volume's directories that have been checked. During this pass, CHKDSK examines each directory that is on the volume, checking for internal consistency and verifying that every file and directory that is represented by a file record segment in the MFT is referenced by at least one directory. CHKDSK confirms that every file or subdirectory that is referenced in a directory actually exists as a valid file record segment in the MFT and also checks for circular directory references. Finally, CHKDSK confirms that the time stamps and file size information for the files are up-to-date in the directory listings for those files.

    At the end of this phase, CHKDSK has made sure that there are no "orphaned" files and that all directory listings are for legitimate files. An orphaned file is a file for which there is a legitimate file record segment but for which there is no listing in any directory. An orphaned file often can be restored to its proper directory if that directory still exists. If the proper directory no longer exists, CHKDSK creates a directory in the root directory and places the file there. If CHKDSK finds directory listings for file record segments that are no longer in use, or for file record segments that are in use but that do not correspond to the file that is listed in the directory, CHKDSK simply removes the directory entry for the file record segment.

    Phase 3: Checking security descriptors

    During its third pass, CHKDSK displays a message that tells you that CHKDSK is verifying security descriptors and, for the third time, displays "percent completed," counting from 0 to 100 percent. During this phase, CHKDSK examines each security descriptor that is associated with files or directories that are on the volume.

    Security descriptors contain information about ownership of a file or directory, about NTFS permissions for the file or directory, and about auditing for the file or directory. The "percent completed" that CHKDSK displays during this phase is the percentage of the volume's files and directories that have been checked. CHKDSK verifies that each security descriptor structure is well formed and is internally consistent. CHKDSK does not verify the actual existence of the users or groups that are listed or the appropriateness of the permissions that are granted.

    Phase 4: Checking sectors

    If the /R switch is in effect, CHKDSK runs a fourth pass to look for bad sectors in the volume's free space. CHKDSK attempts to read every sector on the volume to confirm that the sector is usable. Even without the /R switch, CHKDSK always reads sectors that are associated with metadata. Sectors that are associated with user data are read during earlier phases of CHKDSK if the /R switch is specified.

    When CHKDSK finds an unreadable sector, NTFS adds the cluster that contains that sector to its list of bad clusters. If the bad cluster is in use, CHKDSK allocates a new cluster to do the job of the bad cluster. If you are using a fault-tolerant disk, NTFS recovers the bad cluster's data and writes the data to the newly allocated cluster. Otherwise, the new cluster is filled with a pattern of 0xFF bytes.

    If NTFS encounters unreadable sectors during the course of normal operation, NTFS remaps the sectors in the same way that it does when CHKDSK runs. Therefore, using the /R switch is usually not essential. However, using the /R switch is a convenient way to scan the entire volume if you suspect that a disk might have bad sectors.