Amazing WinRAR problem.. Moved here as requested by TimW

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by maxplanck735, May 9, 2008.

  1. maxplanck735

    maxplanck735 Private E-2

    My log files are located in this thread, I'd repost them here but the forum won't let me. SEE BOTTOM POST IN THIS THREAD FOR MOST UP TO DATE LOGS:
    http://forums.majorgeeks.com/showthread.php?t=159129

    OK, the common part of this story is that WinRAR gives me "CRC failed. File is Corrupt" when I try to extract a large multi-Rar file.

    The uncommon part is: I'm running the latest WinRAR (3.7.1) on Windows XP SP2, SFV Checker checks all RARS as OK, and the RARs extract fine on my girlfriend's computer (Vista, WinRar 3.7.1)! (Yes, I'm starting extraction from the same file on both computers. It works on hers, but not on mine, even though we're using the same version of WinRAR and starting extraction from the same file).

    I'm sure that other people are extracting this archive under XP using WinRAR 3.71 with no problems, because nobody else has complained about CRC Error on this archive.

    I tried PowerArchiver, and I get the same CRC/File Corrupt error on my computer.

    I've scanned my computer for viruses, even run all of the virus scanners/fixes recommended in the majorgeeks.com malware removal support forum (see attached logs). I've even uninstalled WinRar, removed all Winrar entries from the Windows Registry, then Reinstalled WinRar. Still get CRC fail/File Corrupt.

    I ran a test on my RAM using Microsoft's bootable RAM tester application, let it run all night, and it says the RAM's fine. I ran chkdsk on both of my hard drives, and it did find some bad cluster and said it added them to its list (so i'm assuming windows now knows not to use these bad parts of the hard drives).

    I tried deleting and redownloading the RARs after having run chkdsk, but I still get CRC Fail/File Corrupt.

    I even tried taking the disk that I used to transfer the data to my GF's computer (where the extraction worked fine) and copied the data from that disc back to my hard drive, then tried extracting that data on my computer.. STILL CRC Fail/File Corrupt.

    Changed Motherboard battery, that didn't help.

    Tried tugzip, and it extracted with no error. However, when I try to burn and verify data with Nero, I get errors (data on dvd doesn't match data on hard drive). When I extract and burn using same version WinRAR and Nero on my girlfriend's computer, I get no errors.



    My Windows Drive is the drive that had bad clusters. When I ran chkdsk I had both options checked: "Automatically fix file system errors" and "Scan for and attempt recovery of bad sectors." Will chkdsk, with these options, either fix or quarantine the bad sectors so that they're not used anymore?

    My thinking is that perhaps Windows is using a bad sector/cluster in its pagefile, and that is causing WinRAR and Nero to write the wrong data.


    I really want to understand why I've been having these problem, because I want to make sure that my computer isn't writing incorrect data. I spend a lot of time on my computer doing work, it would be disastrous for me if my data was corrupted during the save process.

    If anyone has any ideas about this, please share

    My log files are located in this thread, I'd repost them here but the forum won't let me. SEE BOTTOM POST IN THIS THREAD FOR MOST UP TO DATE LOGS:
    http://forums.majorgeeks.com/showthread.php?t=159129
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I wanted you to do is to do the fix I gave you in the other thread ...then attach the logs in this new thread .....to see if it was successful.

    Then when we are sure it is not malware ...you can pursue the other issues again in the software thread.
     
  3. maxplanck735

    maxplanck735 Private E-2

    I did what you suggested in the old thread.

    I attached the new logs in the old thread, but the forum will not allow me to post the same logs here. So, please refer to the last post in the old thread for the new logs (I linked back to the old thread at the top of my post above).
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will go look at them soon ....please keep the malware logs that we may need in this thread. :)
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again....why is this user profile:

    Code:
    Users on this computer:
    Is Admin? | Username
    ------------------
       Yes    | Administrator
              | ASPNET
              | [U]eMule_Secure[/U]
    

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Otherwise....You look clean and can continue in the software section.

    Here is our standard clean up:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download FixWareout by LonnyRJones from one of the two below links and save it to your desktop.

    http://downloads.subratam.org/Fixwareout.exe

    http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

    * Run Fixwareout.
    * Click Next,
    * then Install,
    * make sure Run fixit is checked
    * and click Finish.
    * The fix will begin; follow the prompts.
    * You will be asked to reboot your computer; please do so.
    * Your system may take longer than usual to load; this is normal.

    When you run fixwareout, just follow the prompts, you will need to restart when prompted.

    After rebooting (restart) back into normal boot mode, make sure you have all web browsers closed.

    * Go into Control Panel -->Network Connections.
    * Right click on your connection
    * and click Properties.
    * On the Properties page, highlight Internet Protocol(TCP/IP)
    * Click Properties. This will bring up another page.
    * Select Obtain DNS Server Automatically.
    * Click the ok button. The page will close.
    * Press ok on the page in front of you.
    * Restart the computer.
    * Reconnect to the Internet using Internet Explorer.
    * Now come back here and attach the log from fixwareout. It is located at c:\fixwareout\report.txt
     
  7. maxplanck735

    maxplanck735 Private E-2

    Here's the log.

    I deleted the emule and Asp user accounts before running fixwareout. These user accounts were probably legitimate, simply used by these applications. But deleting them isn't a big deal, if I can get my problem solved.

    Should I post back in software now, or wait for replies here?

    Thanks again
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....at this point, any additional problems should be addressed in the software thread ....at least now you know it isn't malware! :)
     
  9. maxplanck735

    maxplanck735 Private E-2

    OK, thank a lot Tim!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds