Nar.vbs

Discussion in 'Malware Help (A Specialist Will Reply)' started by McSeon, Oct 4, 2008.

  1. McSeon

    McSeon Private E-2

    Hello, i have been trying to get rid of this Malware for about the last week and a half now and seem to be doing nothing but agravating the situation.
    My system stopped autorunning CD's about 2 months ago, didnt think that it was much of an issue at the time. however about a week ago it started viewing any cd, game disc, or dvd in it as a blank CD even when the icon clearly was not. it has taken a longertime to shut down, and now its to the point that i cant even restart it or shut it down with the cd drive closed (as its a laptop) i am pretty sure that i got this malware from a USB Thumbdrive from work. i have run everything that was recommended in your read this thread. in addition to my normal antivirus, Bit defender, Ad-aware, and Avast home edition. Avast is the only program that has even found it, however it cannot delete it as once it deletes it from the C: drive it replicates to the H drive and so on. i have searched on google for the nar.vbs and the only thing i have been able to find is that its a nasty little bugger peice of malware that does something to the Autorun.inf file. and thats about all i really understand from it anyway. if you would please help me solve this issue i would be greatly in your debt.

    P.S. also, i have noticed that when i run avast antivirus when it finds the problem and i tell it to delete it, it does so but then it find it on the next drive down the chain, dont know if that helps or not.

    McSeon
     

    Attached Files:

  2. McSeon

    McSeon Private E-2

    and here is the second attachment for the logs as per the read me thread
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The very first instructions in the READ & RUN ME specify that you must only have one antivirus installed. You have Avast and Bitdefender installed. You must unintall one of these immediately before continuing.

    Note that all writeable removable media that has been plugged into this PC is most likely infected. Also any PCs that this removable media has been plugged into are also likely infected.

    You need to put your PC into Normal Startup mode with MSconfig as was requested in step 1 of the READ & RUN ME.


    Uninstall the below old versions of software:
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - AppInit_DLLs: kus109.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    You need to look for any of the below files on all hard disks and removable drives and delete these files if found.
    Autorun.inf
    bdod.bin
    nar.vbs
    auto.exe
    d.com
    autorun.exe
    Install FreeAgent Tools.exe


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. McSeon

    McSeon Private E-2

    I ran the Analyse.exe as administrator and i couldnt find any of the files that were specified. i am enclosing the log i got from it that lists the files that are available.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please finish the procedure and only attach the logs that I asked for.
     
  6. McSeon

    McSeon Private E-2

    I ran all the steps, except the analasis because the files that told me to fix were not there, in addition when i try to double click on my removeable media, i get a windows script host popup that says "can not find script file "E:\nar.vbs". second issue is that i cannot attach my MGlogs.zip file to this forum as i have already posted one. i tried renameing it but it will not post either way.
     

    Attached Files:

    Last edited: Oct 8, 2008
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because you did not follow the instructions given. You need to do the below as requested to get a new log:
    Hoiwever before getting a new MGlogs.zip file, you did not run combofix like the procedure requested. You were supposed to create the CFScript.txt file and drag it on top of the ComboFix.exe file on your Desktop. What you did was just run ComboFix which does not apply the fix.
     
  8. McSeon

    McSeon Private E-2

    it seems to have worked, i am no longer getting errors, it doesnt autoplay discs, but i feel thats ok so long as it is reading them again. What program would you recomend for me to keep my system from being infected again?

    i followed the steps, ran the getlogs.bat, got new mglogs, ran combo fix again with the cfscript. this time the cf script took, for some reason it didnt take the first time i ran it. however i cannot post the new MGlogs because it is saying that i already posted them to the forum.
     

    Attached Files:

    Last edited: Oct 9, 2008
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it is still the same log. Delete the current MGlogs.zip file that you have right now. Make sure you still have UAC disabled as requested in the READ & RUN ME. If it is not disabled, you must disable it and then reboot. And then run C:\MGtools\GetLogs.bat and make sure you let it finish running. Then attach the new C:\MGlogs.zip file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds