Win32/Agent.ONB Trojan virus built into an mp3 player rom

Win32/Agent.ONB Trojan virus built into an mp3 player rom

Secure Home | Search | About

Anti-Virus Software - Computer security - anti-virus software 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Win32/Agent.ONB Trojan virus built into an mp3 player rom GJ 12-30-2008
Posted by GJ on December 30, 2008, 10:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
My nephew was given a no-name mp3 player, which looks like a USB drive, for
Christmas.

When the MP3 Player is plugged into a USB port on our computer, it is
identified by Windows XP home as two devices :-



1) AMT_CDROM , a read only drive



2) MP3_PLAY, a drive which contains mp3 files to be played by the
player.





The AMT_CDROM drive contains some files which try to run as soon as the
player is plugged in using the Windows AUTORUN function. These files are in
a chip on the player and cannot be deleted.

These files are



autorun.inf

AMT.sn

start.exe



The result of this is that Windows tries to run the file "start.exe", and as
soon as this happens it is flagged by the anti-virus software (NODS32) as
containing the Win32/Agent.ONB Trojan virus



There are some references to this virus on the web, but nothing very useful
which I have found so far - the following has been translated from Italian
on a forum and relates a similar experience.



"Hello everyone I have a question to be asked: I bought an mp3 player
similar to your shuffle from china 2 gi
The problem is that if I connect off with usb cable to PC then turn fits ...
you see, it works and everything is ok ...
But if the spengo and then riaccendo tells me "device not recognized" and
then at the end asks me to reboot the PC.
But the main problem is that my view on the PC in addition to "removable
disk" also similar to a disc player that if I clicked on from the antivirus
(nod 32) recognize a file start.exe. "
"G: \ AMT.sn 'cabinet' BackupTool.exe - probably a variant of
Win32/PSW.Agent horse tr ** a"
the presence of a file infested by trojan.
The result is this: "G: \ start.exe - Win32/Agent.ONB horse tr ** a - error
while deleting - file is locked - error while deleting - file is locked -
error while deleting - file is blocked. "
of course I can not remove in any way .... this disc (AMT_CDROM) despite the
low level formatting does not delete them ... but still active ... I do is
safe to use? You can delete? "



I can't find any details on what the virus does, if it really exists, does.



Has anyone come across this before ? If there is a virus present, it seems
to be encoded into the rom chip on the mp3 player during it's manufacture.

I can't imagine the presence of the virus pattern is a coincidence because
the function of the start.exe must be fairly simple in this use .



Look forward to hearing of any similar incidents or anything else about this
one you can tell me.



Thanks,



GJ



Posted by David H. Lipman on December 31, 2008, 6:22 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| My nephew was given a no-name mp3 player, which looks like a USB drive, for
| Christmas.

| When the MP3 Player is plugged into a USB port on our computer, it is
| identified by Windows XP home as two devices :-

| 1) AMT_CDROM , a read only drive
| 2) MP3_PLAY, a drive which contains mp3 files to be played by the
| player.

| The AMT_CDROM drive contains some files which try to run as soon as the
| player is plugged in using the Windows AUTORUN function. These files are in
| a chip on the player and cannot be deleted.

| These files are

| autorun.inf
| AMT.sn
| start.exe

| The result of this is that Windows tries to run the file "start.exe", and as
| soon as this happens it is flagged by the anti-virus software (NODS32) as
| containing the Win32/Agent.ONB Trojan virus

| There are some references to this virus on the web, but nothing very useful
| which I have found so far - the following has been translated from Italian
| on a forum and relates a similar experience.

| "Hello everyone I have a question to be asked: I bought an mp3 player
| similar to your shuffle from china 2 gi
| The problem is that if I connect off with usb cable to PC then turn fits ...
| you see, it works and everything is ok ...
| But if the spengo and then riaccendo tells me "device not recognized" and
| then at the end asks me to reboot the PC.
| But the main problem is that my view on the PC in addition to "removable
| disk" also similar to a disc player that if I clicked on from the antivirus
| (nod 32) recognize a file start.exe. "
"G:: \ AMT.sn 'cabinet' BackupTool.exe - probably a variant of
| Win32/PSW.Agent horse tr ** a"
| the presence of a file infested by trojan.
| The result is this: "G: \ start.exe - Win32/Agent.ONB horse tr ** a - error
| while deleting - file is locked - error while deleting - file is locked -
| error while deleting - file is blocked. "
| of course I can not remove in any way .... this disc (AMT_CDROM) despite the
| low level formatting does not delete them ... but still active ... I do is
| safe to use? You can delete? "

| I can't find any details on what the virus does, if it really exists, does.

| Has anyone come across this before ? If there is a virus present, it seems
| to be encoded into the rom chip on the mp3 player during it's manufacture.

| I can't imagine the presence of the virus pattern is a coincidence because
| the function of the start.exe must be fairly simple in this use .

| Look forward to hearing of any similar incidents or anything else about this
| one you can tell me.

| Thanks,

| GJ


It is an AutoRun worm. If Eset doesn't provide technical information on what
this AutoRun
worm does, you'll have to provide the EXE file to Virus Total to see who else
recognizes
this threat and see if they have technical information on what this AutoRun does.


Please submit a sample to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition Virus
Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by on December 31, 2008, 7:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Same here - just got three of them from an ebay seller. I managed to
repartition and reformat, but still opens a virtual cdrom with said
files... cheers M

Posted by GJ on December 31, 2008, 9:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | My nephew was given a no-name mp3 player, which looks like a USB drive,
> for
> | Christmas.
>
> | When the MP3 Player is plugged into a USB port on our computer, it is
> | identified by Windows XP home as two devices :-
>
> | 1) AMT_CDROM , a read only drive
> | 2) MP3_PLAY, a drive which contains mp3 files to be played by
> the
> | player.
>
> | The AMT_CDROM drive contains some files which try to run as soon as the
> | player is plugged in using the Windows AUTORUN function. These files are
> in
> | a chip on the player and cannot be deleted.
>
> | These files are
>
> | autorun.inf
> | AMT.sn
> | start.exe
>
> | The result of this is that Windows tries to run the file "start.exe",
> and as
> | soon as this happens it is flagged by the anti-virus software (NODS32)
> as
> | containing the Win32/Agent.ONB Trojan virus
>
> | There are some references to this virus on the web, but nothing very
> useful
> | which I have found so far - the following has been translated from
> Italian
> | on a forum and relates a similar experience.
>
> | "Hello everyone I have a question to be asked: I bought an mp3 player
> | similar to your shuffle from china 2 gi
> | The problem is that if I connect off with usb cable to PC then turn fits
> ...
> | you see, it works and everything is ok ...
> | But if the spengo and then riaccendo tells me "device not recognized"
> and
> | then at the end asks me to reboot the PC.
> | But the main problem is that my view on the PC in addition to "removable
> | disk" also similar to a disc player that if I clicked on from the
> antivirus
> | (nod 32) recognize a file start.exe. "
> "G:: \ AMT.sn 'cabinet' BackupTool.exe - probably a variant of
> | Win32/PSW.Agent horse tr ** a"
> | the presence of a file infested by trojan.
> | The result is this: "G: \ start.exe - Win32/Agent.ONB horse tr ** a -
> error
> | while deleting - file is locked - error while deleting - file is
> locked -
> | error while deleting - file is blocked. "
> | of course I can not remove in any way .... this disc (AMT_CDROM) despite
> the
> | low level formatting does not delete them ... but still active ... I do
> is
> | safe to use? You can delete? "
>
> | I can't find any details on what the virus does, if it really exists,
> does.
>
> | Has anyone come across this before ? If there is a virus present, it
> seems
> | to be encoded into the rom chip on the mp3 player during it's
> manufacture.
>
> | I can't imagine the presence of the virus pattern is a coincidence
> because
> | the function of the start.exe must be fairly simple in this use .
>
> | Look forward to hearing of any similar incidents or anything else about
> this
> | one you can tell me.
>
> | Thanks,
>
> | GJ
>
>
> It is an AutoRun worm. If Eset doesn't provide technical information on
> what this AutoRun
> worm does, you'll have to provide the EXE file to Virus Total to see who
> else recognizes
> this threat and see if they have technical information on what this
> AutoRun does.
>
>
> Please submit a sample to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In addition
> Virus
> Total will provide the sample to all participating vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL...
> mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
Will do, but the mp3 player is now in Ballarat - I'll have to wait until my
nephew comes back to Melbourne.

Thanks,

GJ



Posted by kurt wismer on December 31, 2008, 4:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
GJ wrote:
> My nephew was given a no-name mp3 player, which looks like a USB drive, for
> Christmas.
>
> When the MP3 Player is plugged into a USB port on our computer, it is
> identified by Windows XP home as two devices :-
>
>
>
> 1) AMT_CDROM , a read only drive
>
>
>
> 2) MP3_PLAY, a drive which contains mp3 files to be played by the
> player.

this sounds like a variation on the U3 technology that certain usb flash
drives (notably the sandisk cruzer) come with... the technology allows
certain usb devices to bypass normal windows limitations on usb flash
drives (ie. normally usb drives initiate autoplay instead of autorun) by
presenting windows with 2 devices - one of them a CD drive (which by
default initiates autorun rather than autoplay)...

> The AMT_CDROM drive contains some files which try to run as soon as the
> player is plugged in using the Windows AUTORUN function. These files are in
> a chip on the player and cannot be deleted.

i think you may find that it is possible to delete these files, or more
accurately it should be possible to overwrite the partition on which
virtual cd drive exists with a new ISO file containing whatever you like...

it will almost certainly require special software specific to the
technology involved but i was able to 'neuter' the U3 installer on the
sandisk cruzer i bought earlier this year using just such a method...
unfortunately i don't know the name of the technology that would give
you the AMT_CDROM drive - a U3 disk would show U3 as the name of the cd
drive...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

Similar ThreadsPosted
DVD Player opens when shutting down. July 6, 2006, 6:45 am
Windows Media Player Error February 27, 2006, 8:53 pm
Windows Media Player 9 Problem! February 28, 2006, 5:48 pm
Windows Media Player DRM Exploit August 11, 2006, 7:54 pm
Any Internet Login & Media Player Not Working July 26, 2006, 6:27 pm
Researcher Finds Media Player Flaws Options (FWD) August 4, 2007, 6:47 am
Trojan Virus Please help April 22, 2007, 8:08 am
avg & trojan virus July 18, 2007, 12:48 pm
Has anyone seen details of this new trojan/virus? May 31, 2005, 10:21 am
help with virus deletion - trojan June 12, 2006, 4:50 am

The site map in XML format XML site map

Contact Us | Privacy Policy