Win32/Agent.ONB Trojan virus built into an mp3 player rom

Win32/Agent.ONB Trojan virus built into an mp3 player rom

Secure Home | Search | About

Anti-Virus Software - Computer security - anti-virus software 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Win32/Agent.ONB Trojan virus built into an mp3 player rom GJ 12-30-2008
Posted by Ernie B. on December 31, 2008, 5:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Wed, 31 Dec 2008 16:36:17 -0500 kurt wismer wrote:

> GJ wrote:
> > My nephew was given a no-name mp3 player, which looks like a USB drive, for
> > Christmas.
<snip>
> > 1) AMT_CDROM , a read only drive
> >
> >
> >
> > 2) MP3_PLAY, a drive which contains mp3 files to be played by the
> > player.
<snip>
>
> i think you may find that it is possible to delete these files, or more
> accurately it should be possible to overwrite the partition on which
> virtual cd drive exists with a new ISO file containing whatever you like...
>
> it will almost certainly require special software specific to the
> technology involved but i was able to 'neuter' the U3 installer on the
> sandisk cruzer i bought earlier this year using just such a method...
> unfortunately i don't know the name of the technology that would give
> you the AMT_CDROM drive - a U3 disk would show U3 as the name of the cd
> drive...
>
You might consider a LiveCD of gparted,
<http://gparted.sourceforge.net/livecd.php>. It should be possible to delete
the partition in question and then expand the remaining partition to occupy
the entire drive.
--
Ernie B.

Communication: The art of moving an idea from one mind to another, hopefully
without distortion.

Posted by GJ on December 31, 2008, 6:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> On Wed, 31 Dec 2008 16:36:17 -0500 kurt wismer wrote:
>
>> GJ wrote:
>> > My nephew was given a no-name mp3 player, which looks like a USB drive,
>> > for
>> > Christmas.
> <snip>
>> > 1) AMT_CDROM , a read only drive
>> >
>> >
>> >
>> > 2) MP3_PLAY, a drive which contains mp3 files to be played by
>> > the
>> > player.
> <snip>
>>
>> i think you may find that it is possible to delete these files, or more
>> accurately it should be possible to overwrite the partition on which
>> virtual cd drive exists with a new ISO file containing whatever you
>> like...
>>
>> it will almost certainly require special software specific to the
>> technology involved but i was able to 'neuter' the U3 installer on the
>> sandisk cruzer i bought earlier this year using just such a method...
>> unfortunately i don't know the name of the technology that would give
>> you the AMT_CDROM drive - a U3 disk would show U3 as the name of the cd
>> drive...
>>
> You might consider a LiveCD of gparted,
> <http://gparted.sourceforge.net/livecd.php>. It should be possible to
> delete
> the partition in question and then expand the remaining partition to
> occupy
> the entire drive.
> --
> Ernie B.
>
> Communication: The art of moving an idea from one mind to another,
> hopefully
> without distortion.

I don't think this is the same as the U3 system, which is based on a
software start-up and it's easy to delete the U3 system software files(I've
done this on my 4Gb Sandisk Cruzer). The files involved here seem to be in
a rom in the device and they are ungettable at if you get my drift. The evil
partition seems to be set up by hardware and the files can't be deleted.
GJ



Posted by kurt wismer on December 31, 2008, 8:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
GJ wrote:
[snip]
> I don't think this is the same as the U3 system, which is based on a
> software start-up and it's easy to delete the U3 system software files(I've
> done this on my 4Gb Sandisk Cruzer). The files involved here seem to be in
> a rom in the device and they are ungettable at if you get my drift. The evil
> partition seems to be set up by hardware and the files can't be deleted.

well, i don't know about your cruzer, but mine had files on the 'cd
drive' as well as on the normal usb drive... the ones on the 'cd drive'
were not editable in the normal way either - they were as read-only as
the contents of any CD in fact... but i was able to find software to
write a new ISO to that drive...

oh, and U3 is not purely software-based, the hardware itself has to be
different from a standard usb flash drive in order to report multiple
devices to windows... basically the hardware has to lie to your
computer, which is not a standard practice...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

Posted by kurt wismer on December 31, 2008, 8:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Ernie B. wrote:
> On Wed, 31 Dec 2008 16:36:17 -0500 kurt wismer wrote:
[snip]
>> i think you may find that it is possible to delete these files, or more
>> accurately it should be possible to overwrite the partition on which
>> virtual cd drive exists with a new ISO file containing whatever you like...
>>
>> it will almost certainly require special software specific to the
>> technology involved but i was able to 'neuter' the U3 installer on the
>> sandisk cruzer i bought earlier this year using just such a method...
>> unfortunately i don't know the name of the technology that would give
>> you the AMT_CDROM drive - a U3 disk would show U3 as the name of the cd
>> drive...
>>
> You might consider a LiveCD of gparted,
> <http://gparted.sourceforge.net/livecd.php>. It should be possible to delete
> the partition in question and then expand the remaining partition to occupy
> the entire drive.

these aren't the same as logical partitions on a single physical
drive... the device reports 2 physical drives, one a removable drive and
one a cd drive...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

Posted by GJ on January 1, 2009, 2:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>
> these aren't the same as logical partitions on a single physical drive...
> the device reports 2 physical drives, one a removable drive and one a cd
> drive...

Yes, that's exactly what the mp3 player did.

Strangely I can't find this Win32/Agent.ONB virus listed anywhere in the
usual virus description libraries so I'm not sure how dangerous it is.

GJ



Similar ThreadsPosted
DVD Player opens when shutting down. July 6, 2006, 6:45 am
Windows Media Player Error February 27, 2006, 8:53 pm
Windows Media Player 9 Problem! February 28, 2006, 5:48 pm
Windows Media Player DRM Exploit August 11, 2006, 7:54 pm
Any Internet Login & Media Player Not Working July 26, 2006, 6:27 pm
Researcher Finds Media Player Flaws Options (FWD) August 4, 2007, 6:47 am
Trojan Virus Please help April 22, 2007, 8:08 am
avg & trojan virus July 18, 2007, 12:48 pm
Has anyone seen details of this new trojan/virus? May 31, 2005, 10:21 am
help with virus deletion - trojan June 12, 2006, 4:50 am

The site map in XML format XML site map

Contact Us | Privacy Policy