Win32/Agent.ONB Trojan virus built into an mp3 player rom

Win32/Agent.ONB Trojan virus built into an mp3 player rom

Secure Home | Search | About

Anti-Virus Software - Computer security - anti-virus software 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Win32/Agent.ONB Trojan virus built into an mp3 player rom GJ 12-30-2008
Posted by kurt wismer on January 1, 2009, 1:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
GJ wrote:
>> these aren't the same as logical partitions on a single physical drive...
>> the device reports 2 physical drives, one a removable drive and one a cd
>> drive...
>
> Yes, that's exactly what the mp3 player did.
>
> Strangely I can't find this Win32/Agent.ONB virus listed anywhere in the
> usual virus description libraries so I'm not sure how dangerous it is.

i'm afraid there are far too many pieces of malware out there for them
to all have a description in an online database - and the family name
"agent" specifically is used for so many things that it is of little
help either... did you follow david's suggestion and submit it to
virustotal.com? i've tried running "agent.onb" through vgrep to find
what other scanners might call it but there were not results returned...

what david said is almost certainly true, it's an autorun worm, but any
additional capabilities it might have depends very much on getting a
description for that specific variant...

if the search for a description is fruitless you may have to assume the
worst (ie. stealth, password stealing, etc)...

another thing you *could* try, however, is to contact the company that
makes your scanner and ask if it's a false alarm or not (you'll probably
have to send them a copy of the file)... they should be able to clear up
some of your other questions too...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

Posted by Oco on January 3, 2009, 6:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> GJ wrote:
> >> these aren't the same as logical partitions on a single physical drive=
...
> >> the device reports 2 physical drives, one a removable drive and one a =
cd
> >> drive...
>
> > Yes, that's exactly what the mp3 player did.
>
> > Strangely I can't find this Win32/Agent.ONB virus listed anywhere in th=
e
> > usual virus description libraries so I'm not sure how dangerous it is.
>
> i'm afraid there are far too many pieces of malware out there for them
> to all have a description in an online database - and the family name
> "agent" specifically is used for so many things that it is of little
> help either... did you follow david's suggestion and submit it to
> virustotal.com? i've tried running "agent.onb" through vgrep to find
> what other scanners might call it but there were not results returned...
>
> what david said is almost certainly true, it's an autorun worm, but any
> additional capabilities it might have depends very much on getting a
> description for that specific variant...
>
> if the search for a description is fruitless you may have to assume the
> worst (ie. stealth, password stealing, etc)...
>
> another thing you *could* try, however, is to contact the company that
> makes your scanner and ask if it's a false alarm or not (you'll probably
> have to send them a copy of the file)... they should be able to clear up
> some of your other questions too...
>
> --
> "it's not the right time to be sober
> now the idiots have taken over
> spreading like a social cancer,
> is there an answer?"

Your mp3 player looks like this? http://www.unibit.com.cn/English/products_=
show.asp?id=3D323
If so, try to update firmware/iso with the tool provided in download
section. There are several models in that page. Good luck

Posted by pjdura on March 15, 2009, 7:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

I had the same problem, but with the Trojan.Horse.PSW.Agent.YOM using
AVG 8.

And I SOLVED that, configuring my mp3 player to not auto music
transfer:

1) Press the Mp3 player configuration button to enter the configuration
Menu,

2) then choose the option: Sys
( It is the 5th option to the right: Msc, Rec, Voi, Fm, SYS, txt, tel )

3) Inside Sys configuration menu:, choose: Auto Music Transfer
( it is the 8th option to the righ: Record quality, Backlight time,
Color, Power Off, Replay set, Contrast, Languaje, AUTO MUSIC TRANSFER,
Memory info, Edition, Default, Exit )

4) Inside Auto Music Transfer: choose No ( close or disabled )

And after that, the next time you plug your mp3 player, you will not
see the AMT_CDROM again.

Hope that this would be usefull.


--
pjdura
------------------------------------------------------------------------
pjdura's Profile: http://forums.techarena.in/members/pjdura.htm
View this thread: http://forums.techarena.in/antivirus-software/1095733.htm

http://forums.techarena.in


Posted by aimie077 on May 5, 2009, 5:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Hello!
I have the same problem, tried An USB vaccine and what you said, but i
simply don't have this 'configuration' on my mp3 here so i couldnt make
it through and the plus driver, with the Trojan does not let me open
files and send them to the mp3 player,
could you pls help me?

thanx in advance


--
aimie077
------------------------------------------------------------------------
aimie077's Profile: http://forums.techarena.in/members/96530.htm
View this thread: http://forums.techarena.in/antivirus-software/1095733.htm

http://forums.techarena.in


Posted by 1PW on May 5, 2009, 7:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On 05/05/2009 02:08 PM, aimie077 sent:
> Hello!
> I have the same problem, tried An USB vaccine and what you said, but i
> simply don't have this 'configuration' on my mp3 here so i couldn't make
> it through and the plus driver, with the Trojan does not let me open
> files and send them to the mp3 player,
> could you pls help me?
>
> thanx in advance

Hello Aimie:

The problem with "stealing" the thread from GJ is that the focus can
change to you without a proper solution for GJ.

After reading this, please start a thread of your very own stating the
exact circumstances you believe you have this malware presently in your
system. Please include the exact details of your OS and antimalware
application that reported it and the full pathname to the infection.

Please don't leave out the "small" details

Pete
--
1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]

Similar ThreadsPosted
DVD Player opens when shutting down. July 6, 2006, 6:45 am
Windows Media Player Error February 27, 2006, 8:53 pm
Windows Media Player 9 Problem! February 28, 2006, 5:48 pm
Windows Media Player DRM Exploit August 11, 2006, 7:54 pm
Any Internet Login & Media Player Not Working July 26, 2006, 6:27 pm
Researcher Finds Media Player Flaws Options (FWD) August 4, 2007, 6:47 am
Trojan Virus Please help April 22, 2007, 8:08 am
avg & trojan virus July 18, 2007, 12:48 pm
Has anyone seen details of this new trojan/virus? May 31, 2005, 10:21 am
help with virus deletion - trojan June 12, 2006, 4:50 am

The site map in XML format XML site map

Contact Us | Privacy Policy