I found nothing in reference to the usb_d.exe, although there is
a bit of reference to usb_d + and usb_d - relating to usb
drivers.  I also found nothing here:

http://www.sysinfo.org/startupinfo.php

So maybe just a stray usb driver? Symantec has no info on it.

Incidentally, I hope everyone on the list has that link for
startups as part of their regular browser links.  It is perhaps
the most helpful site I have found when you want to see what is
what with programs on the system and has been recently updated
and recoded into a very comprehensive database.

Roger

=======================================================
The early bird gets the worm, but the second mouse gets the
cheese.



----- Original Message ----- 
From: "[EMAIL PROTECTED]"
<[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, December 26, 2003 2:16 AM
Subject: PCWorks: What is usb_d.exe, trojan of some kind?


> Does anyone know what usb_d.exe is?  I cannot find it at any
> search engine.  I'm presuming it's a worm, virus, Trojan, etc.
> because of the behavior that was exhibited it getting it.  Some
> parasite is sending out SPAM and when you click the link in it
> http://antwan052.com/special/ (which I did to find any email
> addresses at the site & no surprise is Ch*inese), it goes to a
> page that gives you download dialog box from 66.98.188.67
> which prompts you to OPEN "page.hta".  I instead of course
> saved it.  I got no AV software alert and my AV software is
> updated.  Of course this could easily be a new malicious
> code and no def's are available yet.  I also right clicked and
> scanned it, still no alert.  It's 62k in size.  I opened it in
> Notepad and it's a VBScript file which in ASCII format
> resembles that of a worm.  Out of curiosity (yeah, I know)
> I clicked the page.hta file and got a firewall warning (see
> below) from 66.98.188.67 & cjdra.com (both EV1) and
> cjdra.com is registered to the same parasite of the URL
> in the SPAM.  I of course denied the firewall request.  That
> file usb_d.exe is in the folder specified below and was just
> put there (and I deleted it from the system32 folder).  Right
> clicking it gives absolutely no info on what exactly it is.
> It's 27k in size.  When I ctrl-alt-del'd, usb_d.exe was
> running and I closed it down.  While it may not be a worm
> or virus, it does appear to be some type of spyware with
> Trojan behavior that sends info back to the sender.
>
> All of my anti-spyware programs showed nothing.  However SpyBot
> showed it (usb_d) WAS added to the startup group which I
> removed.  I had run MSCONFIG prior to this and oddly it didn't
> show in the startup tab then.  I searched the registry for
> usb_d and it showed up only under "run-disabled" which of
> course was there due to the fact I disabled it from starting
> up.  I deleted that key.
>
> Firewall warning:
>
> File Version :
> File Description : C:\WINDOWS\system32\usb_d.exe
> File Path :  C:\WINDOWS\system32\usb_d.exe
> Process ID :  508 (Heximal) 1288 (Decimal)
> Connection origin : local initiated
> Protocol :  TCP
> Local Address :  192.168.0.134
> Local Port :  3312
> Remote Name :  cjdra.com
> Remote Address : 66.98.188.67
> Remote Port :   80 (HTTP - World Wide Web)
> Ethernet packet details:
> Ethernet II (Packet Length: 62)
>  Destination:  00-50-18-09-61-4c
>  Source:  00-07-e9-02-0c-58
> Type: IP (0x0800)
> Internet Protocol
>  Version: 4
>  Header Length: 20 bytes
>  Flags:
>   .1.. = Don't fragment: Set
>   ..0. = More fragments: Not set
>  Fragment offset:0
>  Time to live: 64
>  Protocol: 0x6 (TCP - Transmission Control Protocol)
>  Header checksum: 0xc967 (Correct)
>  Source: 192.168.0.134
>  Destination: 66.98.188.67
> Transmission Control Protocol (TCP)
>  Source port: 3312
>  Destination port: 80
>  Sequence number: 351767516
>  Acknowledgment number: 0
>  Header length: 28
>  Flags:
>   0... .... = Congestion Window Reduce (CWR): Not set
>   .0.. .... = ECN-Echo: Not set
>   ..0. .... = Urgent: Not set
>   ...0 .... = Acknowledgment: Not set
>   .... 0... = Push: Not set
>   .... .0.. = Reset: Not set
>   .... ..1. = Syn: Set
>   .... ...0 = Fin: Not set
>  Checksum: 0xcb1d (Correct)
>  Data (0 Bytes)
> Binary dump of the packet:
> 0000:  00 50 18 09 61 4C 00 07 : E9 02 0C 58 08 00 45 5C |
> .P..aL.....X..E\
> 0010:  00 30 12 CF 40 00 40 06 : 67 C9 C0 A8 00 86 42 62 |
> [EMAIL PROTECTED]@.g.....Bb
> 0020:  BC 43 0C F0 00 50 14 F7 : 8B DC 00 00 00 00 70 02 |
> .C...P........p.
> 0030:  F7 80 1D CB 00 00 02 04 : 05 A0 01 01 04 02       |
> ..............
>
> -Clint
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to