I found nothing in reference to the usb_d.exe, although there is a bit of reference to usb_d + and usb_d - relating to usb drivers. I also found nothing here:
http://www.sysinfo.org/startupinfo.php So maybe just a stray usb driver? Symantec has no info on it. Incidentally, I hope everyone on the list has that link for startups as part of their regular browser links. It is perhaps the most helpful site I have found when you want to see what is what with programs on the system and has been recently updated and recoded into a very comprehensive database. Roger ======================================================= The early bird gets the worm, but the second mouse gets the cheese. ----- Original Message ----- From: "[EMAIL PROTECTED]" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, December 26, 2003 2:16 AM Subject: PCWorks: What is usb_d.exe, trojan of some kind? > Does anyone know what usb_d.exe is? I cannot find it at any > search engine. I'm presuming it's a worm, virus, Trojan, etc. > because of the behavior that was exhibited it getting it. Some > parasite is sending out SPAM and when you click the link in it > http://antwan052.com/special/ (which I did to find any email > addresses at the site & no surprise is Ch*inese), it goes to a > page that gives you download dialog box from 66.98.188.67 > which prompts you to OPEN "page.hta". I instead of course > saved it. I got no AV software alert and my AV software is > updated. Of course this could easily be a new malicious > code and no def's are available yet. I also right clicked and > scanned it, still no alert. It's 62k in size. I opened it in > Notepad and it's a VBScript file which in ASCII format > resembles that of a worm. Out of curiosity (yeah, I know) > I clicked the page.hta file and got a firewall warning (see > below) from 66.98.188.67 & cjdra.com (both EV1) and > cjdra.com is registered to the same parasite of the URL > in the SPAM. I of course denied the firewall request. That > file usb_d.exe is in the folder specified below and was just > put there (and I deleted it from the system32 folder). Right > clicking it gives absolutely no info on what exactly it is. > It's 27k in size. When I ctrl-alt-del'd, usb_d.exe was > running and I closed it down. While it may not be a worm > or virus, it does appear to be some type of spyware with > Trojan behavior that sends info back to the sender. > > All of my anti-spyware programs showed nothing. However SpyBot > showed it (usb_d) WAS added to the startup group which I > removed. I had run MSCONFIG prior to this and oddly it didn't > show in the startup tab then. I searched the registry for > usb_d and it showed up only under "run-disabled" which of > course was there due to the fact I disabled it from starting > up. I deleted that key. > > Firewall warning: > > File Version : > File Description : C:\WINDOWS\system32\usb_d.exe > File Path : C:\WINDOWS\system32\usb_d.exe > Process ID : 508 (Heximal) 1288 (Decimal) > Connection origin : local initiated > Protocol : TCP > Local Address : 192.168.0.134 > Local Port : 3312 > Remote Name : cjdra.com > Remote Address : 66.98.188.67 > Remote Port : 80 (HTTP - World Wide Web) > Ethernet packet details: > Ethernet II (Packet Length: 62) > Destination: 00-50-18-09-61-4c > Source: 00-07-e9-02-0c-58 > Type: IP (0x0800) > Internet Protocol > Version: 4 > Header Length: 20 bytes > Flags: > .1.. = Don't fragment: Set > ..0. = More fragments: Not set > Fragment offset:0 > Time to live: 64 > Protocol: 0x6 (TCP - Transmission Control Protocol) > Header checksum: 0xc967 (Correct) > Source: 192.168.0.134 > Destination: 66.98.188.67 > Transmission Control Protocol (TCP) > Source port: 3312 > Destination port: 80 > Sequence number: 351767516 > Acknowledgment number: 0 > Header length: 28 > Flags: > 0... .... = Congestion Window Reduce (CWR): Not set > .0.. .... = ECN-Echo: Not set > ..0. .... = Urgent: Not set > ...0 .... = Acknowledgment: Not set > .... 0... = Push: Not set > .... .0.. = Reset: Not set > .... ..1. = Syn: Set > .... ...0 = Fin: Not set > Checksum: 0xcb1d (Correct) > Data (0 Bytes) > Binary dump of the packet: > 0000: 00 50 18 09 61 4C 00 07 : E9 02 0C 58 08 00 45 5C | > .P..aL.....X..E\ > 0010: 00 30 12 CF 40 00 40 06 : 67 C9 C0 A8 00 86 42 62 | > [EMAIL PROTECTED]@.g.....Bb > 0020: BC 43 0C F0 00 50 14 F7 : 8B DC 00 00 00 00 70 02 | > .C...P........p. > 0030: F7 80 1D CB 00 00 02 04 : 05 A0 01 01 04 02 | > .............. > > -Clint ============= PCWorks Mailing List ================= Don't see your post? Check our posting guidelines & make sure you've followed proper posting procedures, http://pcworkers.com/rules.htm Contact list owner <[EMAIL PROTECTED]> Unsubscribing and other changes: http://pcworkers.com =====================================================
