Clint, do you by chance have a PDA connected to your system by USB?  I 
can't remember the reference file specifically but a relative had this on 
his system after he installed his sync software for his PDA.

Try a google on usb_d and drop the extension.

The page.hta in windows and IE is the Object Type validation vulnerability, 
there is a patch for it from MS with more info from CERT here: 
http://www.cert.org/advisories/CA-2003-22.html

Happy holidays,

Peter Kaulback

In the hour of 04:16 AM 12/26/2003, [EMAIL PROTECTED] spoke this:

>Does anyone know what usb_d.exe is?  I cannot find it at any
>search engine.  I'm presuming it's a worm, virus, Trojan, etc.
>because of the behavior that was exhibited it getting it.  Some
>parasite is sending out SPAM and when you click the link in it
>http://antwan052.com/special/ (which I did to find any email
>addresses at the site & no surprise is Ch*inese), it goes to a
>page that gives you download dialog box from 66.98.188.67
>which prompts you to OPEN "page.hta".  I instead of course
>saved it.  I got no AV software alert and my AV software is
>updated.  Of course this could easily be a new malicious
>code and no def's are available yet.  I also right clicked and
>scanned it, still no alert.  It's 62k in size.  I opened it in
>Notepad and it's a VBScript file which in ASCII format
>resembles that of a worm.  Out of curiosity (yeah, I know)
>I clicked the page.hta file and got a firewall warning (see
>below) from 66.98.188.67 & cjdra.com (both EV1) and
>cjdra.com is registered to the same parasite of the URL
>in the SPAM.  I of course denied the firewall request.  That
>file usb_d.exe is in the folder specified below and was just
>put there (and I deleted it from the system32 folder).  Right
>clicking it gives absolutely no info on what exactly it is.
>It's 27k in size.  When I ctrl-alt-del'd, usb_d.exe was
>running and I closed it down.  While it may not be a worm
>or virus, it does appear to be some type of spyware with
>Trojan behavior that sends info back to the sender.
>
>All of my anti-spyware programs showed nothing.  However SpyBot
>showed it (usb_d) WAS added to the startup group which I
>removed.  I had run MSCONFIG prior to this and oddly it didn't
>show in the startup tab then.  I searched the registry for
>usb_d and it showed up only under "run-disabled" which of
>course was there due to the fact I disabled it from starting
>up.  I deleted that key.
>
>Firewall warning:
>
>File Version :
>File Description : C:\WINDOWS\system32\usb_d.exe
>File Path :  C:\WINDOWS\system32\usb_d.exe
>Process ID :  508 (Heximal) 1288 (Decimal)
>Connection origin : local initiated
>Protocol :  TCP
>Local Address :  192.168.0.134
>Local Port :  3312
>Remote Name :  cjdra.com
>Remote Address : 66.98.188.67
>Remote Port :   80 (HTTP - World Wide Web)
>Ethernet packet details:
>Ethernet II (Packet Length: 62)
>  Destination:  00-50-18-09-61-4c
>  Source:  00-07-e9-02-0c-58
>Type: IP (0x0800)
>Internet Protocol
>  Version: 4
>  Header Length: 20 bytes
>  Flags:
>   .1.. = Don't fragment: Set
>   ..0. = More fragments: Not set
>  Fragment offset:0
>  Time to live: 64
>  Protocol: 0x6 (TCP - Transmission Control Protocol)
>  Header checksum: 0xc967 (Correct)
>  Source: 192.168.0.134
>  Destination: 66.98.188.67
>Transmission Control Protocol (TCP)
>  Source port: 3312
>  Destination port: 80
>  Sequence number: 351767516
>  Acknowledgment number: 0
>  Header length: 28
>  Flags:
>   0... .... = Congestion Window Reduce (CWR): Not set
>   .0.. .... = ECN-Echo: Not set
>   ..0. .... = Urgent: Not set
>   ...0 .... = Acknowledgment: Not set
>   .... 0... = Push: Not set
>   .... .0.. = Reset: Not set
>   .... ..1. = Syn: Set
>   .... ...0 = Fin: Not set
>  Checksum: 0xcb1d (Correct)
>  Data (0 Bytes)
>Binary dump of the packet:
>0000:  00 50 18 09 61 4C 00 07 : E9 02 0C 58 08 00 45 5C |
>.P..aL.....X..E\
>0010:  00 30 12 CF 40 00 40 06 : 67 C9 C0 A8 00 86 42 62 |
>[EMAIL PROTECTED]@.g.....Bb
>0020:  BC 43 0C F0 00 50 14 F7 : 8B DC 00 00 00 00 70 02 |
>.C...P........p.
>0030:  F7 80 1D CB 00 00 02 04 : 05 A0 01 01 04 02       |
>..............
>
>-Clint
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to