RE: wintbp.exe

"Joswiak, Johnny G." <[email protected]>
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
CA is calling it Win32.Peabot.A with a "Medium" alert, McAfee is calling it "W32/IRCbot.worm!MS05-039", Symantec has the Zotob.e, etcetera. 
Patch the systems, this is an MS05-039 exploit. The various antivirus companies can only provide cleanup after the worm hits unless they have buffer overflow protection like VSE8.0i provides (ok a plug but I like it). 
Hope this helps.
Johnny


-----Original Message-----
From:	William O'Malley [mailto:[email protected]]
Sent:	Tue 8/16/2005 8:51 PM
To:	Schlegel, Justin; [email protected]
Cc:	
Subject:	Re: wintbp.exe
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.