Re: wintbp.exe

Nick FitzGerald <[email protected]>
Newsgroups gmane.comp.security.virus
Organization Personal account
Message-ID <43035C9F.11349.B05FE90C@localhost>
[email protected] wrote:

> Don't know if anyone responded yet, but this looks like zotob.e (MS05-039
> Plug and Play vulnerability).
> http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.e.html

From the incredible paucity of data posted, it certainly sounds as if 
it might be that...

BUT, the data posted does not rule out that it is, in fact, the next 
variant of that worm which may, for example, spawn a separate instance 
from a different, temporarily created copy of the main .EXE and might, 
for instance, trash the host's hard drive if it sees the main .EXE 
deleted.

All that could easily be done and not detected by your typical, and 
even quite advanced admin.  It would surely be missed by someone naïve 
enough to think that a filename alone is sufficient grounds for making 
a malware diagnosis...


-- 
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3267092
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.