RE: wintbp.exe
"Schlegel, Justin" <[email protected]>
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
Yes I would have liked to provide additional information but I was dealing with a worm for which no definitions existed. I simply noticed a 6000 machines shutting down on their own. Wintbp.exe was running on every one of those machines. I understand that malicous code could generate random filenames however the fact that the same process (definately not belonging there) was running on 6000 machines and taking up a considerable amount of system resources led me to believe that this had to be malicous. At this point I sent it to CA for analysis. They had not seen it before but told me it was in fact malicous and that they would have a beta fix for me in a few hours. Prior to this I had never seen an outbreak for which I couldn't find some information at Symantec's website. -----Original Message----- From: Nick FitzGerald To: [email protected] Sent: 8/16/2005 7:00 PM Subject: Re: wintbp.exe Schlegel, Justin wrote: > My company has recently been hit with some variety of virus that is > rebooting our machines. As far as I can tell the process causing the > problem is wintbp.exe. I have searched in google and all the major AV > vendors for this file with no luck. Does anyone have any information on > this process as I do not know what virus I am up against? Filenames _ALONE_ are next to entirely useless as diagnostic cues for such things. Sadly "causes the machine to reboot" is not particularly individualistic either... Please send a sample to your preferred AV vendor(s) (and perhaps CC a few of their competitors you trust to hurry them along). Should they happen to be on the following list, then I've saved you the trouble of looking up a suitable address. Authentium (Command Antivirus) <[email protected]> Computer Associates (US) <[email protected]> Computer Associates (Vet/EZ) <[email protected]> DialogueScience (Dr. Web) <[email protected]> Eset (NOD32) <[email protected]> F-Secure Corp. <[email protected]> Frisk Software (F-PROT) <[email protected]> Grisoft (AVG) <[email protected]> H+BEDV (AntiVir, Vexira engine) <[email protected]> Kaspersky Labs <[email protected]> Network Associates (McAfee) <[email protected]> (use a ZIP file with the password 'infected' without the quotes) Norman (NVC) <[email protected]> Panda Software <[email protected]> Sophos Plc. <[email protected]> Symantec (Norton) <[email protected]> Trend Micro (PC-cillin) <[email protected]> (Trend may only accept files from users of its products) In general, you may find the advice under the McAfee entry best followed for any of the others as well. -- Nick FitzGerald Computer Virus Consulting Ltd. Ph/FAX: +64 3 3267092