RE: wintbp.exe

"Schlegel, Justin" <[email protected]>
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
Yes I would have liked to provide additional information but I was dealing
with a worm for which no definitions existed.  I simply noticed a 6000
machines shutting down on their own. Wintbp.exe was running on every one of
those machines.  I understand that malicous code could generate random
filenames however the fact that the same process (definately not belonging
there) was running on 6000 machines and taking up a considerable amount of
system resources led me to believe that this had to be malicous.  At this
point I sent it to CA for analysis.  They had not seen it before but told me
it was in fact malicous and that they would have a beta fix for me in a few
hours.  Prior to this I had never seen an outbreak for which I couldn't find
some information at Symantec's website.  

-----Original Message-----
From: Nick FitzGerald
To: [email protected]
Sent: 8/16/2005 7:00 PM
Subject: Re: wintbp.exe

Schlegel, Justin wrote:

> My company has recently been hit with some variety of virus that is
> rebooting our machines.  As far as I can tell the process causing the
> problem is wintbp.exe.  I have searched in google and all the major AV
> vendors for this file with no luck.  Does anyone have any information
on
> this process as I do not know what virus I am up against?  

Filenames _ALONE_ are next to entirely useless as diagnostic cues for 
such things.  Sadly "causes the machine to reboot" is not particularly 
individualistic either...

Please send a sample to your preferred AV vendor(s) (and perhaps CC a 
few of their competitors you trust to hurry them along).  Should they 
happen to be on the following list, then I've saved you the trouble of 
looking up a suitable address.

   Authentium (Command Antivirus)  <[email protected]>
   Computer Associates (US)        <[email protected]>
   Computer Associates (Vet/EZ)    <[email protected]>
   DialogueScience (Dr. Web)       <[email protected]>
   Eset (NOD32)                    <[email protected]>
   F-Secure Corp.                  <[email protected]>
   Frisk Software (F-PROT)         <[email protected]>
   Grisoft (AVG)                   <[email protected]>
   H+BEDV (AntiVir, Vexira engine) <[email protected]>
   Kaspersky Labs                  <[email protected]>
   Network Associates (McAfee)     <[email protected]>
     (use a ZIP file with the password 'infected' without the quotes)
   Norman (NVC)                    <[email protected]>
   Panda Software                  <[email protected]>
   Sophos Plc.                     <[email protected]>
   Symantec (Norton)               <[email protected]>
   Trend Micro (PC-cillin)         <[email protected]>
     (Trend may only accept files from users of its products)

In general, you may find the advice under the McAfee entry best 
followed for any of the others as well.


-- 
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3267092
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.