Got hit with this real bad at work!
Source: McAfee
Virus Summary
Virus Name - W32/IRCbot.worm!MS05-039
Risk Assessment Corporate User : High Home User : High
Virus Information
Discovery Date: 08/16/2005
Origin: Unknown
Length: 10366 bytes
Type: Virus
SubType: Internet Relay Chat
Minimum DAT: 4560 (08/16/2005)
Updated DAT: 4560 (08/16/2005)
Minimum Engine: 4.4.00
Description Added: 08/16/2005
Description Updated: 08/16/2005 7:10 PM (PT)
Virus Characteristics
This detection is for an Internet Relay Chat (IRC) bot worm which includes the ability to spread by exploiting systems which are not yet patched for the MS05-039 vulnerability .
This worm is designed to contact a remote IRC server and wait for further instructions.
If you think that you may be infected with W32/IRCbot.worm!MS05-039, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present. This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).
Installation
When the file is run the virus copies itself to the Windows System directory (e.g. C:\Windows\System32\ on Windows XP) as WINTBP.EXE. The file can be run automatically by exploiting the MS05-039 vulnerability or by a person directly executing the worm.
Registry keys are created to load the worm at startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "wintbp.exe" = wintbp.exe
Symptoms
If this worm is run on a system which has not yet been patched for the MS05-039 vulnerability, it will continually reboot.
Method Of Infection
This threat scans for MS05-039 exploitable systems. When a vulnerable system is found, it uses a buffer overflow to write the worm file to that machine via a TFTP upload on port 8594. Blocking this port via McAfee Desktop Firewall or McAfee Personal Firewall will prevent infection even if the buffer overflow is not prevented.