W32/Tpbot-A is a network worm with backdoor Trojan functionality for the Windows platform.
When run, W32/Tpbot-A copies itself to the Windows system folder as wintbp.exe and creates the following registry entry in order to run each time a user logs on:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wintbp.exe
"wintbp.exe"
W32/Tpbot-A spreads using a variety of techniques including the exploitation of operating system vulnerabilities such as LSASS and PnP.
The backdoor component connects to an IRC server and joins a predetermined channel where it then awaits commands from attackers.
W32/Tpbot-A may attempt to download and execute additional files.
Patches for the operating system vulnerabilities exploited by W32/Tpbot-A can be obtained from Microsoft at:
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
http://www.microsoft.com/technet/security/bulletin/MS05-039.mspx