CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

cosine.exe & mssqlsrv.exe

 
Post new topic   Reply to topic       All -> FavForums -> Startup Programs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Wed Dec 22, 2004 1:49 am    Post subject: cosine.exe & mssqlsrv.exe
Reply with quote

A few entries I'm interested in, but I can't find anything about them. There's nothing on Google, nothing on a CCSP forum search except on [these] Logs, whereas a search at SWI for cosine only brings up [this] Log (not for the faint hearted). Searches for mssqlsrv brings no results at all, except the one Log I found these on in the first place.

By the way, the are reported to have requested Internet access.

O4 - HKLM\..\Run: [cosine] cosine.exe
O4 - HKLM\..\RunServices: [cosine] cosine.exe

O4 - HKCU\..\Run: [Microsoft SQL Srv] mssqlsrv.exe
O4 - HKLM\..\RunServices: [Microsoft SQL Srv] mssqlsrv.exe

Anybody got anything on these?


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
TonyKlein

Site Moderator
Microsoft MVP

Joined: Oct 15, 2002
Posts: 13120
Location: Netherlands
MIRT Moderators MVP Premium Security Experts

PostPosted: Sat Dec 25, 2004 9:18 am    Post subject:
Reply with quote

Both malware, by the looks of it...

As for your cosine.exe, from here:

Quote:
Scanned file: cosine.exe

cosine.exe - packed with PE-Diminisher cosine.exe - infected by Backdoor.Win32.Rbot.gen


The other one is probably another W.32 Rbot or a Gaobot worm variant.

When in doubt, have the poster upload the file to be tested, for example at http://virusscan.jotti.dhs.org/

Or of course request a sample of the file yourself.

Cheers,


_________________
Tony image CLSID List
Back to top
View users profile Send private message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Sat Dec 25, 2004 12:39 pm    Post subject:
Reply with quote

Okay, I've advised the user about these findings.

Many Thanks Very Happy And Merry Christmas Smile


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
TonyKlein

Site Moderator
Microsoft MVP

Joined: Oct 15, 2002
Posts: 13120
Location: Netherlands
MIRT Moderators MVP Premium Security Experts

PostPosted: Sat Dec 25, 2004 2:52 pm    Post subject:
Reply with quote

You're very welcome.

And of course happy holidays to you and yours as well! Smile


_________________
Tony image CLSID List
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Startup Programs All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer