Sqlserver.exe - it’s not always a virus!

Date November 19, 2007

A few days ago I was looking through my processes window here at work on the Windows machine I use. It runs Windows XP Pro, for what that’s worth. I saw this…

Since I was dealing with a slightly sluggish system of late, I decided to Google this process to find out what the heck it was.

Do the search yourself and see what you think.

Do you think what I thought? A trojan! I was worried about this because I am super careful and consider myself darn savvy about where to click and where not to. I immediately ran my Trend Micro OfficeScan client as well as Windows Defender. Didn’t pick up a thing.

According to one link, the trojan is totally memory resident so scans won’t detect it. Uh, ok.

I found a removal tool, which crashed each time I ran it. Did I really have it and the trojan was knocking out the removal tool? Yikes!

I managed to find the log file generated by the removal tool and it said my ssnetlib.dll was not vulnerable. It shouldn’t be, I am up to date with all my Microsoft Updates.

So what’s the problem, then? I’ve got a process taking up 50 megs (sometimes way more) and I don’t know why. As a side note, I am familiar with the plain jane SQL Server and I have not ever installed it here. I don’t have any reason to.

After a few hours of quitting it and having it restart itself (the process, that is) I happened on a link that mentioned Pinnacle. Well, after seeing Dean Shareski’s green screen presentation for the Flat Classroom Project, I grabbed a copy of Pinnacle Studio 10 with the green screen (couldn’t find v. 11 locally) and installed it.

On a whim, I checked the Add/Remove Programs section and lo and behold…

I promptly removed it and went on about my day with a speedier system. This post is intended to hit the search results rankings so that others can see the sqlserver.exe is not always a trojan.

3 Responses to “Sqlserver.exe - it’s not always a virus!”

  1. Marty said:

    Thanks for your post. I have noticed the sqlserver.exe as well. Sometimes I have two running. When I shut it down, they don’t restart on their own until I reboot.

    I am a technodweeb. I happen to run PostgreSQL and was worried the sqlserver.exe was a part of the program.

    I want to remove the sqlserver.exe, but I’m not connecting with how the Pinnacle, which is a video editing program, will allow me to use the Add/Remove Programs feature.

  2. Chris said:

    Martin,

    Check the add/remove to see if there is something similar to the screenshot.

    My sqlserver.exe had been installed by the Pinnacle program. Not sure why, to be frank.

    Hope this helps..

    Chris

  3. Eric said:

    I would like to point out that your screenshot of the process list is “sqlservr.exe”; NOT “sqlserver.exe”

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>