[ superbaka @ 11.06.2004. 17:32 ] @
nakon instaliranja look n stop 2.05 mi je prijavio da smsc.exe pokusava da se poveze na net... slicnost sa smss.exe me je naterala da malo pronjuskam (pogotovu sto kaspersky i ad-aware cute kao zaliveni) i sve sto sam uspeo da nadjem je ovo
http://www.techsupportforum.com/computer/topic/18278-1.html
gde pri dnu strane tip kaze da treba da se izbrise

delete these files

C:\WINDOWS\System32\lsas.exe not to be confused with lsass.exe
C:\WINDOWS\System32\wserv32.exe
C:\WINDOWS\System32\smsc.exe


zanima me da li neko zna sta ovaj proces predstavlja i ako je stetan koje resenje preporucujete...
[ superbaka @ 11.06.2004. 18:29 ] @
a evo i ovo:
http://www.dslreports.com/foru...rk,10387488~mode=flat~start=20

i kao sto TIW kaze stvarno gasi msconfig ali nisam primetio da reaktivira proces posle desetak minuta
[ djolep @ 11.06.2004. 19:53 ] @
Citat:
I submitted the file to McAfee and they responded very promptly. It is
another variant of W32/Gaobot.worm.gen.


http://www.vsantivirus.com/gaobot-wf.htm
[ borstale @ 11.06.2004. 23:45 ] @
Meni ( i još jednom ortaku ) se to takođe dešava a obojica imamo Nortona 2003. Kod onih koje sam pitao a nemaju Nortona nema ni smsc.exe. Ja mu uvek dozvoljavam pristup netu i nisam primetio ništa loše. Da nemaš možda i ti pomenuti AV?
[ superbaka @ 12.06.2004. 09:34 ] @
ne, koristim kasperskog... poslao sam im fajl na analizu i evo njihovog odgovora:

Citat:
Hello, thank you, detected as Backdoor.ForBot.c


bas me zacudilo koliko su mi brzo odgovorili...
[ deki77 @ 12.06.2004. 11:37 ] @
A meni je nepoznato šta je smss.exe!!! i šta taj proces pokreće(imam AV nod32) !!!
[ reiser @ 12.06.2004. 12:18 ] @
Citat:

Process name: Windows NT Session Manager

Product: Windows

Company: Microsoft

File: smss.exe

Security Rating: +

This is the session manager subsystem, which is responsible for starting the user session. This process is initiated by the system thread and is responsible for various activities, including launching the Winlogon and Win32 (Csrss.exe) processes and setting system variables. After it has launched these processes, it waits for either Winlogon or Csrss to end. If this happens "normally," the system shuts down; if it happens unexpectedly, Smss.exe causes the system to stop responding (hang).

Note: The smss.exe file is located in the c:\windows\System32 folder. In other cases, smss.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager for free.

Virus with same name:
W32.Dalbug.Worm - Symantec Corporation
Adware.DreamAd - Symantec Corporation
W32.Resdoc - Symantec Corporation
Adware.Advision - Symantec Corporation
Backdoor.IRC.Flood.F - Symantec Corporation
Backdoor.IRC.Aladinz.O - Symantec Corporation
and more...
[ byTer @ 12.06.2004. 22:37 ] @
A pazi ovde

http://www.liutilities.com/pro...ntaskspro/processlibrary/smss/

smss - smss.exe - Process Information

Process File: smss or smss.exe
Process Name: Session Manager Subsystem
Description: Application that is used to start, manage, and delete user sessions or client sessions under Terminal Server.
Company: Microsoft Corp.
System Process: Yes
Security Risk ( Virus/Trojan/Worm/Adware/Spyware ): No
Common Errors: N/A