Author Topic: If not in System32 exe-file could be a virus  (Read 974 times)

Offline prodex

  • Comodo's Hero
  • *****
  • Posts: 643
If not in System32 exe-file could be a virus
« on: April 28, 2020, 03:12:54 AM »
There is a file which isn't only in the folder syste32 (smss.exe). If an *.exe file isn't in "system32", the file could be e virus and dangeorous, e.g.:

https://www.2-spyware.com/file-smss-exe.html

Quote
The legitimate SMSS is located at c:\windows\System32\smss.exe directory.

However, if you found this executable in other location, your computer is most likely to be infected with some cyber threat. The malicious smss.exe process can work as an executable file for launching parasites, loading main components of malicious programs and running a destructive payload.

I found this file in other folders (attachment) and uploaded it to virustotal. Result: Every security software: 'undetected'.
But the SMH1 and M5 checksums do not match the exe file in System32.

My PC is clean, "says" hitman pro (free), adware, Malwarebytes (free) and comodo.  :-[

Are there files (smss.exe is not the only file with such an behavour) which are needed from programs in other folders or is there a undetected malicious software (rootkit, malware ..) ?


« Last Edit: April 28, 2020, 03:19:16 AM by prodex »

Offline Ploget

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 2055
  • 'Your best teacher is your last mistake'
    • Schneier on Security
Re: If not in System32 exe-file could be a virus
« Reply #1 on: April 28, 2020, 03:47:31 AM »
Are you experiencing and major problems with essential Windows function such as startup, login etc.?

If not leave it well alone!

It is a critical part of Windows and will show in at least 2 or 3 locations along with System32 . . . Winsxs\amd64 . . . Servicing\LCU\Package folders etc. etc. There are 32 and 64 bit versions also with differing signatures

Be very wary of these sites that tell you a file 'may be' a virus and direct you to some other software to remove it. The one you reference is 2 years old and says nothing really except to raise doubts about a correct file location. Don't go looking for a problem if there isn't one to start with
There is a file which isn't only in the folder syste32 (smss.exe). If an *.exe file isn't in "system32", the file could be e virus and dangeorous, e.g.:
Ploget

Win10 x 64 Pro 21H2 (19044.1826) / CIS Pro 12.2.4.8032
Win11 x 64 Pro - 21H2 (22000.493) / CIS 12.2.2.8012
Comodo Forum Policy
“If you think you are too small to make a difference, try sleeping with a mosquito”

Offline prodex

  • Comodo's Hero
  • *****
  • Posts: 643
Re: If not in System32 exe-file could be a virus
« Reply #2 on: April 28, 2020, 04:06:41 AM »
Thxs for your prompt answer.

No, there are no problems with windows. PC (10 years old, was an upperclass-machine) starts after the start screen (when password is demanded) fix (hard disk, no ssd), sometimes comodo takes some time to show it's icon (but I must not make a coffee !), but the empty/"black" gap in the sys tray is to be seen earlier.
I never download software offered to delet anything.

So, everything is well!
« Last Edit: April 28, 2020, 04:29:53 AM by prodex »

Offline Ploget

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 2055
  • 'Your best teacher is your last mistake'
    • Schneier on Security
Re: If not in System32 exe-file could be a virus
« Reply #3 on: April 28, 2020, 04:15:34 AM »
The coffee sounds good - perfect timing for a system startup  ;)
No, there are no problems with windows. PC (10 years old, was an upper class-machine) starts after the start screen (when password is demanded) fix (hard disk, no ssd), sometimes comodo takes some time to show it's icon (but I must not make a coffee !), but the empty/"black" gab in the sys tray is to be seen earlier.
I never don't download software offered to delee anything.

So, everything is well!
Ploget

Win10 x 64 Pro 21H2 (19044.1826) / CIS Pro 12.2.4.8032
Win11 x 64 Pro - 21H2 (22000.493) / CIS 12.2.2.8012
Comodo Forum Policy
“If you think you are too small to make a difference, try sleeping with a mosquito”

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek