Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

12.1.2015.2015 9.68%
12.1.2015.2015 3.23%
12.1.1000.157 29.03%
12.1.1000.157 3.23%
12.1.1000.157 3.23%
12.1.671.4971 3.23%
12.0.122.161 3.23%
11.0.6300.552 3.23%
11.0.6200.530 3.23%
11.0.6200.530 3.23%
11.0.6100.480 3.23%
11.0.6005.440 3.23%
11.0.6005.440 9.68%
11.0.6000.436 3.23%
11.0.5002.301 3.23%
11.0.4014.23 3.23%
11.0.4000.2261 3.23%
11.0.3001.2189 3.23%
11.0.780.980 3.23%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, LookupPrivilegeValueA, AdjustTokenPrivileges, GetTokenInformation, RegOpenKeyA, RegQueryValueExA, RegCloseKey, RegOpenKeyExA, RegSetValueExA, RegDeleteValueA, RegEnumKeyExA, RegFlushKey, RevertToSelf, ImpersonateLoggedOnUser, RegDeleteKeyA, RegEnumKeyA, RegEnumValueA, RegQueryInfoKeyA, RegCreateKeyExA, RegisterServiceCtrlHandlerA, OpenSCManagerA, OpenServiceA, ControlService, CloseServiceHandle, SetServiceStatus, RegisterEventSourceA, ReportEventA, DeregisterEventSource, StartServiceCtrlDispatcherA, QueryServiceStatus, ChangeServiceConfigA, StartServiceA, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsA, UnregisterTraceGuids, LookupAccountSidW, QueryServiceConfigA, RegOpenKeyExW, RegNotifyChangeKeyValue, RegQueryValueExW, QueryServiceStatusEx, RegCreateKeyExW, RegSetValueExW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, IsValidSecurityDescriptor, FreeSid, AllocateAndInitializeSid, GetLengthSid, AddAccessAllowedAce, GetAclInformation, DeleteAce, CheckTokenMembership, EqualSid, GetUserNameA, CryptAcquireContextA, CryptReleaseContext, CryptGetProvParam, CryptGetUserKey, CryptCreateHash, CryptHashData, CryptDestroyHash, CryptDeriveKey, CryptGenKey, CryptDestroyKey, SetSecurityInfo, AddAce, GetAce, AddAccessDeniedAce, InitializeAcl, GetSecurityInfo, CreateWellKnownSid, TraceMessage, DuplicateToken, CreateProcessAsUserA, RegDeleteKeyW, LookupAccountNameW, GetUserNameW, ChangeServiceConfig2A, GetFileSecurityA, CreateProcessAsUserW, CreateServiceA, DeleteService
crypt32.dll
CryptMsgGetParam, CryptQueryObject, CertGetNameStringW, CertFreeCertificateContext, CryptMsgClose, CertCloseStore, CertFindCertificateInStore
gdi32.dll
CreateCompatibleBitmap, CreateCompatibleDC, CreateSolidBrush
kernel32.dll
GetCurrentProcess, CloseHandle, OpenProcess, GetLastError, LocalAlloc, LocalFree, SetWaitableTimer, AttachConsole, FreeConsole, WTSGetActiveConsoleSessionId, GetSystemDirectoryW, GetComputerNameW, FindCloseChangeNotification, GetPrivateProfileSectionA, GetPrivateProfileSectionNamesA, GetPrivateProfileIntA, GetTempPathA, GetTempFileNameA, GetSystemWindowsDirectoryA, GetFileAttributesExA, ExpandEnvironmentStringsW, SetEnvironmentVariableW, GetEnvironmentVariableW, FindFirstChangeNotificationA, FindNextChangeNotification, CreateNamedPipeW, ConnectNamedPipe, lstrlenW, InterlockedIncrement, CreateFileW, SetFileAttributesA, CompareFileTime, GetSystemTime, SystemTimeToFileTime, GetProcessTimes, MultiByteToWideChar, GetSystemInfo, GetDateFormatA, GetModuleFileNameW, GetTimeFormatA, CreateWaitableTimerA, QueryPerformanceCounter, SetThreadPriority, GetExitCodeThread, TerminateThread, GetStartupInfoA, RemoveDirectoryA, GetComputerNameA, lstrcmpA, GetFileTime, RaiseException, InterlockedCompareExchange, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, InterlockedDecrement, WaitForMultipleObjects, WaitForSingleObjectEx, GetTickCount, LoadLibraryExW, FreeLibrary, GetProcAddress, lstrlenA, GetPrivateProfileStringA, WritePrivateProfileStringA, CreateDirectoryA, FindFirstFileA, FindClose, CreateEventA, WaitForMultipleObjectsEx, ResetEvent, GetCurrentThreadId, Sleep, SetEvent, GetVersionExA, WaitForSingleObject, FindNextFileA, DeleteFileA, CreateFileA, GetFileSize, ReadFile, SetFilePointer, WriteFile, SetEndOfFile, MoveFileA, GetFileAttributesA, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetSystemTimeAsFileTime, OutputDebugStringA, FormatMessageW, GetFileAttributesW, LoadLibraryA, GetWindowsDirectoryA, GetSystemDirectoryA, SetLastError, ExpandEnvironmentStringsA, HeapAlloc, GetProcessHeap, HeapFree, FormatMessageA, GetModuleHandleA, FileTimeToLocalFileTime, FileTimeToSystemTime, SizeofResource, LockResource, LoadResource, FindResourceA, DuplicateHandle, ResumeThread, SleepEx, FindResourceExA, CopyFileA, MoveFileExA, CreateToolhelp32Snapshot, Process32First, GetCurrentProcessId, Process32Next, GetModuleFileNameA, OpenEventA, TerminateProcess, GetExitCodeProcess, GetOverlappedResult, CreateFileMappingA, MapViewOfFile, UnmapViewOfFile, GetSystemDefaultLangID, GetLocaleInfoA, GetUserDefaultLangID, GetStdHandle, WideCharToMultiByte, DebugBreak, GetFullPathNameA, CreateMutexA, OpenMutexA, CreateProcessA, OpenFileMappingA, InterlockedExchange, HeapDestroy, HeapReAlloc, HeapSize, SystemTimeToTzSpecificLocalTime, GetThreadLocale, GetACP, GetNumberFormatA, lstrcpynA, GetShortPathNameW, GetSystemPowerStatus, lstrcatA, ExitProcess, SetConsoleCtrlHandler, GetStringTypeExW, GetStringTypeExA, GetEnvironmentVariableA, lstrcmpiW, lstrcmpiA, CompareStringW, CompareStringA, GetVersion, CreatePipe, GlobalAlloc, lstrcpyA, LoadLibraryExA, CreateThread, ProcessIdToSessionId, GlobalFree, DllMain, GetShortPathNameA, WritePrivateProfileSectionA, _lopen, _lclose, SetProcessWorkingSetSize
licenseman.dll
_LicensemanGetDaysUntilExpiration@4, _LicensemanSetLicenseFileA@4, _LicensemanIsEnforcementEnabled@4, _LicensemanRegisterForNotification@4, _LicensemanInitialize@4, _LicensemanCleanup@0, _LicensemanGetProductType@4
mfc80.dll
DllMain
msvcp100.dll
DllMain
msvcp80.dll
DllMain
msvcp90.dll
DllMain
msvcr100.dll
DllMain
msvcr80.dll
DllMain
msvcr90.dll
DllMain
netapi32.dll
Netbios, NetApiBufferFree
ole32.dll
CoInitialize, CoGetObject, StringFromGUID2, CoCreateInstance, CoUninitialize, CoInitializeEx, CoFreeUnusedLibraries
psapi.dll
GetModuleFileNameExA, GetProcessMemoryInfo, EnumProcessModules, EnumProcesses
setupapi.dll
SetupDiEnumDeviceInfo, SetupDiGetClassDevsA, SetupDiGetDeviceInstanceIdA, CM_Get_DevNode_Status, SetupDiGetDeviceRegistryPropertyA, SetupIterateCabinetA, SetupGetStringFieldA, SetupCloseInfFile, SetupFindNextLine, SetupOpenInfFileA, SetupGetLineTextA, SetupFindFirstLineA, SetupGetIntField, SetupDiDestroyDeviceInfoList
shell32.dll
ShellExecuteExA, ShellExecuteA, SHGetFolderPathA, SHGetSpecialFolderPathA, ExtractIconExW
shlwapi.dll
PathAddBackslashW, SHDeleteKeyA, PathRemoveBackslashA, PathAddBackslashA
spnet.dll
UnzipSignatureFile, UnzipFileToFolder
sylink.dll
SyLinkCreateInstance, SyLinkDeleteInstance
user32.dll
DispatchMessageA, LoadStringA, IsRectEmpty, GetDesktopWindow, CharNextA, MessageBoxA, PeekMessageA, TranslateMessage, MsgWaitForMultipleObjects, FindWindowA, GetSystemMetrics, CharUpperW, ExitWindowsEx, SendMessageTimeoutA, EnumWindows, GetWindowTextA, GetClassNameA, wsprintfA, CharLowerA, CharLowerW, CharUpperA, GetWindowThreadProcessId, GetWindowLongA, DrawIconEx, FillRect, EnableWindow
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueA, GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueW
wininet.dll
InternetCloseHandle, InternetOpenUrlA, InternetSetStatusCallback, InternetOpenA, InternetReadFile
ws2_32.dll
WSASocketA
wtsapi32.dll
WTSSendMessageW, WTSSendMessageA
Export table
BroadcastMessageToGuis
GetInterface
GetPluginHandle
GetSmcPath
GetTechPluginInfo
IsEnforcementEnabled
IsProductTypeSB
IsSepEnabled
IsSnacEnabled
SendMessageToGui
SendMessageToPlugin
SendMessageToService
SmcDebugLog

Smc.exe

Symantec Client Management Component by Symantec Corporation (Signed)

Remove Smc.exe
Version:   12.1.1000.157
MD5:   244687a7f63848235b8b5cc493b6caff
SHA1:   09e5c81563754363e2fc8fa5197550ca8aa5267b
SHA256:   d72df2c923af32059b4b59c727631a779f7eae7fa086aae667abcfcd8cde8ba6

Overview

smc.exe runs as a service under the name SmcService (SmcService) with extensive SYSTEM privileges (full administrator access). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Symantec Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:smc.exe
Publisher:Symantec Corporation
Product name:Symantec Client Management Component
Description:Symantec CMC Smc
Typical file path:C:\Program Files\symantec\symantec endpoint protection\12.1.1000.157.105\bin\smc.exe
File version:12.1.1000.157
Size:1.59 MB (1,667,328 bytes)
Certificate
Issued to:Symantec Corporation
Authority (CA):VeriSign
Effective date:Wednesday, September 8, 2010
Expiration date:Sunday, November 24, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 9.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • SmcService
  • 'SmcService' (Symantec Management Client)
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\Smc.exe'
  • Firewall exception for 'C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe'
Network connections
Access through an approved Windows firewall exception
  • [TCP] wcossep1.cos.agilent.com (130.29.24.61:8014)
  • [UDP] listens on port 49346
  • [UDP] listens on port 1097
  • [UDP] listens on port 1081
  • [UDP] listens on port 1126

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00048226%
    0.028634%
    Kernel CPU:0.00025238%
    0.013761%
    User CPU:0.00022988%
    0.014873%
    Kernel CPU time:33,875 ms/min
    100,923,805ms/min
    CPU cycles:15,176,440/sec
    17,470,203/sec
    Context switches:232/sec
    284/sec
    Memory
    Private memory:26.07 MB
    21.59 MB
    Private (maximum):25.13 MB
    Private (minimum):6.69 MB
    Non-paged memory:26.07 MB
    21.59 MB
    Virtual memory:147.68 MB
    140.96 MB
    Virtual memory (peak):153.14 MB
    169.69 MB
    Working set:12.74 MB
    18.61 MB
    Working set (peak):38.44 MB
    37.95 MB
    Page faults:1,280,914/min
    2,039/min
    I/O
    I/O read transfer:71.41 KB/sec
    1.02 MB/min
    I/O read operations:22/sec
    343/min
    I/O write transfer:8.47 KB/sec
    274.99 KB/min
    I/O write operations:9/sec
    227/min
    I/O other transfer:41.44 KB/sec
    448.09 KB/min
    I/O other operations:852/sec
    1,671/min
    Resource allocations
    Threads:37
    12
    Handles:782
    600
    GUI GDI count:50
    103
    GUI USER count:9
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command line:"C:\Program Files\symantec\symantec endpoint protection\12.1.1000.157.105\bin\smc.exe" /prefetcC:1
    Owner:SYSTEM
    Windows Service
    Service name:SmcService
    Display name:SmcService
    Description:“Provides communication with the Symantec Endpoint Protection Manager. It also provides network threat protection and application and device control for the client.”
    Type:Win32OwnProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    MSVCR90.dll
    Total CPU:0.00951376%
    0.272967%
    Kernel CPU:0.00506684%
    0.107585%
    User CPU:0.00444692%
    0.165382%
    CPU cycles:585,995/sec
    5,741,424/sec
    Context switches:13/sec
    79/sec
    Memory:652 KB
    1.16 MB
    sechost.dll
    Total CPU:0.00211038%
    Kernel CPU:0.00051683%
    User CPU:0.00159356%
    CPU cycles:409,281/sec
    Context switches:2/sec
    Memory:100 KB
    advapi32.dll (Advanced Windows 32 Base API by Microsoft)
    Total CPU:0.00087102%
    Kernel CPU:0.00033809%
    User CPU:0.00053292%
    Context switches:2/sec
    Memory:620 KB
    ntdll.dll
    Total CPU:0.00035632%
    Kernel CPU:0.00028506%
    User CPU:0.00007126%
    CPU cycles:10,178/sec
    Memory:1.23 MB
    ole32.dll
    Total CPU:0.00032314%
    Kernel CPU:0.00015080%
    User CPU:0.00017234%
    CPU cycles:9,885/sec
    Memory:1.36 MB
    Smc.exe (main module)
    Total CPU:0.00009654%
    Kernel CPU:0.00004249%
    User CPU:0.00005405%
    CPU cycles:1,077/sec
    Memory:1.6 MB
    WININET.dll
    Total CPU:0.00008617%
    Kernel CPU:0.00004309%
    User CPU:0.00004309%
    CPU cycles:4,475/sec
    Memory:1.72 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 50.00%
    Windows 7 Home Premium 20.00%
    Windows 7 Home Basic 6.67%
    Windows 7 Enterprise 6.67%
    Windows 7 Starter 6.67%
    Windows 7 Ultimate 3.33%
    Windows Vista Ultimate 3.33%
    Windows 7 Professional 3.33%

    Distribution by countryDistribution by country

    United States installs about 51.72% of Symantec Client Management Component.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 42.86%
    Hewlett-Packard 17.86%
    ASUS 14.29%
    Lenovo 7.14%
    Toshiba 7.14%
    Intel 7.14%
    Acer 3.57%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE