cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1389
Views
1
Helpful
1
Replies

Error Massive error in 8.2.1.21612 version connector

jmandelbaum
Level 1
Level 1

Good morning, I sent the connector to update to the latest version (8.2.1.21612) and after waiting a few hours I see that I have 300 devices in the inbox that report the same event, which is "Suspicious smss.exe Parent Process". Could the new version have a bug? and also events like "Suspicious wininit.exe Parent Process" that says:

 

"End Process \{"amp_fingerprints"=>nil, "creation"=>0, "file_system_attr"=>-1, "modification"=>0, "name"=>"wininit .exe", "original_file_name"=>nil, "original_file_version"=>nil, "original_product_name"=>nil, "original_product_version"=>nil, "original_vendor_name"=>nil, "path"=>"C:\\Windows \\System32", "primary_signature"=>{"root_certificate"=>{"issuer"=>nil, "public_key_hash"=>nil, "serial"=>nil, "sha1"=>nil, "subject"=> nil, "type"=>nil, "valid_from"=>nil, "valid_to"=>nil}, "signing_certificate"=>{"issuer"=>nil, "public_key_hash"=>nil, "serial"=>nil , "sha1"=>nil, "subject"=>nil, "type"=>nil, "valid_from"=>nil, "valid_to"=>nil}}, "secondary_signature"=>{"root_certificate"=>{ "issuer"=>nil, "public_key_hash"=>nil, "serial"=>nil, "sha1"=>nil, "subject"=>nil, "type"=>nil, "valid_from"=>nil, " valid_to"=>nil}, "signing_certificate"=>{"issuer"=>nil, "public_key_hash"=>nil, "serial"=>nil, "sha1"=>nil, "subject"=>nil, "type "=>nil, "valid_from"=>nil, "valid_to"=>nil}}, "sha256"=>nil, "size"=>-1, "subsystem"=>-1}"

 

 

Thank you 

1 Reply 1

Roman Valenta
Cisco Employee
Cisco Employee

Same as this post:
https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922213#M7797

We are currently looking in to this issue and it seems to be related particularly to this version and FP event triggered by BP engine.