You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mystery smbd Process

Hello,

This was posted under a different topic so I am re-posting it here to make the question a little clearer. Perhaps someone with some true networking experience can help with this mystery.

I have a brand new 24-Inch iMac 3.06 GHz Intel Core 2 Duo (6 weeks old) and everything is working fine on it but I have a mystery process - actually two of them - running on this iMac in the Activity Monitor. I have two smbd processes (process id 224 and 225 - both belonging to "root") running in Activity Monitor and I just can't figure out why. The only thing that is "shared" on this new iMac is an Epson Stylus 870 USB Inkjet Printer through Printer Sharing. Nothing else in Sharing Preferences is turned on.

We have a small home network with a D-Link DI-604 router connected to a cable modem, an old Farallon ethernet hub cascaded to the router, an HP LaserJet 2100 TN Ethernet Network Printer, a PowerBook G4/667 and this 24-Inch iMac 3.06 GHz Intel Core 2 Duo all connected to the network. There's nothing else connected to the network at all.

We're not connecting with any Samba servers, Windows or Linux machines, nor have we ever done so in the past . We've never used Windows sharing at any point in the past (or installed any software related to it). There's nothing unrecognized in the /Library/StartupItems/ folder or in the System/Library/StartupItems/ folder on this new iMac at all - in fact, both folders are empty. And there's nothing in Accounts preferences Login Items other than just Mail.app.

This is a real mystery. Whenever I start up this iMac, I get two smbd processes running (process id 224 and 225 - both belonging to "root") showing up in Activity Monitor. The first one uses 2.13 MB of memory (process id 224) and the second one uses 312 KB of memory (process id 225). Both processes use 590.63 MB of virtual memory. Our PowerBook G4/667 running Mac OS X 10.4.11 connected to the same network has no smbd processes running on it at all.

Does anyone know why SMB would be running on this new iMac and if so, how do I turn it off? I can't make heads or tails out of the new Directory Utility in Mac OS X 10.5.6 (it was so much easier using the *Directory Access* Utility in Mac OS X 10.4.11).

Thanks for any help you can provide in solving this mystery.
Gerard

iMac 3.06 GHz Intel Core 2 Duo - 4 GB RAM, Mac OS X (10.5.6), Other Macs: PBG4/667

Posted on Feb 12, 2009 9:15 PM

Reply
4 replies

Feb 13, 2009 1:30 PM in response to Gerard James

Well - to add to the mystery of this whole smbd process thing, I went in and changed the IP address of our router just now (released and renewed the IP) and got a new IP address, restarted my iMac and both smbd processes are both now gone from the Activity Monitor list of processes.

This is just totally weird. Does anyone have any clue of what is going on? I'm really afraid that someone hacked us somehow (we have to have one "open" port on our router for iChat - port 5190 with "enable ping" turned on - in order to get iChat to work).

Thanks,
Gerard

Feb 13, 2009 4:25 PM in response to Limnos

Thanks for the link - it's a bit technical for me but I know what SMB is for and what I don't understand is why SMB keeps running on this iMac. After my last message, smbd stopped running as soon as I changed the IP address of our router and rebooted my iMac. But then - I logged back onto this forum using Safari and smbd began running again.

So I did some searching around on the iMac (still getting used to Leopard) and I noticed that there was a Drop Box folder in my Public Folder that was "shared" (showing as :shared" in the Get Info box for this folder) so I unchecked "shared" in the Get Info box for the Public Folder. Then I went into user account preferences and looked at the settings for Guest Account and noticed that "Allow guest to connect to shared folders" was checked (by default by the looks of it) so I unchecked that option. smbd then shut down right away.

Then I opened Safari again and smbd fired up again. It's on again right now in Activity Monitor - two processes again with different id numbers than the last time. If this is of any help, here is the console log - you'll notice that there are two smbd processes and console refers to one of them as a "stray" process:

Feb 13 15:20:10 my computername loginwindow[34]: USER_PROCESS: 34 console
Feb 13 15:20:10 my computername com.apple.launchd[1] (com.apple.UserEventAgent-LoginWindow[76]): Exited: Terminated
Feb 13 15:28:54 my computername com.apple.launchd[68] (0x1096a0.Locum[138]): Exited: Terminated
Feb 13 15:33:45 my computername com.apple.launchd[1] (org.samba.nmbd[161]): Exited: Terminated
Feb 13 15:33:45 my computername com.apple.launchd[1] (org.samba.nmbd): Throttling respawn: Will start in 10 seconds
Feb 13 15:37:45 my computername com.apple.launchd[1] (org.samba.smbd[174]): *Stray process with PGID equal to this dead job: PID 175 PPID 1 smbd*
Feb 13 15:37:54 my computername com.apple.launchd[1] (org.samba.nmbd): Throttling respawn: Will start in 2 seconds
Feb 13 15:40:02 my computername [0x0-0x26026].com.apple.Safari[220]: Debugger() was called!
Feb 13 15:44:38 my computername EPSON Stylus_Photo870[239]: EPSON Stylus_Photo870(239,0xa0055720) malloc: * error for object 0xffffffff: Non-aligned pointer being freed\n * set a breakpoint in malloc errorbreak to debug
Feb 13 15:47:06 my computername com.apple.launchd[1] (org.samba.smbd[231]): *Stray process with PGID equal to this dead job: PID 232 PPID 1 smbd*
Feb 13 15:47:06 my computername com.apple.launchd[1] (org.samba.smbd[231]): Exited abnormally: Interrupt
Feb 13 15:47:55 my computername com.apple.launchd[68] (0x109d00.Locum[254]): Exited: Terminated
Feb 13 15:49:36 my computername Disk Utility[261]: ********
Feb 13 15:49:36 my computername Disk Utility[261]: Disk Utility started.
Feb 13 15:49:41 my computername Disk Utility[261]: Repairing permissions for “Macintosh HD”
Feb 13 15:49:41 my computername Disk Utility[261]: Reading permissions database.
Feb 13 15:49:41 my computername Disk Utility[261]: Reading the permissions database can take several minutes.
Feb 13 15:53:27 my computername Disk Utility[261]:
Feb 13 15:53:27 my computername Disk Utility[261]: Permissions repair complete
Feb 13 15:53:27 my computername Disk Utility[261]:
Feb 13 15:53:57: --- last message repeated 1 time ---
Feb 13 15:55:37 my computername com.apple.launchd[1] (org.samba.smbd[269]): *Stray process with PGID equal to this dead job: PID 270 PPID 1 smbd*
Feb 13 15:55:45 my computername com.apple.launchd[1] (org.samba.nmbd): Throttling respawn: Will start in 3 seconds
Feb 13 15:56:28 my computername com.apple.launchd[1] (org.samba.nmbd[298]): Exited: Terminated
Feb 13 15:56:28 my computername com.apple.launchd[1] (org.samba.nmbd): Throttling respawn: Will start in 10 seconds

I'm lost. I guess the only real question I'd like to ask from here is that if SMB is running on my iMac, does it make my machine "vulnerable" to the outside world over the Internet?

Thanks for your help (and patience - it's a real mystery),
Gerard

Mystery smbd Process

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.