system
7
The legitimate file is C:\Windows\System32\smss.exe.
The suspicious file is C:\Windows\System\smss.exe
Before proceeding please extract HijackThis into its own folder (C:\HJT\ would be fine) and scan again from that location. Post the results. Also verify that you have smss.exe in the C:\Windows\System (not System32) directory