mrxsmb.sys

Windows SMB Redirector Driver

System DriverStableNetwork
CPU Usage
1-8%
Memory
50-200 MB
Location
C:\Windows\System32\drivers
Publisher
Microsoft Corporation

Quick Answer

mrxsmb.sys is a legitimate Windows SMB redirector driver. It enables client access to network shares by handling SMB requests between the local computer and remote servers.

Is it a Virus?
✔ NO - Safe
Must be located at C:\Windows\System32\drivers\mrxsmb.sys
Warning
SMB activity can spike during file sharing
mrxsmb.sys handles SMB client sessions; unusual spikes may indicate network issues or misconfigured shares
Can I Disable?
✔ NO
mrxsmb.sys is required for Windows network sharing; disabling will break access to remote shares and mapped drives

What is mrxsmb.sys?

mrxsmb.sys is the Windows SMB redirector driver that enables the client portion of SMB communications for network shares. It runs in the Windows kernel and handles requests to access network shares, map drives, and transfer files to and from remote servers when you connect to network shares or mapped drives.

mrxsmb.sys implements the SMB client path, coordinating session setup, signing, and data framing for file shares. It works with the Workstation service to manage connections and retries across the network, enabling reliable remote access.

Quick Fact: mrxsmb.sys is a core SMB client component that helps Windows communicate with network shares without user intervention.

Types of SMB Client Processes

Is mrxsmb.sys Safe?

Yes, mrxsmb.sys is safe when it is the legitimate file from Microsoft signed for Windows SMB client functionality.

Is mrxsmb.sys a Virus or Malware?

The real mrxsmb.sys is NOT a virus. Malware may masquerade with similar names; verify the file path and signature.

How to Tell if mrxsmb.sys is Legitimate or Malware

  1. File Location: Must be in C:\Windows\System32\drivers\mrxsmb.sys. Any other location is suspicious.
  2. Digital Signature: Right-click the file in Explorer > Properties > Digital Signatures. Should show a signature from Microsoft Corporation.
  3. Version and Publisher: In Properties > Details, verify Product name and Publisher reflect Microsoft Corporation and Windows components.
  4. Hash Verification: Compute a SHA256 hash: certutil -hashfile C:\Windows\System32\drivers\mrxsmb.sys SHA256 and compare with official Microsoft values.

Red Flags: If mrxsmb.sys is outside the System32\drivers folder, lacks a valid signature, or shows a tampered timestamp, scan with an updated antivirus and verify with Windows Defender.

Why Is mrxsmb.sys Running on My PC?

mrxsmb.sys runs to support Windows SMB client functionality for network shares. It activates during login, when a network drive is mapped, or when file operations occur with remote servers.

Reasons it's running:

Can I Disable or Remove mrxsmb.sys?

No, you should not disable mrxsmb.sys. It is a core Windows SMB client driver required for network shares and mapped drives.

How to Stop mrxsmb.sys (Not Recommended)

How to Disable SMB Client or Reduce mrxsmb.sys Impact