Explorer.EXE is this a virus???

Page 1 of 2 12 LastLast

  1. Posts : 16
    Windows 7 Home x64
       #1

    Explorer.EXE is this a virus???


    Every time I go to change a feature to my computer for example uninstalling a program my User Account Control window pops up asking me if I would want to allow the following program from an unknown publisher to make changes to this computer?

    Program name: Explorer.EXE
    Publisher: Unknown
    File origin: Hard drive on this computer

    I ask b/c I can't recall my computer ever doing this before Norton has Quarantined it due to suspicious behavior detected and if it is Norton states that the program has been blocked and removed and yet it still pops up each and every time I try to change something.... Norton shows file actions...
    File: c:\windows\syswow64\explorer.exe
    Removed

    it also states the Origin as
    Source File:
    7tsp_gui_v0.3_b(3003).exe
    File Created:
    explorer.exe
      My Computer


  2. Posts : 94
    Windows 7 Ultimate x64
       #2

    Could you please post a screen shot of such a prompt

    Explorer is not a virus (unless infected) it is the shell you see when you go to desktop when you open a folder so it is in essence the interface of windows.
    If a modification was made to the explorer e.g. changing the staring logo etc then it is normal that it will start to display
    Program name: Explorer.EXE
    Publisher: Unknown
    File origin: Hard drive on this computer

    For me as well after i used windows orb changer so yeah you are not the only one!

    I hoped this helped
      My Computer


  3. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #3

    Have you downloaded and installed any 'theme packs'?
      My Computer


  4. Posts : 16
    Windows 7 Home x64
    Thread Starter
       #4

    I have downloaded and installed theme packs & Ive changed my starting logo and orb... Moments ago I experienced my first blue screen. I restarted my computer everything seems to be working ok but Im not sure, Im totally not in any way shape or form a computer expert. Thinking if this is a virus I should restore my computer to an earlier date... Thing is, its only showing a restore point of 11/27. When I click on the box to show more dates nothing changes. Im clueless as to what to do next???
      My Computer


  5. Posts : 7,730
    Windows 7 Ultimate SP1 64-Bit
       #5

    First, I'd be inclined to uninstall any theme packs you've installed.

    Next, download the free version of Malwarebytes and run a full virus scan.

    Malwarebytes : Malwarebytes Anti-Malware PRO removes malware including viruses, spyware, worms and trojans, plus it protects your computer
      My Computer


  6. Posts : 104
    Windows 10 Build 9926
       #6

    Probably it's infected or like others already said here maybe the theme pack you've installed.
      My Computer


  7. Posts : 16
    Windows 7 Home x64
    Thread Starter
       #7

    Thank you seavixen32. I will do that and report back. In the meantime I was directed to the BSOD forum and followed those instructions there and was advised to post my reports of the BSOD dump & system files collection along with the system health reports in a zip file here.

    OS Name Microsoft Windows 7 Home Premium
    Version 6.1.7601 Service Pack 1 Build 7601
    Other OS Description Not Available
    OS Manufacturer Microsoft Corporation
    System Manufacturer Hewlett-Packard
    System Model 310-1124f
    System Type x64-based PC
    Processor AMD Athlon(tm) II X2 240e Processor, 2800 Mhz, 2 Core(s), 2 Logical Processor(s)
    BIOS Version/Date American Megatrends Inc. 6.03, 11/30/2010
    SMBIOS Version 2.6
    Installed Physical Memory (RAM) 4.00 GB
    Total Physical Memory 3.75 GB
    Available Physical Memory 1.70 GB
    Total Virtual Memory 7.50 GB
    Available Virtual Memory 5.07 GB

    Reports.zip
      My Computer


  8. Posts : 16
    Windows 7 Home x64
    Thread Starter
       #8

    I ran the full Malwarebytes scan and received this msg...

    Broken.OpenCommant | Registry Data | HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default)...
    " " HKEY_CLASSES_ROOT\regfile\shell\open\command\(default)...

    -Was this just a glitch or something else or am I being too paranoid?!?!
      My Computer


  9. Posts : 94
    Windows 7 Ultimate x64
       #9

    Kaaz said:
    I ran the full Malwarebytes scan and received this msg...

    Broken.OpenCommant | Registry Data | HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default)...
    " " HKEY_CLASSES_ROOT\regfile\shell\open\command\(default)...

    -Was this just a glitch or something else or am I being too paranoid?!?!
    I am no Malwarebytesbytes expert but i can tell you this, no one program is 100% accurate at scanning threats, restricting yourself to scanning using one program is dangerous
    If i were you i would use Malwarebytes, Avira removal tool, and Kaspersky Virus Removal Tool.

    Use those and post the results

    Finally there is nothing wrong with being nit picky and paranoid about your system when it comes to protection

    I hope this helps
      My Computer


  10. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #10

    Download CKScanner from here http://downloads.malwareremoval.com/CKScanner.exe
    Save it to your desktop. <=== IMPORTANT
    Doubleclick CKScanner.exe and click Search For Files.
    After a very short time, when the cursor hourglass disappears, click Save List To File.
    A message box will verify that the file is saved.
    Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:30.
Find Us