Two Explorer.exe running

Page 1 of 3 123 LastLast

  1. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
       #1

    Two Explorer.exe running


    Hi, I'm kinda confused now. Here's the story.
    Yesterday, MBAM detected a infection named- Heuristics.Reserved.Word.Exploit. The file which was flagged was- C: \Windows\Installer\Explorer.exe
    It always came back after reboot. Upon googling, i found that the threat name refers to the usage of microsoft reserved name outside it's default location.
    So, I booted in safe mode, terminated Explorer.exe (original one), and deleted that duplicate Explorer.exe via cmd (it wont unless i terminate original explorer process).
    Everything is fine now. There's one thing about which i'm concerned.
    I've two Explorer.exe running sometimes, not often. Attached is the screen below.
    Both are running from original default location.
    Any ideas why 2 explorer.exe are running?



    PS: Command line also included in the pic. Maybe if that could reveal something. And I don't have 'Launch folder windows in a separate process' checked. One more thing worth noting that the original explorer.exe and duplicate explorer.exe have same creation date and checksums.
    Attached Thumbnails Attached Thumbnails Two Explorer.exe running-explorer.png  
      My Computer


  2. Posts : 1,426
    7 Pro
       #2

    pid 956 looks like an infection to me... are you sure the machine is clean?
      My Computer


  3. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
    Thread Starter
       #3

    Whoa! That was lightning fast reply.

    Ive done full scan with MBAM and KIS 2011. Machine came up clean.
      My Computer


  4. Posts : 1,426
    7 Pro
       #4

    How's your msconfig /startup sheet looking? The explorer.exe /* doesn't usually equal good things.
      My Computer


  5. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #5
      My Computer


  6. Posts : 1,426
    7 Pro
       #6

    ahh nvm... disregard... the 2nd is a 32bit explorer
      My Computer


  7. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
    Thread Starter
       #7

    Msconfig looks ok. I made another snip now. And both processes seems to change their pid's everytime when they're run. See the pic. Ending explorer.exe/* doesn't closes my desktop.

    @Jacee, thanks. Going to run that after this post.
    Attached Thumbnails Attached Thumbnails Two Explorer.exe running-capture.jpg  
      My Computer


  8. Posts : 1,426
    7 Pro
       #8

    the 2 explorers are bit defined. 1 for 64bit and 1 for 32bit processes
      My Computer


  9. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
    Thread Starter
       #9

    Jacee said:
    Jacee, you want me to generate and attach the report here?
      My Computer


  10. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
    Thread Starter
       #10

    brady said:
    the 2 explorers are bit defined. 1 for 64bit and 1 for 32bit processes
    How? It doesn't say explorer*32 in task manager? And what program would need their own separate explorer.exe?
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 00:31.
Find Us