Two Explorer.exe running

EzioAuditore

Assassin
Guru
Local time
12:22 PM
Messages
1,036
Hi, I'm kinda confused now. Here's the story.
Yesterday, MBAM detected a infection named- Heuristics.Reserved.Word.Exploit. The file which was flagged was- C: \Windows\Installer\Explorer.exe
It always came back after reboot. Upon googling, i found that the threat name refers to the usage of microsoft reserved name outside it's default location.
So, I booted in safe mode, terminated Explorer.exe (original one), and deleted that duplicate Explorer.exe via cmd (it wont unless i terminate original explorer process).
Everything is fine now. There's one thing about which i'm concerned.
I've two Explorer.exe running sometimes, not often. Attached is the screen below.
Both are running from original default location.
Any ideas why 2 explorer.exe are running?



PS: Command line also included in the pic. Maybe if that could reveal something. And I don't have 'Launch folder windows in a separate process' checked. One more thing worth noting that the original explorer.exe and duplicate explorer.exe have same creation date and checksums.
 

Attachments

  • explorer.png
    explorer.png
    32.2 KB · Views: 340

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
pid 956 looks like an infection to me... are you sure the machine is clean?
 

My Computer

OS
7 Pro
Whoa! That was lightning fast reply.

Ive done full scan with MBAM and KIS 2011. Machine came up clean.
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
How's your msconfig /startup sheet looking? The explorer.exe /* doesn't usually equal good things.
 

My Computer

OS
7 Pro

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Msconfig looks ok. I made another snip now. And both processes seems to change their pid's everytime when they're run. See the pic. Ending explorer.exe/* doesn't closes my desktop.

@Jacee, thanks. Going to run that after this post.
 

Attachments

  • Capture.JPG
    Capture.JPG
    12.7 KB · Views: 77

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
the 2 explorers are bit defined. 1 for 64bit and 1 for 32bit processes
 

My Computer

OS
7 Pro

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
the 2 explorers are bit defined. 1 for 64bit and 1 for 32bit processes

How? It doesn't say explorer*32 in task manager? And what program would need their own separate explorer.exe?
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
not 100% sure but my main 32bit system runs 1 explorer.exe and my secure 64bit machine always lists 2 (and it's verified clean)
 

My Computer

OS
7 Pro
As far as the cleanliness of other duplicate explorer.exe is concerned, i uploaded it to virustotal and it came clean. :huh:
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
So, should i assume that it's normal for x64 windows to run 2 Explorer.exe simultaneously? And what about the string in the command line of another explorer.exe with the -embedding switch? What does that mean? And why it's pid changes with it's each instance?
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Ok, will check that out tomorrow. It's already quarter past 2 morning here...
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
What they've said is correct. If you kill the 64 bit version (one with the /factory switch) and then run this command here:

%windir%\syswow64\explorer.exe /separate

You will see the same thing, the factory switch and the GUID. Doesn't appear to be a virus.
 

My Computer

OS
Windows 7
CPU
Quad Core
Memory
8GB
Hard Drives
1TB
@Dranfu
Oh thanks. That cleared 75% of my confusion. Just few questions which are still concerning me..
1. What could have create a duplicate explorer.exe in c:\windows\installer folder?
2. When i already have one explorer.exe running, why does the another 64bit explorer kicks in for no reason?
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
@Dranfu
Oh thanks. That cleared 75% of my confusion. Just few questions which are still concerning me..
1. What could have create a duplicate explorer.exe in c:\windows\installer folder?
2. When i already have one explorer.exe running, why does the another 64bit explorer kicks in for no reason?

Concerning the first point, explorer.exe should normally be located in C:\Windows\explorer.exe, your own screenshot confirms this. Therefore, whatever created explorer.exe in c:\windows\installer was likely not legitimate.

Concerning the second point, IDK. It may be a bug. See here: Has the implementation of the 32-bit Windows Explorer changed in the RC?
 

My Computer

OS
Windows 7
CPU
Quad Core
Memory
8GB
Hard Drives
1TB
Back
Top