- Local time
- 12:22 PM
- Messages
- 1,036
Hi, I'm kinda confused now. Here's the story.
Yesterday, MBAM detected a infection named- Heuristics.Reserved.Word.Exploit. The file which was flagged was- C: \Windows\Installer\Explorer.exe
It always came back after reboot. Upon googling, i found that the threat name refers to the usage of microsoft reserved name outside it's default location.
So, I booted in safe mode, terminated Explorer.exe (original one), and deleted that duplicate Explorer.exe via cmd (it wont unless i terminate original explorer process).
Everything is fine now. There's one thing about which i'm concerned.
I've two Explorer.exe running sometimes, not often. Attached is the screen below.
Both are running from original default location.
Any ideas why 2 explorer.exe are running?
PS: Command line also included in the pic. Maybe if that could reveal something. And I don't have 'Launch folder windows in a separate process' checked. One more thing worth noting that the original explorer.exe and duplicate explorer.exe have same creation date and checksums.
Yesterday, MBAM detected a infection named- Heuristics.Reserved.Word.Exploit. The file which was flagged was- C: \Windows\Installer\Explorer.exe
It always came back after reboot. Upon googling, i found that the threat name refers to the usage of microsoft reserved name outside it's default location.
So, I booted in safe mode, terminated Explorer.exe (original one), and deleted that duplicate Explorer.exe via cmd (it wont unless i terminate original explorer process).
Everything is fine now. There's one thing about which i'm concerned.
I've two Explorer.exe running sometimes, not often. Attached is the screen below.
Both are running from original default location.
Any ideas why 2 explorer.exe are running?
PS: Command line also included in the pic. Maybe if that could reveal something. And I don't have 'Launch folder windows in a separate process' checked. One more thing worth noting that the original explorer.exe and duplicate explorer.exe have same creation date and checksums.
Attachments
My Computer
- Computer Manufacturer/Model Number
- HCL
- OS
- Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
- CPU
- Core 2 Duo e7400 @ 2.90GHz
- Motherboard
- Gigabyte G31M-ES2L
- Memory
- 3GB DDR2
- Graphics Card(s)
- Asus Nvidia GTX 560Ti 1GB
- Sound Card
- On-board
- Monitor(s) Displays
- HCL eZeeBee 18.5" LCD
- Screen Resolution
- 1366x768 @ 60Hz
- Hard Drives
- Western Digital 320GB
- PSU
- Corsair CX500 V2 500W
- Cooling
- Stock
- Keyboard
- Stock
- Mouse
- Stock
- Internet Speed
- 15-25kBps D/L | 10kBps U/L | Hey Don't laugh
