Explorer.exe showing as malware

xxxdannyxxx

Do You Believe
Guru
Gold Member
VIP
Local time
6:11 AM
Messages
2,615
Location
England
Hi All

Ive just run a scan with Hitman Pro and its flagged explorer.exe as Malware.MSE and Malwarebytes scans come back clear.Is this just an FP or do i have a problem.
Any help appreciated.

Danny
 
Last edited:

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up
I would call that a "false positive".
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up
Especially since it shows in C:>Windows, which is the correct location.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Especially since it shows in C:>Windows, which is the correct location.

Thanks whs always appreciate a second opinion

Danny
 

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up

My Computer

Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
I do have custom icons and a custom orb but havent applied any custom themes.
 

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up
I just thought that if you had, maybe the AV had picked up on the altered explorer.exe signature because of the theme changes. I mean, there are people on here who hack many system's .exe and .dll files to make themselves custom Window's theme, so I had to ask if you were one of then. But I guess not, so it's just a normal FP :)

I do have custom icons and a custom orb but havent applied any custom themes.
 

My Computer

Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
I just thought that if you had, maybe the AV had picked up on the altered explorer.exe signature because of the theme changes. I mean, there are people on here who hack many system's .exe and .dll files to make themselves custom Window's theme, so I had to ask if you were one of then. But I guess not, so it's just a normal FP :)

I do have custom icons and a custom orb but havent applied any custom themes.

Actually Lost Colonist your on to something i restored the explorer.exe back-up file that windows 7 start button changer creates and ran it again and no problems, used it again to apply a custom orb and the problems back.
Any Views on this

Danny
 

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up
Every file has a default signature and MD5 hash etc, maybe whatever is in this hitmanpro checks these signatures / hashes. In this case it would have noticed an altered signature/hash and flagged it as infected.

I just thought that if you had, maybe the AV had picked up on the altered explorer.exe signature because of the theme changes. I mean, there are people on here who hack many system's .exe and .dll files to make themselves custom Window's theme, so I had to ask if you were one of then. But I guess not, so it's just a normal FP :)

I do have custom icons and a custom orb but havent applied any custom themes.

Actually Lost Colonist your on to something i restored the explorer.exe back-up file that windows 7 start button changer creates and ran it again and no problems, used it again to apply a custom orb and the problems back.
Any Views on this

Danny
 

My Computer

Computer Manufacturer/Model Number
HP DV6 1330sa
OS
Windows 7 Professional 64 Bit SP1
CPU
INTEL DUAL CORE 2.1Ghz
Motherboard
N/A
Memory
4GB DDR3
Graphics Card(s)
INTEL
Sound Card
LAPTOP
Monitor(s) Displays
2
Screen Resolution
3200x1080
Hard Drives
250GB
PSU
LAPTOP
Case
LAPTOP
Cooling
LAPTOP
Keyboard
SOLID YEAR 260U
Mouse
USB
Internet Speed
20 MB/S
Thats great will mark it as FP and that should be the end of it.

Thanks for the help

Danny
 

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up
You changed the start orb and so as the contents of the original file and so the detection.
My AV too pops up about this. But its no big deal as long as it is at %windir%\explorer.exe and %windir%\SysWOW64\explorer.exe (on x64 machines) and has the same checksums (MD5, SHA-1 etc.) as of the original.
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
You changed the start orb and so as the contents of the original file and so the detection.
My AV too pops up about this. But its no big deal as long as it is at %windir%\explorer.exe and %windir%\SysWOW64\explorer.exe (on x64 machines) and has the same checksums (MD5, SHA-1 etc.) as of the original.

Thanks for this .Which av are you using just out of interest

Danny
 

My Computer

Computer Manufacturer/Model Number
acer aspire 5935g
OS
Windows 7 Home Premium x64 SP1
CPU
intel(R)core(TM)2 duo CPU T6600 @ 2.20GHz
Motherboard
intel gm45/gm47 revision 07
Memory
3 gb ddr3
Graphics Card(s)
ati radeon hd4570/512mb
Monitor(s) Displays
lop156wh2-tle1 15.3 flat
Screen Resolution
1366x768
Hard Drives
OCZ-Agility3 60gig ssd
320gig external hdd
500gig external hdd
Mouse
Optical
Internet Speed
30Mbps Down/30Mbps Up
Kis 2011
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
Back
Top