VersionsVersions

6.3.9600.17031 (winblue_gdr.140221-1952) 2.49%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.71%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.01%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.84%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.01%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.06%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.21%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.01%
6.2.9200.16384 (win8_rtm.120725-1247) 3.24%
6.2.9200.16384 (win8_rtm.120725-1247) 0.15%
6.2.9200.16384 (win8_rtm.120725-1247) 0.60%
6.2.9200.16384 (win8_rtm.120725-1247) 0.88%
6.2.9200.16384 (win8_rtm.120725-1247) 9.34%
6.2.9200.16384 (win8_rtm.120725-1247) 0.95%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.05%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.01%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 0.63%
6.1.7600.16385 (win7_rtm.090713-1255) 1.61%
6.1.7600.16385 (win7_rtm.090713-1255) 35.93%
6.1.7600.16385 (win7_rtm.090713-1255) 1.71%
6.1.7600.16385 (win7_rtm.090713-1255) 2.07%
6.1.7600.16385 (win7_rtm.090713-1255) 3.26%
6.1.7600.16385 (win7_rtm.090713-1255) 10.12%
6.1.7600.16385 (win7_rtm.090713-1255) 1.74%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.56%
6.1.7600.16385 (win7_rtm.090713-1255) 0.05%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.87%
6.1.7600.16385 (win7_rtm.090713-1255) 0.06%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
6.1.7600.16385 (win7_rtm.090713-1255) 0.01%
View more

Relationships

explorer.exe

Windows Explorer by Microsoft Corporation (Signed)

Remove explorer.exe
This is a Windows system installed file with Windows File Protection (WFP) enabled.
Warning 19 antivirus scanners has detected malware in various versions of explorer.exe.

Overview

explorer.exe has 113 known versions, the most recent one is 6.3.9600.17031 (winblue_gdr.140221-1952). explorer.exe is run as a standard windows process with the logged in user's account privileges. It also provides a graphical interface (GUI) for the user to interact with it and contains an icon in the Windows notifictaion system tray (near the clock). During installation the program adds a job to the Task Scheduler that will runs on registration. The average file size is about 1.89 MB. It is an authenticode code-signed executable issued to Microsoft Corporation by the certification authority Microsoft Corporation. Numerous variations of explorer.exe have been installed with both Windows XP (Theme) and Java 7 Update 60. During the process's lifecycle, the typical CPU resource utilization is about 0.0056% including both foreground and background operations, the average private memory consumption is about 60.18 MB with the maximum memory reaching around 107.79 MB. Addionally, typically read and write I/O disk operations is about 519.9 KB per minute for reads and 356.27 KB per minute for writes.

What is explorer.exe?

Windows Explorer also known as File Explorer, is a file manager application and also a navigation tool that is included with releases of the Microsoft Windows operating system. It provides a graphical user interface for accessing the file systems. It is also the component of the operating system that presents many user interface items on the monitor such as the taskbar and desktop. Located in the C:\Windows directory, it is sometimes referred to as the Windows shell, explorer.exe.

DetailsDetails

File name:explorer.exe
Publisher:Microsoft Corporation
Product name:Windows Explorer
Description:Microsoft® Windows® Operating System
Typical file path:C:\windows\explorer.exe
Original name:EXPLORER.EXE.MUI
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Tuesday, July 9, 2013

ResourcesPrograms installed in

(Note, the programs listed below are for all versions of Windows Explorer.)
Mohammad Reza Tavakoli
1% remove

BehaviorsBehaviors

(Note, the behaviors below are for all versions of explorer.exe, select a unique version for details.)
Shell open commands
  • SHCmdFile
Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
  • Handler name 'MSOpenFolderBackup'
  • Handler name 'MSOpenFolder'
Scheduled tasks
  • The task '{AD36F1D3-E56E-44BA-A569-280718EB8C51}' runs on registration in the path '\{AD36F1D3-E56E-44BA-A569-280718EB8C51}'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 19 of them detected the following malware.
Antivirus engineEngine versionDetectionFile version
AegisLab 1.5 W32.Virut 6.00.2900.5634 (xpsp_sp3_qfe.080703-1303)
AVG 2014.0.3629 Startpage.RYH 6.1.7600.16385 (win7_rtm.090713-1255)
Clam AntiVirus 0.97.3 Win.Trojan.Bamital-466 6.00.2900.5634 (xpsp_sp3_qfe.080703-1303)
Clam AntiVirus 0.97.3.0 Win.Trojan.Bamital-211 6.00.2900.5634 (xpsp_sp3_qfe.080703-1303)
Ikarus T3.1.4.0.0 Trojan.Win32.StartPage 6.1.7600.16385 (win7_rtm.090713-1255)
McAfee 5.400.1158 Artemis!BD03715E11F4 6.00.2900.5512 (xpsp.080413-2105)
McAfee Gateway Anti-Malware v2012.1-dat Heuristic.BehavesLike.Win32.Suspicious-BAY.K 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
McAfee Gateway Anti-Malware v2012.1-dat Artemis!BD03715E11F4 6.00.2900.5512 (xpsp.080413-2105)
McAfee Gateway Anti-Malware v2013-dat Heuristic.BehavesLike.Win32.Suspicious-BAY.K 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
McAfee Gateway Anti-Malware v2013-dat Heuristic.BehavesLike.Win32.Suspicious-BAY.K 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
nProtect 2012-11-07.02 Trojan/W32.Agent.1589248.I 6.00.2900.5512 (xpsp.080413-2105)
SUPERAntiSpyware 5.6.0.1008 Trojan.Agent/Gen-Dynamer 6.00.2900.5512 (xpsp.080413-2105)
The Hacker 6.7.0.1.393 Trojan/Patched.cx 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)
The Hacker None Backdoor/Popwin.cnr 6.00.2900.3244 (xpsp.071030-1535)
The Hacker None Backdoor/Popwin.cnr 6.00.2900.3300 (xpsp.080125-2028)
The Hacker None Backdoor/Popwin.cnr 6.00.2900.3311 (xpsp.080212-0004)
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V1001 6.00.2900.5512 (xpsp.080413-2105)
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V0824 6.00.2900.3244 (xpsp.071030-1535)
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V1016 6.00.2900.3300 (xpsp.080125-2028)

VersionsAll file variations of explorer.exe

MD5SHA-1File size
81394c91b7b5a7c799e249ae82491f13 566d18d628ed2122c3ecb5eb70b5ff4a367c58a1 2.26 MB
c1400519d76a364e974e47bba62b95b0 0c8de34d4d7b4d9fa2a9fad2e0ece95595fb5978 2.22 MB
712b0d2ade5297563168c997ddc2dd13 f2dffe7ab1502c2366b646cf1b21656cfe26f8c1 1.97 MB
63dc38c3e4564b2405d562855643aba2 cdf235fa4a238d5f82cfe7e0dc47af97ed562543 2.22 MB
1a0bc9598e4a58fc84570fff5a108e58 c00e4f306475798dd20f31eea5fa2ff962375f02 1.97 MB
8479dc46e9a09015c0777a16bc22a15d 69a663e65333f5f2b5f4f66e2bd33c61d008a2e6 2.22 MB
2cf1204e913aea5a492d89c153f3345e ef3937461e715b4d5a886c7ccb43b8e8b40eb738 2.15 MB
253252bbc9e61728986cb54261f8aecd f1e6acff5f10397182c1ef922fe1403ab8175834 1.92 MB
0e8e6463f81c80afbed533e0f1f8895d eda500ac5c5134f32f1db3a248fcf3009b536867 2.28 MB
eafe46b0292d2bd2467835e2acf717cc 9033be345aded283e0590aac5cb9f6f472ece96a 2.01 MB
5b6ed1b57dbff18d405a0260559b571e 2c0515f1f77d4a0c9fbb66ebbaa465743f39589a 2.02 MB
928791755fddea721b053535ef84fa17 7e51e93497b2bcfe3d1160f615353e1e83312496 2.27 MB
e13a31d5254c25406a7946bdd9b06364 b3a772021b7af2e59a075dfe9f23dbde0d54554c 2.27 MB
953adecff08202a01efc6110214fde02 5053623c90936b194173350c831f5e7a8968f755 2.02 MB
acf8d985d07999daa575ae64e9768a96 5766babcb44bec1540a9e6269fb1fec1aa2b0f52 2.28 MB
9cf221011009e82742cde1ba4ae94f5c 94577a086c3928fbed18f370910384911123cd3f 2.01 MB
e3b79a4bc5823337d81682703aafe714 2f6e8b95bfc62210c01a8b75d6a14be340c064bb 1.98 MB
5bf26a2d94232cd98db92cfbe07e5470 18b4db307f2d0cac339690a5946877f66b0b954b 2.77 MB
2626fc9755be22f805d3cfa0ce3ee727 d76db4dcd710be9c3314cff94824933847565372 2.49 MB
15bc38a7492befe831966adb477cf76f ea97227d34b8526055a543ade7d18587a927f6a3 2.49 MB
332feab1435662fc6c672e25beb37be3 5a49d7390ee87519b9d69d3e4aa66ca066cc8255 2.74 MB
2af58d15edc06ec6fdacce1f19482bbf e2f906421e49c72e10d9589c39ebf69d02e84583 2.49 MB
ac4c51eb24aa95b77f705ab159189e24 4583daf9442880204730fb2c8a060430640494b1 2.74 MB
40d777b7a95e00593eb1568c68514493 89a175a12bc20104770d0ef83e553f8b0e06274b 2.5 MB
8b88ebbb05a0e56b7dcc708498c02b3e cea0890d4b99bae3f635a16dae71f69d137027b9 2.5 MB
0862495e0c825893db75ef44faea8e93 e4b9a40fa341bcb82f20c9c3cefad84825e0d194 2.74 MB
8c3c7739403fc50ae3ec5f08c0ef6641 c6465ed9ab6a0ec435e64868c3a444f8e49aca67 2.91 MB
f585c8f79573cd4494e3744e2acd8938 0d3cf52575b6cf76f66666e72805e6ba6d6028a8 2.27 MB
9aaaec8dac27aa17b053e6352ad233ae 0f841176602288ee1be832573265f88ca78f4ba7 2.74 MB
b95eeb0f4e5efbf1038a35b3351cf047 131d489169c9af3660c79976fb57430a60945147 2.49 MB
ef1d932549140f3bc64bc81ea77b52c5 bd2725db9e69fb6b029a88d74f04f794ec5e9401 2.51 MB
cf7cc537562b8d144b4333361946a769 a2944c7d5de738043f2e41f3e2c753b0d94c0534 2.66 MB
c235a51cb740e45ffa0ebfb9bafcda64 ea23a45adb3d8d61ca478dd90e8d956ba32fa786 2.74 MB
f170b4a061c9e026437b193b4d571799 6bb0f30e4014ada9a01a8fa222fb66150a37c0f4 2.74 MB
d8717966e9ee372b3c2c02c1e00ed2ca bdc9ef726965a5cbba32034ab072159e20667b1f 2.77 MB
50d8b06d18650ee2478bee1692485283 a941dddc13fd2b74a141225031372dcb89465356 2.66 MB
9cba315758a3482f1c5fdc706cd06a46 b90f2a21990654143f18411318abb7bed598d247 2.73 MB
2c7cceb95c10cc4b11976e1d360d94aa e76cbb42990304ba6bdd788d8226ea04e9b9e0e8 2.9 MB
5f93e68f3ccd66ae4ba2e4cc60d3d29d b8996f0d56a6fa50ad9360022391516929ec5067 2.49 MB
6ef4d18ad2a63b2070da79140d163576 cd3563bf73b448885a31e6e9988d3929c46d3ee3 3.33 MB
1ffba7a43eb296626bb5c6af8f070006 429d7882867123e0bad7b688f8704cd3346e1e59 2.74 MB
a7d923bf64c5af89758c38f2b60c525a 9c84bd2d4badd8e011c4bac4becb099905485ef6 2.52 MB
5f19db69aa7490782046e132f2be1015 82d009386f054c596bc78f7b2d5120b99aa9abee 2.95 MB
374d3d15f98ee97804929c5335857c93 7e7949d9875c6a9884a45cfc8c19de5b50e54af8 2.97 MB
1181744907cce66df2fda4bccea0948c 5bacbc5b5465d58e3a34e8ab9bc98bc7faad1c66 3.9 MB
df8244a927975eaf2205c800665dbbb9 b6bf5234f52b6047784d172839c92fa3be25d264 2.91 MB
fc89faca0473641cb625eda9277d0885 8bf2f58e2fc0d98f33984def02c39ff9f683d90b 2.49 MB
b068f76bf4494e04efc1de343de58a06 ef897bdbf4fcdd19689bfd41b92c32cd53bf9f63 2.34 MB
1fed9a78e5c4ebd480af370947719891 5c2034bf89fdccd6c818f24deb116b94e18dde5d 2.74 MB
5e959b5e9451a39f1630ec5c418b9eef 298e0ea52d48c7b68a6bf68a86d0dd8bf88d11c7 2.71 MB
0fb9c74046656d1579a64660ad67b746 0b802d169757431bb61ce1129ee12b2cc8f90998 2.5 MB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 36.00%
Windows 8.1 16.25%
Windows 7 Ultimate 10.75%
Windows 8.1 Pro 10.25%
Windows 7 Professional 8.25%
Windows 8 4.25%
Windows 8.1 Single Language 4.00%
Windows 8 Single Language 2.25%
Windows 8.1 Pro with Media Center 2.00%
Windows 8.1 N 2.00%
Windows 7 Home Basic 1.00%
Windows 8.1 Enterprise Evaluation 1.00%
Windows 8 Pro 1.00%
Windows Vista Home Premium 1.00%

Distribution by countryDistribution by country

United States installs about 56.75% of Windows Explorer.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 26.39%
Hewlett-Packard 18.36%
ASUS 16.83%
Toshiba 12.24%
Acer 10.13%
Lenovo 7.65%
Sony 3.06%
Alienware 2.29%
Samsung 2.29%
GIGABYTE 0.76%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE