PDA

View Full Version : Explore.exe is calling out


Geronimo
11-07-04, 05:02 PM
At startu I invariably get a warning from my software firewall that explorer.exe wants to access the net. I am worried that I have some malware I have not been able to detect.. Any suggestions on finding it. I tried the big 3 pieces of spyware detection.

SimpleSimon
11-07-04, 10:41 PM
Is it explore.exe or explorer.exe - IIRC, explore.exe is a problem.

If you've got a live LAN connection (Ethernet, WiFi), explorer.exe on startup is probably just trying to establish it's neighborhood.

djlong
11-08-04, 09:11 AM
I used to get that until I upgraded my firewall software. Now it recognizes that startup symptom as normal and not an attempted attack.

Redster
11-08-04, 09:44 AM
Process name: Windows Explorer

Product: Windows

Company: Microsoft

File: explorer.exe

Security Rating:
This is the user shell, which we see as the familiar taskbar, desktop, and so on. This process isn't as vital to the running of Windows as you might expect, and can be stopped (and restarted) from Task Manager, usually with no negative side effects on the system.

Note: The explorer.exe file is located in the c:\windows\System32 folder. In other cases, explorer.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager.

A quick summation. If you have explorer.exe in any other folder other than system32. Get rid of it.

Geronimo
11-08-04, 10:13 AM
So why has the message never appeared before?

Redster
11-08-04, 10:58 AM
Well if you have the exe somewhere other than system32 folder, it could be a bug trying to connect. Did you get an upgrade to the firewall ? I know when I upgrade ZAP , it will prompt me even if the program was allowed before. ZAP goes by version as well as name,, any changes and it wants you to reauthorize.

Geronimo
11-08-04, 02:46 PM
I am hesitant here as I wonder if a piece of malware is not trying to use explorer to access the net.

Redster
11-08-04, 03:15 PM
well,, I suggest you do a search and see if you have more than one copy of the file. Does your firewall give you the pathname to the file ? If it is the one in system 32 folder, I wouldnt worry about it. Your desktop wouldnt be running if it had been corrupted or hijacked. As far as malware calling it,, normally the firewall would show which program started the process. Can you enable it temporarily ? Bring up the task manager and watch it,, see if any programs with jumbled letters and numbers starts to suck up all your resources.