Question Possible malware in fake explorer.exe file

trix017

Distinguished
Sep 17, 2011
11
0
18,510
When I boot my PC and open Task Manager a second explorer.exe shows up after about 1 minute. When I open file location from the Task Manager, it goes win C:/Windows, but when I run Glary Utilities, it shows up in my Startup Manager Scheduled Tasks (which it didn't before), and when I open the file location through Glary, the location is: C:\Users\****\AppData\Roaming\Microsoft . It is a hidden file, and from explorer properties and the file properties (which I can only access through Glary as it's hidden), both have hidden greyed so I am unable to show the file in that manner.

I've run multiple scans from Bitdefender/Malwarebytes/Windows Security, but none of them have given alerts.

I'm not 100% sure it's a virus, but everything I can find concerning this issue suggests that it is. Also, it turns off my sleep function until I end the function in Task Manager, which is super shady. I've turned off startup access in Glary and removed all permissions in the properties, but I'm stumped on how to remove or quarantine it permanently. Any advice would be appreciated.

Windows 10 Pro Version 21H2 (OS Build 19044.1766)
 
Last edited:

Ralston18

Titan
Moderator
Check in Task Manager > Startup and also Task Scheduler.

Look for anything that may be launching/triggering a second explorer.exe after about 1 minute.

Or anything else being triggered at or around the one minute mark. Remember that malware "lies".

No rush per se. Take your time exploring and otherwise looking through Task Manager/Startup and Task Scheduler.

Look for something that you do not expect or otherwise recognize. Then we go from there.....
 

trix017

Distinguished
Sep 17, 2011
11
0
18,510
Check in Task Manager > Startup and also Task Scheduler.

Look for anything that may be launching/triggering a second explorer.exe after about 1 minute.

Or anything else being triggered at or around the one minute mark. Remember that malware "lies".

No rush per se. Take your time exploring and otherwise looking through Task Manager/Startup and Task Scheduler.

Look for something that you do not expect or otherwise recognize. Then we go from there.....

Nothing unusual shows up in Startup, but Task Scheduler Library shows an "explorer" process that attempts to run every login. The process is disabled, I assume from when I disabled it in Glary. Properties of explorer in Task Scheduler shows the same location as Glary at: C:\Users\****\AppData\Roaming\Microsoft\explorer.exe. Nothing else looked unusual in the Task Scheduler Library.
 

trix017

Distinguished
Sep 17, 2011
11
0
18,510
Update for anyone that sees this and has the same(I assume) malware: I was able to fix the hidden file problem by locating it using Locate32, then deleting it in Locate32 by right-clicking and using Lock Hunter.