Windows file
explorer.exe (Windows Explorer): genuine Windows shell, or malware using its name?
explorer.exe is Windows Explorer, the program that draws the desktop, taskbar, Start menu and File Explorer windows. The copy in C:\Windows is safe and needed. A copy in any other folder is not, and malware also injects code into the genuine process.
Prefer to check it yourself? The manual checks follow.
explorer.exe in C:\Windows, signed by Microsoft, is safe. Do not delete it. If the desktop or taskbar freezes, restart it from Task Manager instead.
Its name is copied by malware, and the genuine process can have code injected into it, so the name proves nothing. Check the folder and the signature. Malware arrives through bundled free software, spam attachments and links, web injects and exploits, so install programs only from the publisher's own site.
- Task Manager name
- Windows Explorer (explorer.exe)
- Description in the file
- Windows Explorer
- Folders Windows installs it to
- C:\Windows\explorer.exe; C:\Windows\System32\explorer.exe; C:\Windows\SysWOW64\explorer.exe
- Signed by
- Microsoft (the Microsoft builds known to Winbindex are signed)
- Known Microsoft builds
- 794
- Windows releases
- Windows 10 1507 to Windows 11 26H1; the old page says it has existed since Windows 95
- Several copies
- Can be normal when folder windows are set to open in a separate process; otherwise check each one
What Windows Explorer does
explorer.exe is the graphical shell of Windows. It shows the desktop, the taskbar, the Start menu and the File Explorer windows in which you open, copy, cut and delete files on the PC and on connected drives and networks.
The genuine file is part of the operating system and arrives with it. Windows runs without a working shell only with difficulty, so its faults are felt at once: a frozen desktop, icons that do not respond, a Start menu that will not open.
Task Manager lists it under Windows processes as Windows Explorer. It is a different program from Internet Explorer, which was retired on 15 June 2022; a file or process with "Explorer" in its name is not necessarily this one.
About .exe files. An .exe file is a program. It runs as a process you can see in Task Manager, so its name, folder and publisher are what to check.
How to check an explorer.exe
Three checks need nothing installed.
- Where the file is. In Task Manager open the Details tab, right-click explorer.exe and choose Open file location. The shell runs from C:\Windows. A copy in a user folder, AppData, Temp or ProgramData is not Windows.
- Who signed it. Right-click the file, open Properties, then Digital Signatures. The signer must be Microsoft Windows and the signature valid. The command prints the path and signature status of every running copy:
Get-Process explorer | Select-Object Id, Path | ForEach-Object { $_; Get-AuthenticodeSignature $_.Path | Select-Object Status, @{n="Signer";e={$_.SignerCertificate.Subject}} } - How many copies and who started them. Several running copies can be normal, but each should be in C:\Windows and signed. Parent and command line of every copy:
Get-CimInstance Win32_Process -Filter "Name='explorer.exe'" | Select-Object ProcessId, ParentProcessId, ExecutablePath, CommandLine | Format-List - Compare the file with Microsoft's builds. Use the checker on this page: it computes the SHA-256 in your browser and compares it with the known Microsoft builds.
These checks show whether the file is the Windows one. They cannot show that code was injected into a running genuine explorer.exe, which is a documented technique. For that run Microsoft Defender's full scan and, if the signs below apply or the malware blocks your security tools, restart in Safe Mode with Networking and scan there, then run the offline scan.
Check your explorer.exe
Choose the explorer.exe you are unsure about. Its SHA-256 checksum is calculated in your browser and compared with the 794 Microsoft builds indexed from Windows releases and updates.
The file stays on your computer. Nothing is uploaded: the checksum is computed locally.
Warning signs and what they mean
| What you see | What it means |
|---|---|
| explorer.exe outside C:\Windows (AppData, Temp, ProgramData, a user folder) | Not the Windows shell. A program is borrowing the name. |
| Signature missing, invalid or not Microsoft's | The file was replaced, or it is not from Microsoft. The old page also lists copies belonging to Intel, Spark, Apple, Avast or BitTorrent software, which are different programs. |
| Several copies, some outside C:\Windows or unsigned | Extra copies in the right folder can be a folder-window setting. Copies elsewhere are not Windows. |
| New startup entries, scheduled tasks or changed registry keys you did not make | How a fake explorer.exe or its payload starts at every boot, according to the old page; check Task Scheduler and Settings > Apps > Startup. |
| Slow PC, more browser ads and crashing programs together with the signs above | Effects the old page linked to a computer taken over through the name; not proof by itself. |
| Crashes or a frozen desktop with a genuine, signed file in C:\Windows | Usually a Windows fault or a faulty add-on, not malware. Restart the process first. |
Documented abuse of explorer.exe
From MITRE ATT&CK, the public catalogue of attacker techniques. Each row quotes what the entry records and links to it. Two patterns appear: malware named explorer.exe, and code injected into the genuine process.
| Malware | How it used the file | Source |
|---|---|---|
| Sandworm Team | Avoided detection by naming a malicious binary explorer.exe. | T1036.005 match legitimate name or location |
| Emotet | Has been observed injecting into explorer.exe and other processes. | T1055.001 DLL injection |
| ComRAT | Injected its orchestrator DLL into explorer.exe. | T1055.001 DLL injection |
| Kazuar | On Windows saves a DLL to disk that is injected into the explorer.exe process to run the payload. | T1055.001 DLL injection |
| BADHATCH | Can run a malicious DLL by injecting into explorer.exe. | T1055.001 DLL injection |
| Smoke Loader | Spawns a new copy of c:\windows\syswow64\explorer.exe and replaces its code in memory with malware. | T1055.012 process hollowing |
| XLoader | Injects itself into the explorer.exe process by process hollowing. | T1055.012 process hollowing |
A named copy fails the folder and signature checks. An injected genuine explorer.exe passes them, so a clean file check does not clear a PC that shows the signs above. The old page named Reoxtan, DlDer, Blockey and Zhong as threats using the name; they are not in the sources linked here.
Everyday problems that are not malware
The desktop or taskbar is frozen, or the Start menu will not open. What now?
A faulty shell can be restarted without restarting Windows. Press Ctrl+Shift+Esc to open Task Manager (on Windows 10, click More details if only a short list shows).
On the Processes tab find Windows Explorer under Windows processes, right-click it and choose Restart. The taskbar disappears for a moment and returns.
When is restarting Windows Explorer useful?
It replaces a full restart after a change to registry entries that affects the shell, or when part of the graphical interface acts up or crashes.
Can the PC run without explorer.exe?
It can be controlled without it, but you lose the desktop, taskbar and File Explorer, and its failures cause serious problems. Third-party shells exist, but ending the process is not a way to fix anything.
Does a crash mean a virus?
Not by itself. Check the file's folder and signature before concluding anything; a genuine, signed file in C:\Windows that crashes is a Windows problem, and deleting it is never the answer.
explorer.exe versions by Windows release
The newest build indexed for each release, and the update that delivered it. 794 Microsoft builds in total are known.
| Windows release | File version | Delivered by | Size, 64-bit |
|---|---|---|---|
| Windows 11 26H1 | 10.0.28000.3086 | KB5124006, Sep 22, 2026 | 3,421,128 bytes |
| Windows 11 25H2 | 10.0.26100.5074 | original release | 3,067,376 bytes |
| Windows 11 24H2 | 10.0.26100.9549 | KB5124010, Sep 22, 2026 | 3,479,480 bytes |
| Windows 11 23H2 | 10.0.22621.7517 | KB5129242, Sep 14, 2026 | 5,625,200 bytes |
| Windows 11 22H2 | 10.0.22621.5983 | KB5066793, Oct 14, 2025 | 5,625,136 bytes |
| Windows 11 21H2 | 10.0.22000.3079 | KB5044280, Oct 8, 2024 | 5,092,064 bytes |
| Windows 10 22H2 | 10.0.19041.6392 | KB5066198, Sep 25, 2025 | 6,089,624 bytes |
| Windows 10 21H2 | 10.0.19041.7725 | KB5129236, Sep 14, 2026 | 6,090,176 bytes |
| Windows 10 21H1 | 10.0.19041.928 | original release | 4,704,752 bytes |
| Windows 10 20H2 | 10.0.19041.2913 | KB5026361, May 9, 2023 | 5,254,336 bytes |
Questions people ask
Is explorer.exe a virus?
No. It is the Windows shell. Malware can use its name or run inside it, so the folder and signature matter more than the name. The genuine file is in C:\Windows and signed by Microsoft. A copy elsewhere or without a Microsoft signature is not Windows.
Should I remove explorer.exe?
No, not the genuine one. Without it you lose the desktop, taskbar and File Explorer, and nothing it does can be replaced easily. Remove only a copy that failed the folder or signature check, with a full Microsoft Defender scan and, if needed, the offline scan.
How do I restart explorer.exe?
Press Ctrl+Shift+Esc, find Windows Explorer under Windows processes, right-click it and choose Restart. This fixes a frozen desktop or taskbar and can replace a full restart after registry changes. If it keeps failing, scan the PC and check the file.
What if the scan finds nothing but the problem stays?
Restart in Safe Mode with Networking and scan again, because some malware tries to disable security tools. Then run the Microsoft Defender offline scan. Depending on the type of malware you may also need to reset your browsers, as some programs read traffic, cookies or screens.
How does a fake explorer.exe get onto a PC?
Through the usual routes: software bundles with free programs, spam emails and attachments, web injects, exploits and infected links on unsafe websites. The genuine file comes with Windows itself and never needs installing, so any installer, download or attachment offering an explorer.exe is a warning sign in itself.
How do I lower the risk of a fake?
Choose Advanced or Custom installation for free software and untick the extras. Do not open mail from unknown senders or its links and attachments, ignore suspicious ads, avoid file-sharing sites and torrent clients, update Windows and software at once, keep Microsoft Defender on and back up your files to external storage.
Do I have to keep explorer.exe?
Yes, if it is the genuine file. Without it navigating files and folders on local and connected drives becomes hard, although third-party interface software exists. Keep it, and check any other copy you find against the folder and signature tests on this page. The checker above also compares the file with the known Microsoft builds.
Sources
- Microsoft Learn: Windows Shell
- MITRE ATT&CK T1036.005: Masquerading, Match Legitimate Resource Name or Location
- MITRE ATT&CK T1055.001: Process Injection, DLL Injection
- MITRE ATT&CK T1055.012: Process Injection, Process Hollowing
- Winbindex, the Windows binaries index (m417z)
Version data read on Oct 5, 2026.
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
…