Windows file

explorer.exe (Windows Explorer): genuine Windows shell, or malware using its name?

explorer.exe is Windows Explorer, the program that draws the desktop, taskbar, Start menu and File Explorer windows. The copy in C:\Windows is safe and needed. A copy in any other folder is not, and malware also injects code into the genuine process.

Prefer to check it yourself? The manual checks follow.

Genuine Windows file

explorer.exe in C:\Windows, signed by Microsoft, is safe. Do not delete it. If the desktop or taskbar freezes, restart it from Task Manager instead.

Its name is copied by malware, and the genuine process can have code injected into it, so the name proves nothing. Check the folder and the signature. Malware arrives through bundled free software, spam attachments and links, web injects and exploits, so install programs only from the publisher's own site.

Task Manager name
Windows Explorer (explorer.exe)
Description in the file
Windows Explorer
Folders Windows installs it to
C:\Windows\explorer.exe; C:\Windows\System32\explorer.exe; C:\Windows\SysWOW64\explorer.exe
Signed by
Microsoft (the Microsoft builds known to Winbindex are signed)
Known Microsoft builds
794
Windows releases
Windows 10 1507 to Windows 11 26H1; the old page says it has existed since Windows 95
Several copies
Can be normal when folder windows are set to open in a separate process; otherwise check each one

What Windows Explorer does

explorer.exe is the graphical shell of Windows. It shows the desktop, the taskbar, the Start menu and the File Explorer windows in which you open, copy, cut and delete files on the PC and on connected drives and networks.

The genuine file is part of the operating system and arrives with it. Windows runs without a working shell only with difficulty, so its faults are felt at once: a frozen desktop, icons that do not respond, a Start menu that will not open.

Task Manager lists it under Windows processes as Windows Explorer. It is a different program from Internet Explorer, which was retired on 15 June 2022; a file or process with "Explorer" in its name is not necessarily this one.

About .exe files. An .exe file is a program. It runs as a process you can see in Task Manager, so its name, folder and publisher are what to check.

How to check an explorer.exe

Three checks need nothing installed.

  1. Where the file is. In Task Manager open the Details tab, right-click explorer.exe and choose Open file location. The shell runs from C:\Windows. A copy in a user folder, AppData, Temp or ProgramData is not Windows.
  2. Who signed it. Right-click the file, open Properties, then Digital Signatures. The signer must be Microsoft Windows and the signature valid. The command prints the path and signature status of every running copy:
    Get-Process explorer | Select-Object Id, Path | ForEach-Object { $_; Get-AuthenticodeSignature $_.Path | Select-Object Status, @{n="Signer";e={$_.SignerCertificate.Subject}} }
  3. How many copies and who started them. Several running copies can be normal, but each should be in C:\Windows and signed. Parent and command line of every copy:
    Get-CimInstance Win32_Process -Filter "Name='explorer.exe'" | Select-Object ProcessId, ParentProcessId, ExecutablePath, CommandLine | Format-List
  4. Compare the file with Microsoft's builds. Use the checker on this page: it computes the SHA-256 in your browser and compares it with the known Microsoft builds.

These checks show whether the file is the Windows one. They cannot show that code was injected into a running genuine explorer.exe, which is a documented technique. For that run Microsoft Defender's full scan and, if the signs below apply or the malware blocks your security tools, restart in Safe Mode with Networking and scan there, then run the offline scan.

Check your explorer.exe

Choose the explorer.exe you are unsure about. Its SHA-256 checksum is calculated in your browser and compared with the 794 Microsoft builds indexed from Windows releases and updates.

or drop the file here

The file stays on your computer. Nothing is uploaded: the checksum is computed locally.

Warning signs and what they mean

What you seeWhat it means
explorer.exe outside C:\Windows (AppData, Temp, ProgramData, a user folder)Not the Windows shell. A program is borrowing the name.
Signature missing, invalid or not Microsoft'sThe file was replaced, or it is not from Microsoft. The old page also lists copies belonging to Intel, Spark, Apple, Avast or BitTorrent software, which are different programs.
Several copies, some outside C:\Windows or unsignedExtra copies in the right folder can be a folder-window setting. Copies elsewhere are not Windows.
New startup entries, scheduled tasks or changed registry keys you did not makeHow a fake explorer.exe or its payload starts at every boot, according to the old page; check Task Scheduler and Settings > Apps > Startup.
Slow PC, more browser ads and crashing programs together with the signs aboveEffects the old page linked to a computer taken over through the name; not proof by itself.
Crashes or a frozen desktop with a genuine, signed file in C:\WindowsUsually a Windows fault or a faulty add-on, not malware. Restart the process first.

Documented abuse of explorer.exe

From MITRE ATT&CK, the public catalogue of attacker techniques. Each row quotes what the entry records and links to it. Two patterns appear: malware named explorer.exe, and code injected into the genuine process.

MalwareHow it used the fileSource
Sandworm TeamAvoided detection by naming a malicious binary explorer.exe.T1036.005 match legitimate name or location
EmotetHas been observed injecting into explorer.exe and other processes.T1055.001 DLL injection
ComRATInjected its orchestrator DLL into explorer.exe.T1055.001 DLL injection
KazuarOn Windows saves a DLL to disk that is injected into the explorer.exe process to run the payload.T1055.001 DLL injection
BADHATCHCan run a malicious DLL by injecting into explorer.exe.T1055.001 DLL injection
Smoke LoaderSpawns a new copy of c:\windows\syswow64\explorer.exe and replaces its code in memory with malware.T1055.012 process hollowing
XLoaderInjects itself into the explorer.exe process by process hollowing.T1055.012 process hollowing

A named copy fails the folder and signature checks. An injected genuine explorer.exe passes them, so a clean file check does not clear a PC that shows the signs above. The old page named Reoxtan, DlDer, Blockey and Zhong as threats using the name; they are not in the sources linked here.

Everyday problems that are not malware

The desktop or taskbar is frozen, or the Start menu will not open. What now?

A faulty shell can be restarted without restarting Windows. Press Ctrl+Shift+Esc to open Task Manager (on Windows 10, click More details if only a short list shows).

On the Processes tab find Windows Explorer under Windows processes, right-click it and choose Restart. The taskbar disappears for a moment and returns.

When is restarting Windows Explorer useful?

It replaces a full restart after a change to registry entries that affects the shell, or when part of the graphical interface acts up or crashes.

Can the PC run without explorer.exe?

It can be controlled without it, but you lose the desktop, taskbar and File Explorer, and its failures cause serious problems. Third-party shells exist, but ending the process is not a way to fix anything.

Does a crash mean a virus?

Not by itself. Check the file's folder and signature before concluding anything; a genuine, signed file in C:\Windows that crashes is a Windows problem, and deleting it is never the answer.

explorer.exe versions by Windows release

The newest build indexed for each release, and the update that delivered it. 794 Microsoft builds in total are known.

Windows releaseFile versionDelivered bySize, 64-bit
Windows 11 26H110.0.28000.3086KB5124006, Sep 22, 20263,421,128 bytes
Windows 11 25H210.0.26100.5074original release3,067,376 bytes
Windows 11 24H210.0.26100.9549KB5124010, Sep 22, 20263,479,480 bytes
Windows 11 23H210.0.22621.7517KB5129242, Sep 14, 20265,625,200 bytes
Windows 11 22H210.0.22621.5983KB5066793, Oct 14, 20255,625,136 bytes
Windows 11 21H210.0.22000.3079KB5044280, Oct 8, 20245,092,064 bytes
Windows 10 22H210.0.19041.6392KB5066198, Sep 25, 20256,089,624 bytes
Windows 10 21H210.0.19041.7725KB5129236, Sep 14, 20266,090,176 bytes
Windows 10 21H110.0.19041.928original release4,704,752 bytes
Windows 10 20H210.0.19041.2913KB5026361, May 9, 20235,254,336 bytes

Questions people ask

Is explorer.exe a virus?

No. It is the Windows shell. Malware can use its name or run inside it, so the folder and signature matter more than the name. The genuine file is in C:\Windows and signed by Microsoft. A copy elsewhere or without a Microsoft signature is not Windows.

Should I remove explorer.exe?

No, not the genuine one. Without it you lose the desktop, taskbar and File Explorer, and nothing it does can be replaced easily. Remove only a copy that failed the folder or signature check, with a full Microsoft Defender scan and, if needed, the offline scan.

How do I restart explorer.exe?

Press Ctrl+Shift+Esc, find Windows Explorer under Windows processes, right-click it and choose Restart. This fixes a frozen desktop or taskbar and can replace a full restart after registry changes. If it keeps failing, scan the PC and check the file.

What if the scan finds nothing but the problem stays?

Restart in Safe Mode with Networking and scan again, because some malware tries to disable security tools. Then run the Microsoft Defender offline scan. Depending on the type of malware you may also need to reset your browsers, as some programs read traffic, cookies or screens.

How does a fake explorer.exe get onto a PC?

Through the usual routes: software bundles with free programs, spam emails and attachments, web injects, exploits and infected links on unsafe websites. The genuine file comes with Windows itself and never needs installing, so any installer, download or attachment offering an explorer.exe is a warning sign in itself.

How do I lower the risk of a fake?

Choose Advanced or Custom installation for free software and untick the extras. Do not open mail from unknown senders or its links and attachments, ignore suspicious ads, avoid file-sharing sites and torrent clients, update Windows and software at once, keep Microsoft Defender on and back up your files to external storage.

Do I have to keep explorer.exe?

Yes, if it is the genuine file. Without it navigating files and folders on local and connected drives becomes hard, although third-party interface software exists. Keep it, and check any other copy you find against the folder and signature tests on this page. The checker above also compares the file with the known Microsoft builds.

Sources

Version data read on Oct 5, 2026.

Questions and experiences

Ask about this page: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year