Does Start8 modify explorer.exe?

After scanning my pc i always get a information from Avira Internet Security Suite about a suspicious malware HEUR/Modified.SystemFile in modified explorer.exe. Is it possible that Start8 is the reason of this finding?

4,350 views 6 replies
Reply #1 Top

Start8 does not modify any executables on your hard drive or in memory.

While it is always possible Avira is somehow deciding Start8 is causing some issue, I suspect it is nothing to do with Start8.

Does it perhaps indicate which file it thinks is modified? That might make it easier for you to track down.

Reply #2 Top

 Yes, Avira says the file "C:\Windows\explorer.exe" was found with suspicious malware "HEUR/Modified.SystemFile". 

 

 

Reply #3 Top

Quoting myonno, reply 2
 Yes, Avira says the file "C:\Windows\explorer.exe" was found with suspicious malware "HEUR/Modified.SystemFile". 

 

 
End of myonno's quote

If you Google: HEUR/Modified.SystemFile

you will see that it has nothing to do with Start8.

But a strange thing is that it is only Avira that seems to report this.

Not sure why this is, but I'll let you investigate it more.

Reply #4 Top

Hello!

Now, a few weeks later i found the reason of the report from Avira Internet Security 2013. 

After uninstalling Start8 there were some entrys in the registry which were not removed by the Start8 Uninstaller. 

Avira IS noticed this and reported this as possible maleware (just if you set "check the integrity of systemfiles" in Aviras configuration). Now i cleaned the registry and removed all Start8 entrys by hand. 

Everything works fine now again.

I think that the developer of the uninstaller for Start8 should program this better. 

Have a nice week

Reply #5 Top

Quoting myonno, reply 4

Hello!

Now, a few weeks later i found the reason of the report from Avira Internet Security 2013. 

After uninstalling Start8 there were some entrys in the registry which were not removed by the Start8 Uninstaller. 

Avira IS noticed this and reported this as possible maleware (just if you set "check the integrity of systemfiles" in Aviras configuration). Now i cleaned the registry and removed all Start8 entrys by hand. 

Everything works fine now again.

I think that the developer of the uninstaller for Start8 should program this better. 

Have a nice week

 
End of myonno's quote

Which registry keys?  The user settings will remain because people complain if you uninstall to install a new one and it wiped the settings, but nothing else should.

It sounds like a major flaw in a security app to mistakenly believe that a left over registry key means explorer.exe has been modified.

Reply #6 Top

Possibly.

I noticed that only Avira IS means the explorer.exe seems to be modified. I found no other sec. app with this "report" of HEUR/Modified.SystemFile in explorer.exe. 

Strange. I was wondering that a scan result could be incorrectly just because of some registry keys from Start8. (Unhappily i didn“t note the keys).

I will tell you more again after my report to avira.