• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Random folders appearing to my new hard drive

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,263 (4.35/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
Well...that's bizzare. I have no idea what is telling Explorer.exe to do that.

The process list is interesting though. That D:\7-zip\7-zip.dll is very suspicious. I'd look for ones similar to that that stand out. It seems legit for 7-zip if you do have 7-zip installed there.
 
Joined
Feb 8, 2012
Messages
3,014 (0.62/day)
Location
Zagreb, Croatia
System Name Windows 10 64-bit Core i7 6700
Processor Intel Core i7 6700
Motherboard Asus Z170M-PLUS
Cooling Corsair AIO
Memory 2 x 8 GB Kingston DDR4 2666
Video Card(s) Gigabyte NVIDIA GeForce GTX 1060 6GB
Storage Western Digital Caviar Blue 1 TB, Seagate Baracuda 1 TB
Display(s) Dell P2414H
Case Corsair Carbide Air 540
Audio Device(s) Realtek HD Audio
Power Supply Corsair TX v2 650W
Mouse Steelseries Sensei
Keyboard CM Storm Quickfire Pro, Cherry MX Reds
Software MS Windows 10 Pro 64-bit
7-zip is probably harmless and installs with itself windows explorer extension so it's there, but since explorer.exe is the source the culprit is one of the extensions (extra right click menu items and such).
I'd run autoruns.exe also from sysinternals and see what windows explorer extensions are being loaded at startup, and check all file hashes with virus database (function of the program)

EDIT: @FordGT90Concept I see you probably mean install location is out of sorts
 

nemo_fin

New Member
Joined
Feb 22, 2017
Messages
12 (0.00/day)
My 7zip is installed on my d drive yes. Also what is this explorer.exe?

I downloaded autoruns.exe. Is this what u mean? Also idk how to check all file hases sry.
 
Joined
Feb 8, 2012
Messages
3,014 (0.62/day)
Location
Zagreb, Croatia
System Name Windows 10 64-bit Core i7 6700
Processor Intel Core i7 6700
Motherboard Asus Z170M-PLUS
Cooling Corsair AIO
Memory 2 x 8 GB Kingston DDR4 2666
Video Card(s) Gigabyte NVIDIA GeForce GTX 1060 6GB
Storage Western Digital Caviar Blue 1 TB, Seagate Baracuda 1 TB
Display(s) Dell P2414H
Case Corsair Carbide Air 540
Audio Device(s) Realtek HD Audio
Power Supply Corsair TX v2 650W
Mouse Steelseries Sensei
Keyboard CM Storm Quickfire Pro, Cherry MX Reds
Software MS Windows 10 Pro 64-bit
Also idk how to check all file hases sry.

Options > Scan options

Untitled.png


Then after that, enable options > hide virustotal.com clean entries ... only suspicious stuff will remain.
Check the complete list on the Everything tab, it may not be explorer extension listed on that tab.

It may be something stupidly simple like onedrive/skydrive being setup to sync folders that are being dumped remotely.
 
Last edited:
Joined
Jul 16, 2014
Messages
8,246 (2.09/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
show us whats on the Everything tab
 
Joined
Jan 25, 2014
Messages
2,098 (0.51/day)
System Name Ryzen 2023
Processor AMD Ryzen 7 7700
Motherboard Asrock B650E Steel Legend Wifi
Cooling Noctua NH-D15
Memory G Skill Flare X5 2x16gb cl32@6000 MHz
Video Card(s) Sapphire Radeon RX 6950 XT Nitro + gaming Oc
Storage WESTERN DIGITAL 1TB 64MB 7k SATA600 Blue WD10EZEX, WD Black SN850X 1Tb nvme
Display(s) LG 27GP850P-B
Case Corsair 5000D airflow tempered glass
Power Supply Seasonic Prime GX-850W
Mouse A4Tech V7M bloody
Keyboard Genius KB-G255
Software Windows 10 64bit
So you say it's a new drive. What was the last thing you installed before noticing this?
 

nemo_fin

New Member
Joined
Feb 22, 2017
Messages
12 (0.00/day)
Tbh no idea, I installed a lot of programs. But what do u think about the possibility that I got this after I inserted my windows key?
 

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,263 (4.35/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
Do you know what that Solvusoft, toastify, 3rvx, and gyazo is?


In ProcessMon, did you actually see it creating/modifying the files inside the folders?
 
Joined
Oct 17, 2012
Messages
9,781 (2.14/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
Gyazo is safe, it's for pictures or something my nephew has it

I'm assuming the others are also needless software that perform some function that can be done by the user very easily. I would associate these in the category same as download managers etc. delete them

@OP
Post a shot of your installed programs my guess is the solution to several of these issues will be found in there
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
27,598 (3.84/day)
Location
Alabama
System Name RogueOne
Processor Xeon W9-3495x
Motherboard ASUS w790E Sage SE
Cooling SilverStone XE360-4677
Memory 128gb Gskill Zeta R5 DDR5 RDIMMs
Video Card(s) MSI SUPRIM Liquid 5090
Storage 1x 2TB WD SN850X | 2x 8TB GAMMIX S70
Display(s) 49" Philips Evnia OLED (49M2C8900)
Case Thermaltake Core P3 Pro Snow
Audio Device(s) Moondrop S8's on chitt Gunnr
Power Supply Seasonic Prime TX-1600
Mouse Razer Viper mini signature edition (mercury white)
Keyboard Wooting 80 HE White, Gateron Jades
VR HMD Quest 3
Software Windows 11 Pro Workstation
Benchmark Scores I dont have time for that.
why is your explorer.exe capitalized?

You should run a malware scan.

What is in your scheduled tasks?

Can you upload one of the files in those folders in a zip file here?
 

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,263 (4.35/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
I checked myself. C:\windows\explorer.exe is where it should be and Process Monitor always shows it as "Explorer.EXE"

I'm thinking Explorer.EXE handles all folder creation requests because it has to cross reference that with user permissions. The same goes for creating a file. Writing to a file though, Explorer.EXE checks permissions then lets the process proceed. If you're going to catch the culprit, it has to be the application that writes to the files. The files aren't zero length so it definitely happens...eventually.

In Process Monitor, you can add a "Process Name is Explorer.EXE then Exclude" rule to narrow it down. In fact, you can keep it running and keep adding filters to exclude programs you believe are safe and reapply the filter until you find the culprit.
 
Joined
Feb 9, 2009
Messages
1,618 (0.27/day)
not sure why we didnt start out using resource monitor, which is built into windows, to view the process/disk activity

opening an explorer window is going to cause processmonitor to think those folders are being accessed, but that's useless noise information, we are trying to capture the moment when one of these is created.... it looks like each one has a different date & time, does that have any relation to anything? booting or starting something during those times?

you didnt open with text editor or hex edit the files?

forget about what you installed for now, turn off all startups & third party services, have a minimal windows running, avoid using programs & stick to a web browser, now see if a new folder is created during such a time period

you also havent described how & where you downloaded the third party software, if you always make sure to look at the installer to turn off bundled crap, if you turn off features you dont use (like skydrive)

what is that 'workfolders' in autoruns? what's 3rvx & toastify or why do they need to be on startup? what is or why use winthruster? why gyazo?
 

FordGT90Concept

"I go fast!1!11!1!"
Joined
Oct 13, 2008
Messages
26,263 (4.35/day)
Location
IA, USA
System Name BY-2021
Processor AMD Ryzen 7 5800X (65w eco profile)
Motherboard MSI B550 Gaming Plus
Cooling Scythe Mugen (rev 5)
Memory 2 x Kingston HyperX DDR4-3200 32 GiB
Video Card(s) AMD Radeon RX 7900 XT
Storage Samsung 980 Pro, Seagate Exos X20 TB 7200 RPM
Display(s) Nixeus NX-EDG274K (3840x2160@144 DP) + Samsung SyncMaster 906BW (1440x900@60 HDMI-DVI)
Case Coolermaster HAF 932 w/ USB 3.0 5.25" bay + USB 3.2 (A+C) 3.5" bay
Audio Device(s) Realtek ALC1150, Micca OriGen+
Power Supply Enermax Platimax 850w
Mouse Nixeus REVEL-X
Keyboard Tesoro Excalibur
Software Windows 10 Home 64-bit
Benchmark Scores Faster than the tortoise; slower than the hare.
opening an explorer window is going to cause processmonitor to think those folders are being accessed, but that's useless noise information, we are trying to capture the moment when one of these is created.... it looks like each one has a different date & time, does that have any relation to anything? booting or starting something during those times?
Process Monitor ignores itself. He already captured the folders being created in one of the screenshots. The screenshot doesn't show one of the files being written to.
 
Joined
Feb 8, 2012
Messages
3,014 (0.62/day)
Location
Zagreb, Croatia
System Name Windows 10 64-bit Core i7 6700
Processor Intel Core i7 6700
Motherboard Asus Z170M-PLUS
Cooling Corsair AIO
Memory 2 x 8 GB Kingston DDR4 2666
Video Card(s) Gigabyte NVIDIA GeForce GTX 1060 6GB
Storage Western Digital Caviar Blue 1 TB, Seagate Baracuda 1 TB
Display(s) Dell P2414H
Case Corsair Carbide Air 540
Audio Device(s) Realtek HD Audio
Power Supply Corsair TX v2 650W
Mouse Steelseries Sensei
Keyboard CM Storm Quickfire Pro, Cherry MX Reds
Software MS Windows 10 Pro 64-bit
Last edited:
Joined
Jan 25, 2014
Messages
2,098 (0.51/day)
System Name Ryzen 2023
Processor AMD Ryzen 7 7700
Motherboard Asrock B650E Steel Legend Wifi
Cooling Noctua NH-D15
Memory G Skill Flare X5 2x16gb cl32@6000 MHz
Video Card(s) Sapphire Radeon RX 6950 XT Nitro + gaming Oc
Storage WESTERN DIGITAL 1TB 64MB 7k SATA600 Blue WD10EZEX, WD Black SN850X 1Tb nvme
Display(s) LG 27GP850P-B
Case Corsair 5000D airflow tempered glass
Power Supply Seasonic Prime GX-850W
Mouse A4Tech V7M bloody
Keyboard Genius KB-G255
Software Windows 10 64bit
I read a little about your problem on other forums and it's possible that windown update is creating them.
These folders are harmless. Windows Update will place the data required to install data on the largest drive it finds. This has been the default behavior since the dawn of time
 

nemo_fin

New Member
Joined
Feb 22, 2017
Messages
12 (0.00/day)
FordGT90Concept
I dont know whats solvusoft. But gyazo is screenshot app. Toastify, 3rvx were downloaded a way after this incident so they cant be the cause. Im not really sure how to see if its creating/modifying the files inside the folders.

jboydgolfer




Solaris17
I did malware scan with malwarebytes. Not really sure how to see scheduled tasks. I added the file into this post.

FordGT90Concept
Should I still keep the old rule which u told me before? Also how do i know if a program is safe?

kn00tcn
I cant really think of anything what Ive done... It seems to be pretty random. I was also unable to open the files if thats what u mean? Also what third party software are u talking about?
I dont know whats workfolders.. But 3rvx & toastify are sound programs which I downlaoded 2 days ago so they arent the problem. I think someone told me somewhere to download winthruster.. I think that was also just few days ago. Gyazo is screenshot program, very useful.

opojare
These files u have actually look the same as mine.. Is there .file -file inside those folders? Actually I did that thing u told me to. Now the files I had on my hard drive are seperate cache folder. Should I now delete the files from my hard drive?

Devon68
Yes I read this, but I readed also that they should remove themselves in few days which didnt happen in my case.

Edit: deleted thefile for privacy reasons
 
Last edited:

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
27,598 (3.84/day)
Location
Alabama
System Name RogueOne
Processor Xeon W9-3495x
Motherboard ASUS w790E Sage SE
Cooling SilverStone XE360-4677
Memory 128gb Gskill Zeta R5 DDR5 RDIMMs
Video Card(s) MSI SUPRIM Liquid 5090
Storage 1x 2TB WD SN850X | 2x 8TB GAMMIX S70
Display(s) 49" Philips Evnia OLED (49M2C8900)
Case Thermaltake Core P3 Pro Snow
Audio Device(s) Moondrop S8's on chitt Gunnr
Power Supply Seasonic Prime TX-1600
Mouse Razer Viper mini signature edition (mercury white)
Keyboard Wooting 80 HE White, Gateron Jades
VR HMD Quest 3
Software Windows 11 Pro Workstation
Benchmark Scores I dont have time for that.
It is Spotify cache files/encrypted music.
Of course it will reappear if you play any song.

Just change cache folder in your desired folder (Edit - Preferences - Advanced settings - Cache).

We have a winner!

FordGT90Concept
I dont know whats solvusoft. But gyazo is screenshot app. Toastify, 3rvx were downloaded a way after this incident so they cant be the cause. Im not really sure how to see if its creating/modifying the files inside the folders.

jboydgolfer




Solaris17
I did malware scan with malwarebytes. Not really sure how to see scheduled tasks. I added the file into this post.

FordGT90Concept
Should I still keep the old rule which u told me before? Also how do i know if a program is safe?

kn00tcn
I cant really think of anything what Ive done... It seems to be pretty random. I was also unable to open the files if thats what u mean? Also what third party software are u talking about?
I dont know whats workfolders.. But 3rvx & toastify are sound programs which I downlaoded 2 days ago so they arent the problem. I think someone told me somewhere to download winthruster.. I think that was also just few days ago. Gyazo is screenshot program, very useful.

opojare
These files u have actually look the same as mine.. Is there .file -file inside those folders? Actually I did that thing u told me to. Now the files I had on my hard drive are seperate cache folder. Should I now delete the files from my hard drive?

Devon68
Yes I read this, but I readed also that they should remove themselves in few days which didnt happen in my case.

Its spotify.

 
Joined
Feb 19, 2006
Messages
6,270 (0.89/day)
Location
New York
Processor INTEL CORE I9-9900K @ 5Ghz all core 4.7Ghz Cache @1.305 volts
Motherboard ASUS PRIME Z390-P ATX
Cooling CORSAIR HYDRO H150I PRO RGB 360MM 6x120mm fans push pull
Memory CRUCIAL BALLISTIX 3000Mhz 4x8 32gb @ 4000Mhz
Video Card(s) EVGA GEFORECE RTX 2080 SUPER XC HYBRID GAMING
Storage ADATA XPG SX8200 Pro 1TB 3D NAND NVMe,Intel 660p 1TB m.2 ,1TB WD Blue 3D NAND,500GB WD Blue 3D NAND,
Display(s) 50" Sharp Roku TV 8ms responce time and Philips 75Hz 328E9QJAB 32" curved
Case BLACK LIAN LI O11 DYNAMIC XL FULL-TOWER GAMING CASE,
Power Supply 1600 Watt
Software Windows 10
Last edited:
Top