Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


What are these files?

  • Please log in to reply
3 replies to this topic

#1 Hikermann


  • Members
  • 68 posts
  • Local time:08:12 PM

Posted 23 October 2013 - 11:10 PM

I notice numerous files with string designations similar to these showing up in my backup; what are they; can they be deleted?



BC AdBot (Login to Remove)


#2 Roodo


  • Members
  • 760 posts
  • Gender:Male
  • Local time:10:12 PM

Posted 23 October 2013 - 11:33 PM


#3 noknojon


  • Banned
  • 10,871 posts
  • Gender:Not Telling
  • Local time:02:12 PM

Posted 23 October 2013 - 11:54 PM

Hello -

I am just asking if there is a special reason to find this out ?

Do you just want to know, or do you want to remove them ?

They "seem" to be related to a Seagate Drive, about I can find -


Put bdfff555f7845c308e0f5d76afe0 into Google and you get ..............


Bleeping Computer -

I notice numerous files with string designations similar to these showing up in my backup; what are they; can they be deleted?


Seagate forum Feb 24 2013
Looking in Windows Explorer, there is a file under Seagate



Hikermann 4 minutes ago 
Do you have Seagate drive ?
>>Toms Hardware -


I notice numerous files with string designations similar to these showing up in my backup; what are they; can they be deleted?
>>MYCE -


Why not just leave them for now .......... :thumbup2:


Thank You -

Edited by noknojon, 24 October 2013 - 12:03 AM.

#4 quietman7


    Bleepin' Janitor

  • Global Moderator
  • 51,932 posts
  • Gender:Male
  • Location:Virginia, USA
  • Local time:11:12 PM

Posted 24 October 2013 - 09:22 PM

Are you sure they are files and not folders?

Randomly named alpha/numeric folders are commonly created and used temporarily when updating Windows components. They are also used by some software programs (i.e. Microsoft Office, Microsoft Visual Studio, etc) during update or installation to hold setup files (.inf, .cat, .gpd, .ppd and .dlls) and other information. These files and folders are usually automatically removed as part of the update process. However, its not uncommon for them not to be cleaned up and left behind after the update has been applied. When that occurs they usually can be manually deleted at any time.

For example, when you run the MS Malicious Software Removal Tool (MSRT), a temporary folder with random alpha/numeric characters (i.e. C\79f142e5e9e574d23954) will be created on your C:\ drive that contains mrt.exe, mrtstub.exe and a file named $shtdwn$.req. Since external drives can be a hiding place for malicious files, MSRT will scan them too and you may find a left over folder in that location. Usually fter performing a scan and you click finish or cancel, the folder will automatically be removed right away or after the next restart of the computer. If not, Microsoft says the folder and its contents can be manually deleted without an adverse effect on the computer.

The following is an excerpt from Microsoft explaining the folders used by MSRT:

The Malicious Software Removal Tool does not use an installer. Typically, when you run the Malicious Software Removal Tool, it creates a randomly named temporary directory on the root drive of the computer. This directory contains several files, and it includes the Mrtstub.exe file. Most of the time, this folder is automatically deleted after the tool finishes running or after the next time that you start the computer. However, this folder may not always be automatically deleted. In these cases, you can manually delete this folder, and this has no adverse effect on the computer.

Installation of service packs, security updates from Microsoft for MSMXL packages and hotfixes also create temporary randomly alpha/numeric named folders. Sometimes these folders create sub-folders as described here or contain sub-folders like amd64 and i386. The creation date should match the installation date of the updates or show in the ReportingEvents.log located in the C:\Windows\SoftwareDistribution folder. spmsg.dll is a Microsoft Service Pack file commonly found in randomly named alpha/numeric folders as shown here. SP1QFE, SP2QFE, SP3QFE and SP2GDR are also Service Pack files from Microsoft which you may encounter.

Again, finding these leftover temporary files are not uncommon after applying an update. Other legitimate programs can also create randomly named folders in various areas of your hard drive. Sometimes identifying the source is as simple as opening the folder and looking inside for sub-folders and file names which may provide a clue as to what program created them. In many cases if you delete these folders, the program will recreate them immediately after rebooting the computer.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users