Which app's process is this

306c4d24.exe looks like you are on Win11.
Nothing shows up on google.
See if it shows in task manager under process or details. Right-click it and open file location and you might get some lead.

Also, better scan your system with malwarebytes as it will instantly identify such processes and let us know the results.
 
Last edited:
  • Like
Reactions: becool773
His query is regarding 306c4d24.exe. Lol
looks like you are on Win11.
He is on Windows 10. Those icons give it away.
See if it shows in task manager under process or details. Right-click it and open file location and you might get some lead.
Or he can look up this exe on Everything, check it's properties for signatures and upload it on virustotal.
let us know the results.
Yeah OP let us know what you got in there.
 
Last edited:
  • Like
Reactions: calvin1719
306c4d24.exe looks like you are on Win11.
Nothing shows up on google.
See if it shows in task manager under process or details. Right-click it and open file location and you might get some lead.

Also, better scan your system with malwarebytes as it will instantly identify such processes and let us know the results.
No, on windows 10. Scanned using windows defender, kvrt all clean. Installed and scanned using malwarebytes just now and it found these

Registry Value: 2
PUM.Optional.DisableMRT, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, No Action By User, 7430, 676881, 1.0.85157, , ame, , ,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, No Action By User, 7430, 676881, 1.0.85157, , ame, , ,

What exactly do you think are these? I have very limited softwares installed in this pc and that too related to work. Though I have installed O&Oshutpup 10, wpd10 and privatezilla to reduce telemetry and what not 6 months back. Can these be the issue? The pc works fine btw.

This process is not showing in task manager anywhere.

@rootyme
Everything shows zero results about 306c4d24.exe
 
No, on windows 10. Scanned using windows defender, kvrt all clean. Installed and scanned using malwarebytes just now and it found these

Registry Value: 2
PUM.Optional.DisableMRT, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, No Action By User, 7430, 676881, 1.0.85157, , ame, , ,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, No Action By User, 7430, 676881, 1.0.85157, , ame, , ,

What exactly do you think are these? I have very limited softwares installed in this pc and that too related to work. Though I have installed O&Oshutpup 10, wpd10 and privatezilla to reduce telemetry and what not 6 months back. Can these be the issue? The pc works fine btw.

This process is not showing in task manager anywhere.

@rootyme
Everything shows zero results about 306c4d24.exe
Observe for a day or two if the process returns.
AFAIK MB nullifies such infections even if they cannot be completely removed.

Also, I hope you have windows defender active, updated and kicking. Check the process or exclusions there.

Most importantly, check in Task Scheduler for any unknown fishy entry. Carefully analyze and delete it.
More here..

 
  • Like
Reactions: becool773
Observe for a day or two if the process returns.
AFAIK MB nullifies such infections even if they cannot be completely removed.

Also, I hope you have windows defender active, updated and kicking. Check the process or exclusions there.

Most importantly, check in Task Scheduler for any unknown fishy entry. Carefully analyze and delete it.
More here..

MalwareBytes has quanratied it. Should I delete them?

WD is already updated and running. I scanned with kvrt too, all clean.

Nothing in task manager.

I did not understand that thread, can you please eli5 what these PUM's are?

I have installed these
Could these be the reason behind it?
 
MalwareBytes has quanratied it. Should I delete them?
You should.
WD is already updated and running. I scanned with kvrt too, all clean.

Nothing in task manager.
Thank MalwareBytes.
I did not understand that thread, can you please eli5 what these PUM's are?

I have installed these
Could these be the reason behind it?
Ignore. It was just for ref.
 
  • Like
Reactions: becool773
You should.

Thank MalwareBytes.

Ignore. It was just for ref.
Found more processes


Am I fcked? Ran kvrt+MalwareBytes again everything is clean. What should I do now?

Can apps like these behind these processes?
I ran all three together about 4 months ago. But noticed these kinda weird processes few weeks ago only.

+ @guest_999 @LinkdJay @calvin1719 @rootyme
 
Right click on them & select "open file location" then post those locations here.
Right click open loc only works from taskmanager not windows app.
@becool773 check if these are running in task manager.

Have you checked task scheduler? I told you to do so last time.

I wonder why you were so much afraid of telemetry that you installed those tools and then this.

You need to dive deep inside registry editor along with task scheduler. If you cannot then best bet is to reinstall the os rather than playing around as not all infections can be 100% cleaned.
 
Right click open loc only works from taskmanager not windows app.
@becool773 check if these are running in task manager.

Have you checked task scheduler? I told you to do so last time.

I wonder why you were so much afraid of telemetry that you installed those tools and then this.

You need to dive deep inside registry editor along with task scheduler. If you cannot then best bet is to reinstall the os rather than playing around as not all infections can be 100% cleaned.
There is nothing in task manager. Task scheduler when opened shows about usual processes scheduled under active tasks. Can we search for these processes there?
Besides malwarebytes, anything else that can be tried before reinstallation? And as malwarebytes and kvrt are saying that all files are clean, so is it safe to copy files and folders elsewhere?
 
Can't find these locations/folders in C:\Users\xxxx\AppData\Local\Temp
There is nothing in task manager. Task scheduler when opened shows about usual processes scheduled under active tasks.
It seems those files were removed by antivirus/defender/mbam but leaving behind traces in the form of scheduled tasks. I suggest you to follow the advice given by others & format & reinstall windows & this time don't install any "tweak/privacy software/script".
 
  • Sad
Reactions: becool773
There is nothing in task manager. Task scheduler when opened shows about usual processes scheduled under active tasks. Can we search for these processes there?
Unfortunately, such infections and their process are rather dynamic in nature hence not every error can be found on the net.
Besides malwarebytes, anything else that can be tried before reinstallation? And as malwarebytes and kvrt are saying that all files are clean, so is it safe to copy files and folders elsewhere?
You can give a try to Avast av and select Boot scan in the settings, it reboots your pc and does a boot scan before loading the actual os.
Last best bet before giving up.
 
  • Sad
Reactions: becool773
Unfortunately, such infections and their process are rather dynamic in nature hence not every error can be found on the net.

You can give a try to Avast av and select Boot scan in the settings, it reboots your pc and does a boot scan before loading the actual os.
Last best bet before giving up.
Bro if i go for reinstall of windows then do I need to format the whole drive i.e. format the d drive also? Or just install windows in c drive like usual?
On an average, how much writes does reinstallation takes in a ssd? And as malwarebytes and kvrt are saying that all files are clean, so is it safe to copy files and folders elsewhere?
+ @guest_999
 
do I need to format the whole drive i.e. format the d drive also? Or just install windows in c drive like usual?
Just install windows in C drive as usual after formatting the C drive only. make sure to not delete/format the wrong partition so give attention to the partition sizes assuming your C & D partition have different size.

how much writes does reinstallation takes in a ssd?
Unless you are installing windows every week you can ignore this, it takes around 20-40GB I think.
 
  • Like
Reactions: becool773
Just install windows in C drive as usual after formatting the C drive only. make sure to not delete/format the wrong partition so give attention to the partition sizes assuming your C & D partition have different size.


Unless you are installing windows every week you can ignore this, it takes around 20-40GB I think.
As malwarebytes and kvrt are saying that all files are clean, so is it safe to copy files and folders elsewhere? I mean will the copied files or folders infect other systems?
 
Since you are using this machine for work, could even be some badly behaved corporate application that is creating and running these files. E.g. one guy had Adobe Acrobat create hexadecimal named files right in their drive root : https://superuser.com/questions/160...-with-hex-names-that-show-up-in-my-drive-root


Not only Adobe, many other corporate darling applications, including scripts by internal IT team are badly behaved i.e. create suspicious files and don't clean up properly.

Check the creation times of these files, and what you were doing around that time. Maybe write a script to check that folder for files every minute. Also stop posting the hexadecimal name on the internet, because it might encode some information about you or your employer.
 
  • Sad
Reactions: becool773
Not only Adobe, many other corporate darling applications, including scripts by internal IT team are badly behaved i.e. create suspicious files and don't clean up properly.
He is running privacy/performance tweaks script which modify core windows system files, I really doubt his pc is having any corporate control.
 
  • Like
Reactions: becool773