Jump to content
msudave

SppExtComObjPatcher.exe not removing

Recommended Posts

ok so ended up with some issues tonight

system detected potential harmful issue if i proceeded while web surfing so i backed out, but then had some programs that wouldn't load such as my Photoshop and Lightroom, so did a few things to try to fix that (error said mfc110u.dll was not found) and had to do a restart then got an error from my pass.us uploader saying Nativelogic.dll was not found, easy fix i just got rid of pass (photo sharing program). but my Malwarebytes at start up keeps saying C:\Windows\System32\SppExtComObjPatcher.exe was found and quarantine but it keeps coming back. how do I remove this for good. Seen where it could be a key logger program sending everything I type to con artist. 

Share this post


Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.
Click Attach this file.
Click the Add reply button.
===

Please post the logs  for my review.

Wait for further instructions

Share this post


Link to post
Share on other sites

system was fairly new so decided to do a clean install and after all the reboots and updates and more reboots I still have the issue and now defender is finding an AutoKMS that needs to go too. 

Addition.txt FRST.txt

Share this post


Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Could this be the culprit?
Task: {4D304788-A028-473D-8EAD-41362F1CFE9C} - System32\Tasks\KMS_VL_ALL => C:\Windows\schemas\Scripts\KMS_VL_ALL.cmd

Rename KMS_VL_ALL.cmd to b]Old_KMS_VL_ALL.cmd.old[/b]

Restart the computer normally.

How is it now?

Share this post


Link to post
Share on other sites

i know when I scan with Windows Defender it's comes up with the KMS issue and poitnts at the C:\Windows\System32\SppExtComObjPatcher.exe file

Share this post


Link to post
Share on other sites


Hi,

This filx will remove these entries if found.
Task: {4D304788-A028-473D-8EAD-41362F1CFE9C} - System32\Tasks\KMS_VL_ALL => C:\Windows\schemas\Scripts\KMS_VL_ALL.cmd
C:\Windows\schemas\Scripts\KMS_VL_ALL.cmd
C:\Windows\schemas\Scripts\Old_KMS_VL_ALL.cmd.old
C:\Windows\System32\SppExtComObjPatcher.exe

This is an indication that you are running or have used a cracked version of Windows or program.

If the problem persists clean the Windows Defender quarantine folder.
Delete all contents.

https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus
Restart the computer normally. 
===

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

fixlist.txt

Share this post


Link to post
Share on other sites

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.