How to remove sppextcomobjpatcher.exe
- File Details
- Overview
- Analysis
sppextcomobjpatcher.exe
The module sppextcomobjpatcher.exe has been detected as Hack.KMS
File Details
MD5: |
0bf6fc2387197df2142eb9709ae74d55 |
Size: |
8 KB |
First Published: |
2017-05-21 05:04:49 (8 years ago) |
Latest Published: |
2025-07-21 23:01:22 (2 days ago) |
Status: |
Hack.KMS (on last analysis) |
|
Analysis Date: |
2025-07-21 23:01:22 (2 days ago) |
Overview
Signed By: |
WZT |
Status: |
Valid |
%windir%\system32 |
%sysdrive%\vtroot\harddiskvolume3\users\user\appdata\local\temp\kmsauto |
%temp%\kmsauto |
%sysdrive%\windows.old\windows\system32 |
%sysdrive%\$recycle.bin\s-1-5-21-2275429643-1357250638-3055656149-1001 |
%sysdrive%\$windows.~bt\newos\windows\system32 |
%system% |
%temp% |
%sysdrive%\windows.old\windows |
%sysdrive%\system volume information\systemrestore\frstaging\windows |
SppExtComObjPatcher.exe |
sppextcomobjpatcher.exe |
$RYJ4C6Q.exe |
SppExtComObjPatcher.exe.quarantined |
South Korea |
14.1% |
|
Russia |
13.7% |
|
Ukraine |
11.0% |
|
Mexico |
5.6% |
|
Spain |
3.9% |
|
Peru |
3.9% |
|
Argentina |
3.8% |
|
Iran |
3.4% |
|
Colombia |
3.0% |
|
Chile |
2.6% |
|
Vietnam |
1.9% |
|
Romania |
1.9% |
|
Belarus |
1.8% |
|
Egypt |
1.7% |
|
Indonesia |
1.5% |
|
Brazil |
1.5% |
|
Turkey |
1.2% |
|
United States |
1.1% |
|
Saudi Arabia |
1.0% |
|
Ecuador |
0.9% |
|
Palestine |
0.9% |
|
France |
0.9% |
|
Italy |
0.9% |
|
Czech Republic |
0.8% |
|
Bolivia |
0.8% |
|
Thailand |
0.8% |
|
Dominican Republic |
0.7% |
|
Bulgaria |
0.6% |
|
Morocco |
0.6% |
|
United Kingdom |
0.6% |
|
India |
0.6% |
|
Algeria |
0.6% |
|
Pakistan |
0.6% |
|
El Salvador |
0.6% |
|
Uruguay |
0.6% |
|
Germany |
0.5% |
|
Poland |
0.5% |
|
Greece |
0.5% |
|
Costa Rica |
0.4% |
|
Kazakhstan |
0.4% |
|
Venezuela |
0.4% |
|
Portugal |
0.4% |
|
Guatemala |
0.3% |
|
Iraq |
0.3% |
|
Israel |
0.3% |
|
Australia |
0.3% |
|
Netherlands |
0.3% |
|
China |
0.3% |
|
Armenia |
0.3% |
|
Paraguay |
0.3% |
|
Hungary |
0.3% |
|
Malaysia |
0.3% |
|
Taiwan |
0.3% |
|
Nicaragua |
0.3% |
|
Finland |
0.2% |
|
Estonia |
0.2% |
|
Switzerland |
0.2% |
|
Latvia |
0.2% |
|
Laos |
0.2% |
|
Austria |
0.2% |
|
Philippines |
0.2% |
|
United Arab Emirates |
0.2% |
|
Moldova |
0.1% |
|
Libya |
0.1% |
|
Sweden |
0.1% |
|
Georgia |
0.1% |
|
Bahrain |
0.1% |
|
Canada |
0.1% |
|
Myanmar |
0.1% |
|
Sri Lanka |
0.1% |
|
Belgium |
0.1% |
|
Croatia |
0.1% |
|
Japan |
0.1% |
|
Bangladesh |
0.1% |
|
Denmark |
0.1% |
|
Oman |
0.1% |
|
Panama |
0.1% |
|
Azerbaijan |
0.1% |
|
Hong Kong |
0.1% |
|
Reunion |
0.1% |
|
Kyrgyzstan |
0.1% |
|
Niger |
0.1% |
|
Mali |
0.1% |
|
Angola |
0.1% |
|
Ghana |
0.1% |
|
Singapore |
0.1% |
|
Cambodia |
0.1% |
|
Syria |
0.1% |
|
Norway |
0.1% |
|
Yemen |
0.1% |
|
Windows 10 |
92.7% |
|
Windows 8.1 |
7.0% |
|
Windows Embedded 8.1 |
0.1% |
|
Windows Server 2016 |
0.1% |
|
Windows Server 2012 R2 |
0.1% |
|
Windows Server 2008 R2 |
0.1% |
|
Windows 7 |
0.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x00001000 |
Name |
Size of data |
MD5 |
.text |
1024 |
f4c696a25346888e110e3a6df8265945 |
.rdata |
1536 |
5823acce36bad8c8cb1a6c1332f2b13b |
.pdata |
512 |
b9eabb0a9a3f9e3e07b4174fa36c1881 |
.rsrc |
512 |
8d096de51d16180d98ba04bad2632f19 |