A couple of days ago, I was watching YouTube when a “Do you want to allow this app to make changes to your computer” window popped up. It was onedrivepatcher.exe
As I was not installing or updating anything, I found it suspicious and did not click on either yes or no. The window disappeared on its own after a while. I assumed that means no access is allowed, please correct me if I’m wrong.
After a quick google search indicated onedrivepatcher.exe is a malware.
Norton and nordVPN threat protection both failed to catch it.
Under task manager -
- startup app looks normal to me
- details, there was strange program with a name which was something like lll:nn:nn:nn (l= letters and n=numbers). I think it started with S as it was close to svchost.exe but I am not sure
In the meantime, Norton was being manually updated which triggered a restart.
After the restart, the weird program was gone from details. I assumed it was the malware and it was a temp file that was purged with the restart. Assumed is playing a big part here as I’m pretty much a computer idiot.
- did Get-ChildItem -Path C:\ -Filter "onedrivepatcher.exe" -Recurse -ErrorAction SilentlyContinue which came back with nothing (I just found out this don’t search for hiddle files smh)
- task scheduler looks normal
- no new extension on Edge and Firefox
- no new account under task manager- users
Did the following scans
- Norton Startup scan
- Window defender startup scan (there was no Event ID 1001 file for some reason after I did it 3 times, not sure if it actually finished)
- Malwarebytes deep scan
- MRT full scan
All came back ok apart from the event id 1001 issue mentioned above
I assumed with all these checks that the malware had not successfully installed/infected my pc but want some professional opinion.
I am making this post as I read a Reddit post saying that it is a DLL sideloading malware and assume compromised and to reinstall Windows
I want some suggestions if it is really necessary to reinstall window as I do not have a recent backup and is it just better to reinstall to be on the safe side? Also, if I do go down this route, will a factory reset enough as I don’t have a usb drive to download window on?
Is there any other check I do to confirm?
Also, just curious, what does onedrivepatcher.exe do?
Thanks in advance