What is onenote.exe?
onenote.exe is a legitimate process file popularly known as Microsoft Office OneNote application. It is associated with Microsoft Office OneNote, developed by Microsoft Corporation. It is located in C:\Program Files by default. Malware programmers create files with virus scripts and name them after onenote.exe with an intention to spread virus on the internet.
Affected Platform: Windows OS
How to check if your computer is infected with onenote.exe malware?
Keep an eye for the following symptoms to see if your PC is infected with onenote.exe malware:
- Internet connection fluctuates
- onenote.exe takes too much CPU space
- PC slows down significantly
- Browser automatically redirects to some irrelevant websites
- Unsolicited ads and popups starts appearing
- Screen freezes constantly
Take the following steps to diagnose your PC for possible onenote.exe malware attack:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside C:\Program Files, then you should run an antivirus scan to get rid of the malware.
How to remove onenote.exe malware from system using Comodo Free Antivirus?
Step 1: Download the award-winning Comodo Antivirus.
Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.
Step 3: After network detection is complete, press “Close” button for a scan window.
Step 4: Restart your PC.
Step 5: It will take some time for the Comodo Internet Security to update the antivirus.
Step 6: Proceed with a quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be prompted with an alert screen.
Step 8: Comodo Antivirus will remove onenote.exe malware from your computer including all other malwares!
| No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Executable | 9797e824b07daa7e 528a7164cd8a39db 99562dfc |
f509f60916829cd5 e7c4bac046986b5c |
Unclassified Malware |
No | 12.0.4518. 1014 |
12.0.4518. 1014 |
Italy |
N/A |
| 2 | N/A | Executable | 7df347853ce463ad f741a081f884e81e 38261673 |
be8a82cedd33fe48 ee3417b19ff68273 |
Virus.Win32. Ramnit.K |
No | 8.01.0008 | 8.01.0008 | Turkey |
N/A |
| 3 | Microsoft Corporation | Executable | 77cc52d5cb8fd348 9e3d7a402894b349 2eb245c7 |
85d42a4d84c2f260 8492f9341d32e361 |
Virus.Win32. Sality.gen |
No | 14.0.4763. 1000 |
14.0.4763. 1000 |
197.144.36.1/32 |
N/A |
| 4 | N/A | Executable | 38bdd3ea46fc970e 812038ca11d13894 528e320c |
3e2173d5258c828e ff545657cef6bcf2 |
Virus.Win32. Sality.gen |
No | N/A | N/A | Egypt |
N/A |
| No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Executable | a81233878a8f4847 2f71921635803e50 b0829568 |
657df601ce24bcbb 53f92e61627e7459 |
Yes | 16.0.17628 .20144 |
16.0.17628 .20144 |
104.238.128.144/32 |
| 2 | Microsoft Corporation | Executable | 30379c0b031b470a fad4fac3e8b0ec10 aef4fdfd |
5ef3e8d764dce846 722655d38bcc403e |
Yes | 16.0.15225 .20288 |
16.0.15225 .20288 |
10.224.25.61/32 |
| 3 | Microsoft Corporation | Executable | 5b0b2e854f3f66ac 066642b994822776 8d391d4c |
a1ff7b29e39c85ca b79d9665650f3ddc |
Yes | 14.0.4763. 1000 |
14.0.4763. 1000 |
10.224.1.59/32 |
| 4 | Microsoft Corporation | Executable | b91fad7dc4574c5b ae1bc655b6c1afc0 37975b9b |
b4cebbfc5502f528 59d31c2a365600ee |
Yes | 14.0.6022. 1000 |
14.0.6022. 1000 |
10.224.1.65/32 |
- 4 items per page
- 8 items per page
- 16 items per page
- 32 items per page

Italy
Turkey
197.144.36.1/32
Egypt
Brazil
United States
Botswana
Indonesia
Canada
Russian Federation
India
Japan
Philippines
Romania
Europe
Thailand
