cant remove oneetx.exe

Status
Not open for further replies.

dongxi

New Member
Thread author
Apr 4, 2023
3
Hello,

Yesterday I downloaded : href.li
just 18MB but when unzip is 1.38GB cant put it on virustotal.... and I scanned with malwarebytes (free version) with no harm... but now my conputer very slow and when open browser it always open 30 process of browser.

I'm try to Google oneetx.exe its russian botnet from 2018...and deleted this file but I can't fully remove all
 
Last edited by a moderator:

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Attach Files.
Navigate to the location of the File.
Click the file. It will appear in the reply section.
Click the Post Reply button.

Please post the logs for my review.

Let me know what problems persists.

Wait for further instructions
 

dongxi

New Member
Thread author
Apr 4, 2023
3
Hi,
now I open browser like firefox, chrome....its auto opens to many process up to 30 ..what should i do to normal again

update : i used hjackthis to remove it this is backup file
1680620471137.png
 

Attachments

  • Addition.txt
    66.5 KB · Views: 12
  • FRST.txt
    58.6 KB · Views: 13
Last edited:

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Would you by any chance know what this installed program comes from?
If you decide to remove it use this method.
Remove this program in bold using the Control Panel > Programs > Programs and Features...
жÔØ¡¶Ãû½«Èý¹ú¡· (HKLM-x32\...\{BEF8B702-32EA-40D8-9538-FCC9DCFA6F0B}) (Version: - ±±¾©ÈñÎҿƼ¼ÓÐÏÞ¹«Ë¾)

Cracked/warez versions of programs

Cracked/warez versions of programs sound "good" and "cheap", but they can cause all sorts of headaches for you and damage to your computer. No reputable forum will support any method of cracking, warez, workarounds, providing any methods, tools, or posting of links designed for this express purpose.

There are people who have spent a great deal of money on developing and testing hardware and software, marketing and distributing it, and then on education and support for it. They have spent long, tedious, difficult and brain-numbing days/nights on their endeavor. They are attempting to make an honest living and feed their families.

Let's not support the thieves who rip them off and cheat them out of the fruits of their labor.
IDM 6.39 build 8 6.39.8 (HKLM-x32\...\IDM 6.39 build 8 6.39.8) (Version: 6.39.8 - CrackingPatching)
You should remove this program in bold using the Control Panel > Programs > Programs and Features...
<<<>>>

The Fix suggested will not create a restore point before proceeding.
You need at least 6% of free space to do it.
ATTENTION: System Restore is disabled (Total:222.92 GB) (Free:5.55 GB) (2%) you only have 2%.

I hope you can delete or transfers some important files to an Eternal Driver before you can proceed.
If something goes wrong with this fix you will not be able to retore your system to a time prior to you proceeding with the fix.

Presently your Windows Firewall is disabled. As well as your Windows Updates.
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
Windows updates is not able to proceed as it creates a Restore point before proceeding.
<<<>>>

The suggested fix.

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • Fixlist.txt
    9.4 KB · Views: 13

dongxi

New Member
Thread author
Apr 4, 2023
3
Hi,
Thank you so much.

жÔØ¡¶Ãû½«Èý¹ú¡· << this is game from Insert title here ( removed)
 

Attachments

  • Fixlog.txt
    159.2 KB · Views: 10
Last edited by a moderator:

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

My apologies for this late reply.
I leave in the Westend of Montreal, Quebec Canada and I lost the power to my home due to an Ice Storm from Wednesday night on the 5th of April . I stayed in a Hotel and got back when the power was restored late this Monday Afternoon.

Any remaining issues?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top