Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Dec 06, 2018 | Updated Jan 09, 2022

TrojanDownloader:O97M/Obfuse

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Microsoft Defender Antivirus detects and removes this threat.

This threat is associated with the distribution of banking trojans like Emotet, Trickbot, or Qakbot that typically spreads through phishing emails with malicious attachments.

Read the following Microsoft security blogs:

Microsoft Defender Antivirus  automatically removes threats as they are detected. If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.

  • Run a full antivirus scan on the device.
  • Check the source of infection through the device timeline, as the trojan might have entered via direct link download in an email or via a malicious Office document.
  • Turn off Microsoft Office macros, and enforce “Protected View” if possible because this threat often takes advantage of the ability to socially engineer users into clicking "Enable Macros" or to not enable “Protected View” as a way to launch arbitrary code.
  • Remove admin privileges where possible, as this trojan often misuses administrative privileges to turn off antivirus software using native OS commands.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us