Trojan:O97M/Mountsi.D!ml: what it is and how to remove it
Trojan:O97M/Mountsi.D!ml - heuristic detection name that states about a trojan malware installed. It might be the case that Microsoft Defender or another AV tool or security program mistakenly indicates an infection on the machine that is safe.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If you want to confirm nothing else came with Trojan:O97M/Mountsi.D!ml, a full scan checks the usual places in one pass.
Do it yourself · free Remove Trojan:O97M/Mountsi.D!ml yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Trojan:O97M/Mountsi.D!ml: summary
| Distribution | Threats can spread silently when it comes to trojans and other sneaky viruses. Malicious macros,[1] infected or corrupted files, hacked sites can lead to infiltration of such virus too |
|---|---|
| Name | Trojan:O97M/Mountsi.D!ml |
| Type | Trojan/ false virus detection |
| Issue | The AV program can show such false detections and scare the user without any reason, but serious infections like this can run to damage the machine, steal data, expose the system to more dangerous programs |
| Detection names | No Microsoft detection name is known |
| Damage | Not recorded in the old report |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 5 more facts
| Symptoms | A Windows Security "Threats found" notification |
|---|---|
| Evidence | 4 write-ups by security sites; details still limited |
| First seen | 27 October 2020 |
| Microsoft Defender name | Trojan:O97M/Mountsi.D!ml |
| Facts checked | 6 October 2026 |
What Trojan:O97M/Mountsi.D!ml does on an infected PC
From our report of Oct 2020 · not reviewed since
Trojan:O97M/Mountsi.D!ml is the possible false detection that informs about malware on the computer
Trojan:O97M/Mountsi.D!ml - heuristic detection name that states about a trojan malware installed.
It might be the case that Microsoft Defender or another AV tool or security program mistakenly indicates an infection on the machine that is safe. You should double-check before eliminating any programs or files related to the pop-up alert of the detection.
This Trojan:O97M/Mountsi.D!ml virus is one of many detections that can appear on the screen when your anti-malware tool checks the state of the machine that is possibly infected or affected by the intruder. You should pay close attention to random alerts from AV vendors because, in many cases, these warnings and virus detections are false positives and not related to anything on your particular machine.
When your tool delivers you the message about positive findings, you can rely on the software and remove the threat, but a full scan and double-checking should help you determine if it is really needed.
Trojan:O97M/Mountsi.D!ml is a computer virus that can trigger processes in the background and make changes without your permission or knowledge. The worst thing about such silent intruders as trojans, malware, and worms is the distribution and shady methods of running needed procedures in the machine's background.
You might get exposed to malicious material and find the Trojan:O97M/Mountsi.D!ml installed later on. It happens quickly, and you cannot know when the infiltration happened unless you recall the file you downloaded or the page you already visited.
Malicious files with the payload of this malware can be dropped on the computer by another virus too. You may need to remove Trojan:O97M/Mountsi.D!ml and another program that triggered the infection in the first place. This is why anti-malware tools are needed, and experts recommend keeping such tools on the system and running them more often.
You should avoid these infections as much as possible, but it is not that easily achievable. Trojans can be malware droppers or downloaders and lead to infections of damaging threats like ransomware. Threat behaves as it is coded for, so you might not even notice Trojan:O97M/Mountsi.D!ml, but only encounter the later virus that caused damage.
Make sure that Trojan:O97M/Mountsi.D!ml removal is a process that is needed in the first place. Incompatibility issues can trigger False-positive detection s. Running or a PC tool can help indicate what issues are caused by the infection and other problems that are not related to malware infections.
If you find files, suspicious programs, or different additions on the machine, you should try to determine if the infection alert is really associated with malware pieces like Trojan:O97M/Mountsi.D!ml. You can try to find processes running on resources and files that trigger suspicious behavior. Rely on proper AV tools and security programs before you delete anything from the machine.


From our report of Oct 2020 · not reviewed since
Trojan payload gets dropped directly on the computer
Trojans and other malware that is spreading around using malicious files, shady websites, or other intruders can mask various tasks in the background and hide traces of the infection entirely.
It is designed to use common file types and drop payload files using EXE or DLL files via email attachments and directly from pages and pirated software packages.
Some exploits and vulnerabilities can be used to infect computers with such malware. Remote access tools or scams can be set to result in these trojan attacks too. Internet is not a safe place, so make sure to run security tools more often since malicious emails and even suspicious files can be indicted, and virus infiltration avoided.
From our report of Oct 2020 · not reviewed since
More from our earlier report on Trojan:O97M/Mountsi.D!ml
- You should remove Trojan:O97M/Mountsi.D!ml using a powerful anti-malware tool, so programs can get detected and terminated properly
- Changes in the system can affect the performance of your machine significantly or lead to privacy and security issues, so you should run or a similar application that could help with virus damage
How to check the PC for Trojan:O97M/Mountsi.D!ml
Microsoft's name for Trojan:O97M/Mountsi.D!ml is Trojan:O97M/Mountsi.D!ml.
Defender sorts threats by category first, so the word before the colon tells you what kind of program was found, even if the family name means nothing to you.
Do not search for a removal tool by the detection name alone; fake "removal tools" use the same keywords. How the naming works is explained in our guide to antivirus detection names.
How to remove Trojan:O97M/Mountsi.D!ml
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like Trojan:O97M/Mountsi.D!ml add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after Trojan:O97M/Mountsi.D!ml, its publisher or created on the day the problem started.Delete those folders, and check
C:\Program FilesandC:\Program Files (x86)too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of Trojan:O97M/Mountsi.D!ml that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Trojan:O97M/Mountsi.D!ml can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Manual removal using Safe Mode
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.

- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.
- Go to Advanced options.

- Select Startup Settings.

- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.

Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.

- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.

- Go back to the process, right-click and pick End Task.

- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.

- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.

- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
From our report of Oct 2020 · not reviewed since
You might have difficulty when trying to remove Trojan:O97M/Mountsi.D!ml virus
The process of virus removal is the one that can be controlled by the user when anti-malware tools get used.
Relying on anti-malware software or security programs like and ensures that the system is fully checked and scanned for any threats, possibly running on the machine. You can remove Trojan:O97M/Mountsi.D!ml alongside other related pieces.
Trojan:O97M/Mountsi.D!ml removal or a full scan with an anti-malware tool alone can improve you' performance. Checking for any intruders and removing them automatically can ensure that the state of your PC security is great. Of course, system damage is not pleasant, so repair issues with the machine using , for example.
[GI=method-1]Remove the threat by rebooting the machine in SafeMode with Networking
[GI=method-2]System Restore feature is the one that can help cleaning the machine
After removal: passwords, accounts and prevention
Your passwords after Trojan:O97M/Mountsi.D!ml
Removing Trojan:O97M/Mountsi.D!ml does not undo what it may already have sent out while the PC showed the Windows Security detection Trojan:O97M/Mountsi.D!ml.
Treat saved browser passwords and logged-in sessions on this PC as known to the attacker.
From another device, change the e-mail password first and end all its sessions. Then do the same for the bank, PayPal, Microsoft, Google and Apple accounts. Stolen session cookies keep working after a password change until you sign out everywhere.
Move crypto to a new wallet created on a clean device. A step-by-step order for every kind of account is in our guide to account security after an infection.
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
Questions about Trojan:O97M/Mountsi.D!ml
Defender removed Trojan:O97M/Mountsi.D!ml. Am I safe now?
Often yes, but check two things. First, whether the detection was caught on arrival: a file in Downloads or in an archive that Defender quarantined before it ran is the best case.
Second, whether Trojan:O97M/Mountsi.D!ml comes back. If it returns, or if Protection history shows several different detections around the same date, something on the PC keeps producing the file and needs to be found.
Run a full scan and, if anything remains, an offline scan. If the category names a password stealer or a backdoor, change your passwords from another device even if the file is gone.
Should I change my passwords after Trojan:O97M/Mountsi.D!ml?
It depends on the category and on whether the file ran. If the name begins with PWS, Spy, Backdoor or Trojan and the file sat in AppData, ProgramData or Temp, assume it ran and change your important passwords from a different device, starting with e-mail, then banking.
Sign out of all sessions too. If Trojan:O97M/Mountsi.D!ml is a PUA or was caught in Downloads before you opened anything, a password change is a precaution rather than a must. When in doubt, change the e-mail password and turn on two-step verification; it is quick and protects everything else.
Is Microsoft Defender enough to remove Trojan:O97M/Mountsi.D!ml?
For most home PCs it is a solid first step. Defender detects this threat as Trojan:O97M/Mountsi.D!ml, and a full scan followed by an offline scan covers the places where Trojan:O97M/Mountsi.D!ml usually hides. The offline scan runs before Windows starts, so malware that hides while Windows is running cannot interfere: Run a Microsoft Defender Offline scan.
Defender does not undo everything, though. It does not restore browser settings, decrypt files or change passwords that may have been copied, which is why this guide has separate steps for those. If Defender finds the same item again after removal, something else keeps reinstalling it.
Is it safe to do online banking after seeing the Windows Security detection Trojan:O97M/Mountsi.D!ml?
Not on that PC until it is clean. A program that produces the Windows Security detection Trojan:O97M/Mountsi.D!ml runs with your rights and could read what you type or what the browser shows. Use a phone or another computer for banking and for changing passwords.
When the offline scan of the affected PC is clean and nothing suspicious starts with Windows any more, you can go back to using it. Check your bank statements for the past weeks either way, and call the bank if anything looks unfamiliar; banks can block cards and reset access quickly.
My antivirus was on. How did a trojan get past it?
Antivirus programs see a file only when it is written or run, and criminals test each new build against popular scanners before release. Detection catches up within hours or days, which is often after the first victims ran it.
Archives with passwords, installers that fetch the malware later, and scripts run through PowerShell make the job harder. That is why behaviour such as downloading cracks or pasting commands matters more than any setting. Keep Windows and Defender updated, and turn on Reputation-based protection in App & browser control.
Why can't I find Trojan:O97M/Mountsi.D!ml in antivirus databases?
Because it is new or because it is listed under a different name. Antivirus companies name threats after the family they belong to, and a program that appears as Trojan:O97M/Mountsi.D!ml on your PC may carry a generic or unrelated label in their databases.
Many new samples are first detected only by behaviour, without a family name. What you saw, the Windows Security detection Trojan:O97M/Mountsi.D!ml, is enough to act on:
- end the program
- remove its startup entry
- run a Microsoft Defender offline scan
- secure your accounts
A detection name from a scan is worth noting for later.
I found AnyDesk or ScreenConnect that I did not install. Is that Trojan:O97M/Mountsi.D!ml?
Not necessarily Trojan:O97M/Mountsi.D!ml, but it is a warning sign. These are legitimate remote support tools, and criminals use them as ready-made backdoors, especially after tech support scams or fake invoice calls.
If you did not install it and no one you trust set it up, uninstall it, change passwords from a clean device and check your bank account. If someone connected to your PC through it, follow the steps for remote access trojans and consider a Windows reset. Installed apps sorted by date shows when it appeared.
How do I know if my PC has Trojan:O97M/Mountsi.D!ml?
Often you do not, which is the point of a trojan. Possible signs are an antivirus alert naming Trojan:O97M/Mountsi.D!ml or a generic trojan detection, unknown programs or scheduled tasks, processes with random names in Task Manager, browser extensions you did not add, security settings turned off, slower performance, or account alerts about logins from unknown places.
The reliable check is a full scan followed by Microsoft Defender's offline scan. If you recently ran a crack, a fake installer or a command a website told you to paste, scan even without symptoms.
Do I need to reinstall Windows to get rid of Trojan:O97M/Mountsi.D!ml?
Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see the Windows Security detection Trojan:O97M/Mountsi.D!ml again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.
Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.
Will Fortect remove Trojan:O97M/Mountsi.D!ml?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Trojan:O97M/Mountsi.D!ml, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Wikipedia: Malicious macros (read October 6, 2026)
- Webroot: What is a Computer Virus and What Does It Do? (read October 6, 2026)
- FTC: How to recognize, remove and avoid malware (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 6, 2026)
- Microsoft Learn: How Microsoft names malware (read October 6, 2026)