How to Remove a Trojan from a Cached OneNote Notebook
Question details
The user needs to remove a Trojan or malware threat that their antivirus software detected within an embedded file, attachment, or local cache of a Microsoft OneNote notebook.

- Product
- Microsoft OneNote
- Device & OS
- Windows
- Scenario
- Antivirus software alerts the user about a Trojan infection linked to a Microsoft OneNote cache file or notebook attachment.
- Observed behavior
- The malware threat is persistently stored in the synchronized notebook cache or an embedded attachment rather than the main OneNote application executable, causing recurring security alerts.
Before proceeding, ensure your device's antivirus software is fully up to date and temporarily disconnect from the internet to prevent the infected notebook from synchronizing further.
Clear Local Cache and Remove Infected Cloud Attachments
Delete the local OneNote cache to clear the immediate threat from your computer, then locate and delete the malicious attachment from a safe cloud version of your notebook.
Since OneNote does not execute HTML or script languages directly, the Trojan is almost certainly hidden inside an embedded file or attachment. Deleting the cache removes the offline copy, but you must still clean the synchronized cloud notebook to prevent reinfection.
Ensure Microsoft OneNote is completely closed on your computer so that the cache files are not locked by the application.
Press Windows + R to open the Run dialog box. Type the path C:\Users\<user>\AppData\Local\Microsoft\OneNote\16.0\cache (replacing <user> with your actual Windows username) and press Enter.
Select all files within the cache folder and permanently delete them. OneNote will automatically recreate this folder the next time you launch the application.
Using a protected and fully updated device, log into OneNote via your web browser to access a safe copy of your cloud notebook.
Carefully inspect your sections, pages, embedded files, and attachments. Scan downloaded attachments individually, locate the infected content, and delete it from the cloud notebook before resynchronizing.

Try WPS Office for Secure and Lightweight Document Management
If you are dealing with persistent caching issues or complicated file management in Microsoft Office, consider switching to WPS Office. It is a highly compatible, secure, and lightweight alternative that simplifies managing Word, Excel, PowerPoint, and PDF files seamlessly.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the Suite: Run the installer and follow the simple on-screen instructions to set up the software on your device.
- 3. Open Your Documents Securely: Launch WPS Office and securely open your existing Word, Excel, PowerPoint, or PDF files to continue working immediately.

Frequently Asked Questions
Can OneNote execute viruses or macros directly?
No, OneNote cannot execute HTML or script languages directly and does not support VBA macros. The threat is almost always stored within an embedded file or attachment inserted into a notebook page.
Will deleting the OneNote cache delete my synced notes?
Deleting the local cache only removes the offline copy of your notebooks from your hard drive. Any notes that have been successfully synced to the cloud (OneDrive) will remain safe and will re-download when you open OneNote.
Why does my antivirus flag OneNote cache files?
When you sync a notebook containing a malicious attachment, OneNote downloads and stores a local copy of that attachment in its cache directory. Your antivirus scans this directory and correctly identifies the hidden threat within the cached file.




