What a Trojan is and why it needs to come off your computer

A Trojan is malware that disguises itself as something legitimate — a software update, a document, a game — so you will run it. Once it is on your computer, it can steal passwords, watch what you type, download other malware, or lock your files until you pay. Unlike a virus, a Trojan does not copy itself; it just sits there doing damage until you remove it.

The steps to remove a Trojan depend on whether your antivirus software can still run, whether you can start Windows normally, and how deep the infection goes. Most of the time you can get it off yourself. If your computer will not start or your antivirus is broken, you may need to use a different machine to download a repair tool.

Key Takeaways

  • Run a full scan with your antivirus software first — many Trojans are caught and removed automatically if your antivirus is current.
  • If your antivirus finds nothing but you still suspect a Trojan, download Malwarebytes on a clean computer and transfer it to the infected one to scan in Safe Mode.
  • Safe Mode with Networking lets you run your computer with only essential programs, making it harder for a Trojan to hide or interfere with the scan.
  • If your computer will not start at all, use another computer to create a bootable antivirus tool on a USB drive and scan from outside Windows.
  • After removal, change your passwords from a different device, update Windows and all software, and consider a full backup restore if the Trojan had admin access.

Start with a full antivirus scan in Safe Mode

Before you assume your antivirus missed the Trojan, run a full scan while your computer is in Safe Mode. Safe Mode loads Windows with only the bare minimum — no third-party programs, no startup items — which prevents the Trojan from running and interfering with the scan.

To enter Safe Mode on Windows 10 or 11: restart your computer, and as soon as it starts to boot, press F8 repeatedly until you see the boot menu. Select "Safe Mode with Networking" (the networking part lets you download tools if you need them). On older Windows versions, hold Shift while clicking Restart, then choose Troubleshoot > Advanced Options > Startup Settings, and press 4 or F4 for Safe Mode.

Once you are in Safe Mode, open your antivirus software and run a full system scan. This scan checks every file on your computer, not just the ones you use often. It takes 30 minutes to an hour. If your antivirus finds the Trojan, it will quarantine it (move it to a locked folder where it cannot run) or delete it. Restart your computer normally when the scan finishes.

Use Malwarebytes if your antivirus finds nothing

If your antivirus ran a full scan and found nothing, but you still see signs of a Trojan — strange pop-ups, programs opening on their own, your computer running slowly — download Malwarebytes and run it in Safe Mode. Malwarebytes is a second-opinion scanner that catches Trojans your main antivirus might have missed.

Download Malwarebytes on a different computer (one you trust), transfer it to a USB drive, and plug the USB into the infected computer while it is in Safe Mode with Networking. Run the installer from the USB, then run a full scan. Malwarebytes will show you what it finds and give you the option to remove it. The free version is enough for a one-time scan.

After Malwarebytes finishes, restart your computer normally and run your regular antivirus scan again. Two scans from different tools give you much better confidence that the Trojan is gone.

Create a bootable antivirus tool if Windows will not start

If your computer will not start Windows at all — you see a black screen, error messages, or it restarts over and over — the Trojan may have damaged critical files. In this case, you need to scan from outside Windows using a bootable tool.

On a working computer, download Kaspersky Rescue Disk (free) or Bitdefender Rescue Environment (free). Both are bootable antivirus tools that run from a USB drive without needing Windows. Plug a USB drive into the working computer, download the tool, and follow the instructions to write it to the USB. Then plug the USB into the infected computer, restart it, and press F12 or Delete (depending on your computer brand) to boot from the USB instead of the hard drive.

The bootable tool will scan your entire hard drive from outside Windows, where the Trojan cannot hide or interfere. This takes longer — often 1 to 2 hours — but it is the most thorough method. When the scan finishes, remove the USB and restart normally. If Windows still will not start, the Trojan may have corrupted system files beyond what a scan can fix, and you may need to reinstall Windows.

Change your passwords and check for damage

Once the Trojan is removed, assume it saw your passwords while it was on your computer. Change the passwords for your email, banking, social media, and any other important accounts — but do it from a different device (your phone, a tablet, or another computer) in case the Trojan is still hiding.

Check your email account for forwarding rules or recovery email addresses that the Trojan may have added. Log into your email settings, look for "Forwarding" or "Forwarded Emails," and delete any rules you did not create. Check the recovery email and phone number on file — if they are not yours, change them immediately.

If the Trojan had admin access (which many do), it may have created a hidden user account on your computer. Open Settings > Accounts > Other People and look for accounts you do not recognize. Delete any unfamiliar accounts. Also check Windows Defender Firewall settings to make sure the Trojan did not disable it.

Update Windows and all your software

Trojans often get onto your computer through outdated software — old versions of Java, Adobe Reader, or Windows itself have security holes that malware exploits. After removal, close those holes so another Trojan cannot get in the same way.

Open Settings > Update & Security > Windows Update and install all available updates. Restart when prompted. Then open each program you use regularly — your browser, Office, Adobe products, anything else — and check for updates in the Help or Settings menu. Most programs have an "Check for Updates" option. Install everything.

Turn on automatic updates so you do not have to remember to do this manually. In Windows Settings, go to Update & Security > Windows Update > Advanced Options and toggle "Receive updates for other Microsoft products" on. For third-party software, most modern programs update automatically in the background.

Back up your files and consider a full restore

If the Trojan had admin access and was on your computer for more than a few days, the safest option is to back up your personal files and do a clean Windows reinstall. This removes any hidden malware that the scans might have missed and resets your system to a known-clean state.

Copy your documents, photos, and other personal files to an external hard drive or cloud storage (Google Drive, OneDrive, Dropbox). Do not back up program files or system files — only your personal data. Then go to Settings > System > Recovery > Reset This PC and choose "Remove Everything." This erases Windows and reinstalls it fresh. You will need your Windows product key or a Microsoft account to complete this.

If you do not want to reinstall Windows, at minimum create a full backup of your computer now that it is clean. Use Windows Backup (Settings > System > Backup) or a third-party tool like Acronis or Macrium Reflect. If the Trojan comes back or you suspect new malware, you can restore from this clean backup instead of scanning and hoping.

Frequently Asked Questions

How do I know if I actually have a Trojan and not just a slow computer?

Real signs include programs opening on their own, your browser homepage changing without your action, new toolbars appearing, or your antivirus software being disabled. A slow computer alone is usually not a Trojan — it is often just too many programs running at startup or a full hard drive. Run a full antivirus scan first. If it finds nothing and your computer is still slow, the problem is probably not malware.

Can I remove a Trojan without antivirus software?

Not reliably. Trojans are designed to hide, and finding and deleting them by hand is nearly impossible unless you know exactly what file name to look for. Antivirus software scans thousands of files in seconds and knows what Trojans look like. If your antivirus is broken, download Malwarebytes on another computer and transfer it via USB, or create a bootable antivirus tool.

What if the Trojan comes back after I remove it?

It is probably getting back in through the same hole it used the first time. Update Windows and all your software immediately — that closes most entry points. If it keeps coming back after updates, the Trojan may have created a hidden startup item or scheduled task. In Safe Mode, open Task Scheduler (search for it) and look for unfamiliar tasks, especially ones that run at startup. Delete anything you do not recognize.

Do I need to replace my hard drive after a Trojan infection?

Only if the Trojan physically damaged the drive, which is rare. Most Trojans are just files — they can be scanned and removed. If your computer works normally after removal and a full scan finds nothing, your hard drive is fine. If your computer crashes repeatedly or makes clicking sounds, the drive itself may be failing, but that is a hardware problem, not a Trojan problem.

Is it safe to use my computer while it is being scanned?

No. Close all programs and let the scan run without interruption. If you open files or run programs during a scan, the Trojan may run and interfere with the scan, or the scan may miss files that are in use. A full scan takes time, but running it uninterrupted gives you the best result.