Home › Knowledgebase › KB-426

How to recognise and remove a trojan horse infection from your Windows PC

Summary

This guide helps you troubleshoot and resolve: How to recognise and remove a trojan horse infection from your Windows PC. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

A trojan horse is a type of malicious software that disguises itself as a legitimate programme to trick you into installing it. Once on your system, it can steal sensitive data, open a backdoor for other threats, or give an attacker remote control of your computer. Because trojans are designed to look genuine, infections can go unnoticed for weeks or even months. This guide will walk you through the warning signs to look for, how to remove an infection, and what to do afterwards to keep your Windows PC secure.

Warning Signs of a Trojan Infection

Trojans are built to hide, but they often leave subtle clues. If you notice any of the following behaviours, your PC may be compromised:

Important: If you suspect a trojan infection, avoid logging into banking, email, or any account containing sensitive information until the threat has been removed. An attacker may be monitoring your activity in real time.

What to Do Before You Begin

Step-by-Step Removal Guide

Step 1: Boot into Safe Mode with Networking

Safe Mode loads Windows with only the essential drivers and services, which prevents most malware from running.

  1. Click Start, then select Power.
  2. Hold down Shift and click Restart.
  3. Choose Troubleshoot, then Advanced options.
  4. Select Startup Settings, then click Restart.
  5. After the restart, press 5 or F5 for Safe Mode with Networking.

Step 2: Delete Temporary Files

Removing temporary files can speed up your malware scan and may delete some malicious files that hide in these folders.

  1. Press Windows + R, type temp, and press Enter.
  2. Select all files in the folder and delete them.
  3. Repeat the process for %temp% and prefetch.

Step 3: Run Microsoft Defender Offline Scan

Microsoft Defender includes an offline scan that runs outside of Windows, making it harder for malware to hide.

  1. Open Settings from the Start menu.
  2. Go to Privacy & security (Windows 11) or Update & Security (Windows 10), then Windows Security.
  3. Select Virus & threat protection.
  4. Under Current threats, click Scan options.
  5. Choose Microsoft Defender Offline Scan and click Scan now.
  6. Your PC will restart and perform the scan. Follow any prompts to remove detected threats.

Step 4: Use a Second-Opinion Malware Scanner

A second scanner can catch threats that your primary antivirus may have missed. Two reputable free options are Malwarebytes and ESET Online Scanner.

  1. From another clean device, download the installer from the official website.
  2. Transfer the installer via USB drive and install it on the infected PC.
  3. Run a Full Scan rather than a quick scan.
  4. Quarantine or delete everything the scan identifies as malicious.
  5. Restart your computer when prompted.
Tip: If the malware prevents you from installing or running security software, try renaming the installer file (for example, from mbsetup.exe to explorer.exe). Some trojans block known security filenames.

Step 5: Check Startup Programmes and Scheduled Tasks

Trojans often configure themselves to relaunch on startup. Removing these entries helps ensure the infection does not return.

  1. Press Ctrl + Shift + Esc to open Task Manager.
  2. Click the Startup apps tab.
  3. Review the list and disable any unfamiliar or suspicious entries by right-clicking and selecting Disable.
  4. Open Task Scheduler by searching for it in the Start menu.
  5. Review scheduled tasks and delete any you did not create or do not recognise.

Step 6: Reset Your Browsers

Many trojans modify browser settings to redirect your searches or inject advertisements.

  1. Open your browser (for example, Chrome, Edge, or Firefox).
  2. Navigate to the browser's settings and find the option to Reset settings or Restore to defaults.
  3. Confirm the reset and restart the browser.
  4. Remove any unfamiliar extensions or add-ons from the extensions menu.

After the Infection Is Removed

Once your PC is clean, take these steps to close any gaps the trojan may have exploited:

Caution: If the trojan had access to your system for an extended period, assume that any credentials stored in browsers, email clients, or password managers may be compromised. Treat them as exposed and change them immediately.

Preventing Future Infections

Troubleshooting

The malware keeps coming back after a scan

Some persistent trojans reinstall themselves after removal. In this case:

  1. Boot into Safe Mode with Networking as described in Step 1.
  2. Run a full scan with both Microsoft Defender Offline and a second-opinion scanner such as Malwarebytes.
  3. Use a dedicated removal tool from your antivirus vendor if a specific trojan family has been identified.
  4. Check Startup programmes, scheduled tasks, and registry run keys for any remaining malicious entries.
  5. If the infection persists, consider a full system reset or a clean reinstallation of Windows as a last resort. Back up your data first.

The PC will not boot into Safe Mode

If Windows is too damaged to start normally:

When to seek professional help

If you are unable to remove the infection, or if the trojan appears to have accessed banking or business systems, contact a professional IT support technician. Do not continue using the device for sensitive transactions until it has been verified as clean.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket