How to recognise and remove a trojan horse infection from your Windows PC
Summary
This guide helps you troubleshoot and resolve: How to recognise and remove a trojan horse infection from your Windows PC. Follow the steps below to fix the issue.
Common Causes
A trojan horse is a type of malicious software that disguises itself as a legitimate programme to trick you into installing it. Once on your system, it can steal sensitive data, open a backdoor for other threats, or give an attacker remote control of your computer. Because trojans are designed to look genuine, infections can go unnoticed for weeks or even months. This guide will walk you through the warning signs to look for, how to remove an infection, and what to do afterwards to keep your Windows PC secure.
Warning Signs of a Trojan Infection
Trojans are built to hide, but they often leave subtle clues. If you notice any of the following behaviours, your PC may be compromised:
- Your computer has become noticeably slower, especially during startup or when opening programmes.
- You see unfamiliar applications installed that you do not remember downloading.
- Your browser homepage or default search engine has changed without your permission.
- Pop-up windows or advertisements appear even when you are not browsing the web.
- Your internet connection is unusually active, even when you are not using the network.
- Friends or colleagues report receiving strange emails or messages from your accounts.
- Your antivirus software has been disabled or will not start.
- Files have gone missing, been renamed, or appear corrupted.
What to Do Before You Begin
- Disconnect from the internet to stop the trojan from communicating with its operator.
- Back up any critical files to an external drive or cloud storage. Do not back up executable files (
.exe) as they may also be infected. - If possible, use a second, known-clean device to download any tools you will need.
Step-by-Step Removal Guide
Step 1: Boot into Safe Mode with Networking
Safe Mode loads Windows with only the essential drivers and services, which prevents most malware from running.
- Click Start, then select Power.
- Hold down Shift and click Restart.
- Choose Troubleshoot, then Advanced options.
- Select Startup Settings, then click Restart.
- After the restart, press 5 or F5 for Safe Mode with Networking.
Step 2: Delete Temporary Files
Removing temporary files can speed up your malware scan and may delete some malicious files that hide in these folders.
- Press
Windows + R, typetemp, and press Enter. - Select all files in the folder and delete them.
- Repeat the process for
%temp%andprefetch.
Step 3: Run Microsoft Defender Offline Scan
Microsoft Defender includes an offline scan that runs outside of Windows, making it harder for malware to hide.
- Open Settings from the Start menu.
- Go to Privacy & security (Windows 11) or Update & Security (Windows 10), then Windows Security.
- Select Virus & threat protection.
- Under Current threats, click Scan options.
- Choose Microsoft Defender Offline Scan and click Scan now.
- Your PC will restart and perform the scan. Follow any prompts to remove detected threats.
Step 4: Use a Second-Opinion Malware Scanner
A second scanner can catch threats that your primary antivirus may have missed. Two reputable free options are Malwarebytes and ESET Online Scanner.
- From another clean device, download the installer from the official website.
- Transfer the installer via USB drive and install it on the infected PC.
- Run a Full Scan rather than a quick scan.
- Quarantine or delete everything the scan identifies as malicious.
- Restart your computer when prompted.
mbsetup.exe to explorer.exe). Some trojans block known security filenames.Step 5: Check Startup Programmes and Scheduled Tasks
Trojans often configure themselves to relaunch on startup. Removing these entries helps ensure the infection does not return.
- Press
Ctrl + Shift + Escto open Task Manager. - Click the Startup apps tab.
- Review the list and disable any unfamiliar or suspicious entries by right-clicking and selecting Disable.
- Open Task Scheduler by searching for it in the Start menu.
- Review scheduled tasks and delete any you did not create or do not recognise.
Step 6: Reset Your Browsers
Many trojans modify browser settings to redirect your searches or inject advertisements.
- Open your browser (for example, Chrome, Edge, or Firefox).
- Navigate to the browser's settings and find the option to Reset settings or Restore to defaults.
- Confirm the reset and restart the browser.
- Remove any unfamiliar extensions or add-ons from the extensions menu.
After the Infection Is Removed
Once your PC is clean, take these steps to close any gaps the trojan may have exploited:
- Change your passwords from a different, trusted device. Start with email, banking, and any account that holds sensitive information. See our guide on password reset (Windows login) for help with your local account password.
- Enable multi-factor authentication on every account that supports it.
- Update Windows by going to Settings > Windows Update and clicking Check for updates. Install all available patches.
- Update your browser and plugins, including Java (if still installed) and PDF readers.
- Review installed programmes in Settings > Apps > Installed apps and uninstall anything unfamiliar.
- Check your email accounts for any forwarding rules or unfamiliar sign-in activity.
Preventing Future Infections
- Keep Windows, your browser, and your antivirus software up to date at all times.
- Do not open email attachments or click links from unknown senders.
- Download software only from official sources. Avoid third-party download sites.
- Be cautious with USB drives from unknown sources.
- Use a standard user account for daily work rather than an administrator account.
- Schedule regular full scans with your antivirus software.
Troubleshooting
The malware keeps coming back after a scan
Some persistent trojans reinstall themselves after removal. In this case:
- Boot into Safe Mode with Networking as described in Step 1.
- Run a full scan with both Microsoft Defender Offline and a second-opinion scanner such as Malwarebytes.
- Use a dedicated removal tool from your antivirus vendor if a specific trojan family has been identified.
- Check Startup programmes, scheduled tasks, and registry run keys for any remaining malicious entries.
- If the infection persists, consider a full system reset or a clean reinstallation of Windows as a last resort. Back up your data first.
The PC will not boot into Safe Mode
If Windows is too damaged to start normally:
- Use the Windows Recovery Environment from a bootable USB or DVD.
- Run Microsoft Defender Offline from the recovery environment.
- Consider using a bootable antivirus rescue disk such as the Kaspersky Rescue Disk or ESET SysRescue.
When to seek professional help
If you are unable to remove the infection, or if the trojan appears to have accessed banking or business systems, contact a professional IT support technician. Do not continue using the device for sensitive transactions until it has been verified as clean.
Still Having Issues?
💻 Open a Ticket