Skip to content
RU
← All articles

What Is a Trojan? How It Works and How to Remove One

An antivirus quarantine window with a detected threat beside a USB drive and a phone

What is a Trojan? A Trojan, or Trojan horse, is malware disguised as something you want — a cracked app, an invoice, a browser update — that quietly works for an attacker once you run it: stealing passwords, opening remote access or pulling down more malware. Unlike a true virus, it does not copy itself; you launch it.

What a Trojan is — and why "Trojan virus" is a misnomer

The name comes from the wooden horse of Greek legend: a gift on the outside, soldiers on the inside. The defining trait of a Trojan is not what it does but how it gets in — by deception. It rides on a file that looks legitimate, and the user grants it exactly the permissions their own account has.

People say "Trojan virus" all the time, but technically the two are different. A virus infects other files and spreads when they run; a worm scans networks and copies itself to vulnerable machines. A Trojan does neither. That distinction matters in practice: patching stops worms well, but no patch stops a person from double-clicking Setup_Full_Crack.exe. MITRE ATT&CK catalogues this disguise as Masquerading (T1036).

What does a Trojan do?

"Trojan" describes the delivery, not the payload. Depending on what is packed inside, it may:

  • harvest browser passwords, session cookies, crypto wallet files and saved FTP or SSH credentials;
  • give an attacker live control of the machine — screen, files, shell, sometimes webcam;
  • download and run whatever the operator is selling access to this week: ransomware, a coin miner, adware;
  • enrol the device in a botnet that sends spam, launches DDoS attacks or relays other people's traffic;
  • on phones, intercept SMS one-time codes and draw fake login screens over banking apps.

How Trojans get onto a computer

  • Pirated software, keygens and "activators". The single most reliable infection route, and the installer usually asks you to disable your antivirus first.
  • Email attachments. Password-protected ZIPs (the mail gateway cannot scan inside), ISO and IMG images, LNK shortcuts, macro-enabled documents and double extensions like invoice.pdf.exe. Turn on file extensions: in Windows 11, File Explorer → View → Show → File name extensions.
  • Fake update prompts. A compromised website overlays "Your browser is out of date" and serves an installer. Chrome, Edge, Firefox and Safari update themselves; they never ask you to download an update from a random page.
  • Malicious search ads. A sponsored result leads to a pixel-perfect copy of a popular tool's download page with a trojanized installer.
  • Sideloaded Android apps — APK files sent in messages or hosted outside Google Play.

Types of Trojans

Security vendors group Trojans by their main behaviour. Real samples often combine several roles, so treat the categories as labels, not boxes.

TypeWhat it doesWhat you might notice
BackdoorKeeps a hidden, persistent way back into the systemUnknown services or scheduled tasks, outbound connections to odd hosts
RAT (Remote Access Trojan)Full remote control: desktop, files, keystrokes, cameraCursor moving on its own, camera light, unexpected windows
InfostealerGrabs passwords, cookies and wallets, exfiltrates them in secondsOften nothing — until your accounts are taken over
Banking TrojanInjects fake forms, swaps payment details, intercepts codesYour bank "asks again" for card data; codes you did not request
Downloader / loaderFetches and runs other malware from a remote serverNew detections keep appearing after the first one
DropperCarries an embedded payload and writes it to diskNew executables in %AppData% or %Temp%
MinerSpends your CPU or GPU on cryptocurrencyFans and CPU busy while the machine is idle
RansomwareEncrypts files and demands paymentRenamed files and a ransom note

How to read a detection name like Trojan:Win32/Wacatac.B!ml

Microsoft Defender names follow Type:Platform/Family.Variant!Suffix. Here, Trojan is the category, Win32 the Windows executable platform, Wacatac the family, and !ml means a machine-learning model flagged the file rather than an exact signature. Generic, heuristic and ML verdicts are the ones most likely to be false positives, so a disputed file deserves a second opinion from other engines before you panic — or before you trust it.

Trojan vs virus vs worm

TrojanVirusWorm
How it spreadsDeception — the user runs itAttaches to other files and runs with themExploits vulnerabilities across the network
Needs a host fileNo, it is a standalone programYesNo
Self-replicatesNoYes, within a systemYes, between systems
Best defenceCareful downloads, antivirus, non-admin accountsAntivirusPrompt patching, firewalling

Real-world malware blurs the lines. WannaCry was ransomware that spread like a worm over SMB; Emotet began as a banking Trojan and evolved into a loader that rented access to other gangs.

Signs your computer has a Trojan

  • High CPU or GPU load at idle that drops the moment you open Task Manager — a known miner trick.
  • Your antivirus is switched off, will not update, or security vendors' websites fail to load.
  • Unfamiliar browser extensions, a new homepage or a changed default search engine.
  • Login alerts from devices you do not own; contacts receiving links "from you".
  • Startup entries or scheduled tasks with random names running files from %AppData% or %Temp%.

The absence of symptoms proves nothing. An infostealer can run for a few seconds, ship everything it found and delete itself.

How to remove a Trojan from Windows 10 or 11

  1. Disconnect from the network to cut the command-and-control channel. Download any tools on a clean device, or reconnect only while updating definitions.
  2. Run a full Defender scan from an elevated PowerShell:
    Update-MpSignature
    Start-MpScan -ScanType FullScan
    Get-MpThreatDetection
    The classic equivalent is "%ProgramFiles%\Windows Defender\MpCmdRun.exe" -Scan -ScanType 2; all switches are in the Microsoft documentation.
  3. Run an offline scan. Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus (offline scan), or Start-MpWDOScan. The PC reboots and scans before Windows loads, which catches rootkits that hide from a running system.
  4. Get a second opinion with an on-demand scanner that does not replace your antivirus: Microsoft Safety Scanner (it expires ten days after download, so always fetch a fresh copy) or the free version of Malwarebytes. Download only from the vendor's own site.
  5. If the Trojan blocks your tools, boot into Safe Mode: Settings → System → Recovery → Advanced startup → Restart now, then Troubleshoot → Advanced options → Startup Settings → Restart, and press 4 (Safe Mode) or 5 (Safe Mode with Networking).
  6. Audit persistence by hand. Sysinternals Autoruns lists every autostart location; enable Options → Hide Microsoft Entries and look hard at unsigned items. For scheduled tasks:
    Get-ScheduledTask | Where-Object {$_.State -ne 'Disabled'} | Select-Object TaskPath, TaskName
  7. Check live connections with netstat -ano, then map a PID to its program with tasklist /fi "PID eq 1234".

When to wipe instead of clean

Antivirus removes the Trojan's files, not necessarily everything it did — new local accounts, changed settings, secondary payloads. If the detections included a backdoor, RAT or rootkit and the infected account had admin rights, back up documents (never executables), scan them, and rebuild the system from scratch. On company machines, that call belongs to the security team, and it usually needs investigation rather than just cleanup; see EDR vs antivirus for the tooling side.

Trojans on Android and iPhone

On Android, boot into safe mode (on most models, hold the power button, then long-press Power off), uninstall recently added apps from outside Google Play, and revoke device-admin rights from anything that refuses to uninstall — usually under Settings → Security → Device admin apps, though the path varies by manufacturer. Check Accessibility for services you did not enable, then run Play Store → profile icon → Play Protect → Scan. A factory reset is the fallback.

On a non-jailbroken iPhone, apps come only from the App Store, so classic Trojans are rare. The more common problem is a configuration profile someone talked you into installing: review Settings → General → VPN & Device Management.

After removal: passwords and sessions

This is the step most people skip. An infostealer takes session cookies as well as passwords, and a stolen cookie lets an attacker into your account without a password or a second factor. So:

  • change passwords from a different, clean device, starting with email, since every other account resets through it;
  • sign out of all other sessions — in a Google account under Security → Your devices, in Telegram under Settings → Devices → Terminate all other sessions;
  • turn on two-factor authentication wherever it was missing;
  • move crypto funds to a new wallet created on a clean device;
  • rotate hosting, FTP and admin-panel credentials if they were ever used from that machine — then check whether your old passwords were already exposed, as described in how to check if a password was leaked.

Trojans on websites: web shells and injected scripts

Servers get their own Trojans. Through a vulnerable CMS plugin or stolen hosting credentials — frequently lifted by an infostealer from the admin's laptop — an attacker uploads a web shell, a small PHP script that runs commands on the server from a browser. It survives the original bug being patched. The other family is injected code: scripts that redirect mobile visitors to scams, show fake browser-update pages, add hidden spam links or skim card data from checkout forms. Many only fire for search-engine visitors, so the owner never sees them.

With shell access, a first sweep looks like this:

# PHP files modified in the last 7 days
find /var/www -name "*.php" -mtime -7 -ls

# common obfuscation patterns in web shells
grep -rlE "eval\(base64_decode|gzinflate\(base64_decode|assert\(\$_(POST|GET|REQUEST)" /var/www

# executable PHP has no business in an uploads folder
find /var/www -path "*/uploads/*" -name "*.php"

Treat hits as leads to read, not files to delete blindly — legitimate code occasionally uses the same constructs. If the compromise is confirmed, follow what to do in the first hour after a hack.

How to check a site or a file

Frequently asked questions

Can antivirus miss a Trojan?

Yes. Attackers repack samples so they match no known signature, and a fresh build can go undetected for hours or days. That is why an offline scan, a second scanner and a re-scan a few days later are worth the effort.

Can I get a Trojan just by visiting a website?

With an up-to-date browser, rarely — it takes an unpatched exploit. Far more often the site talks you into downloading and running something: an "update", a "codec", a "document". Until you run it, it does nothing.

Does resetting or reinstalling Windows remove a Trojan?

A clean reinstall that formats the system drive removes it in practically all cases — unless you restore an infected file from backup afterwards. It does not undo what was already stolen, so passwords and sessions still need resetting.

Is a downloaded but unopened Trojan dangerous?

A file sitting on disk does nothing by itself. Delete it; if you are unsure whether it was run, do a full scan.

Do Macs get Trojans?

Yes. Fake installers and cracked apps work on macOS as well; Gatekeeper and XProtect block known samples, but a user who overrides the warning can still run one.

Check your website right now

Check your site's security →
More articles: Security
Security
How to Check a Website for Malware: 4 Layers and a Cleanup
01.04.2026 · 1 217 views
Security
Cookie Security Flags: HttpOnly, Secure, SameSite
14.03.2026 · 621 views
Security
Web Server Security Hardening Checklist: Nginx and Apache
16.03.2026 · 616 views
Security
How to Check a Website for Fraud: 12 Signs of a Phishing Site
18.07.2026 · 524 views