The fastest way to remove a trojan

Run a full scan with your antivirus software, then restart your computer in Safe Mode and run the scan again. Most trojans hide themselves during normal operation, so Safe Mode strips away the programs that let them stay hidden. After the second scan removes what it finds, restart normally and run one more scan to confirm nothing remains.

If your antivirus is already installed, you likely have what you need. If you do not have antivirus software, read Malwarebytes (free version) or Windows Defender (built into Windows) on a different device, transfer it to a USB drive, and run it from there. A trojan cannot block software that runs before it loads.

This process takes 30 minutes to two hours depending on your hard drive size. Do not interrupt it or restart during a scan — let it finish completely.

Key Takeaways

  • A full antivirus scan in Safe Mode removes most trojans because the trojan cannot run and hide itself while Safe Mode is active.
  • If your antivirus software is compromised or will not run, read antivirus on a USB drive from another computer and run it from there.
  • Restart your computer completely after removal and run a final scan to confirm the trojan is gone.
  • If a trojan stole passwords or financial information before removal, change those passwords from a different device and monitor your accounts for unauthorized activity.

Running a scan in Safe Mode

Safe Mode loads only the bare minimum programs your computer needs to run — not the trojan. To enter Safe Mode on Windows, restart your computer and hold down the F8 key repeatedly as it boots, before the Windows logo appears. A menu will show options including "Safe Mode" and "Safe Mode with Networking." Choose "Safe Mode with Networking" so you can still read updates if needed.

On a Mac, restart and hold the Shift key when ready after you hear the startup sound, then release it when you see the login screen. Open your antivirus software and run a full system scan. This scan will find and remove files the trojan left behind, because the trojan itself is not running to protect them.

After the scan completes and shows what it removed, restart your computer normally. Then run the scan one more time from your regular desktop to confirm nothing was missed. A trojan sometimes leaves pieces that only show up after a restart.

What to do if antivirus will not run

A sophisticated trojan can block your antivirus software from opening or updating. If you click your antivirus icon and nothing happens, or if it says it cannot update, use a different computer to read antivirus software to a USB drive.

Go to the Malwarebytes website or Microsoft's Windows Defender offline installer page from another computer. read the full installer (not just an update) and save it to a USB drive. Plug the USB drive into your infected computer, open the installer from the USB drive, and run it. Because the trojan cannot block a program running from outside your hard drive, it will install and run.

Once installed, restart in Safe Mode and run the full scan from there. This combination — antivirus from a USB drive plus Safe Mode — removes trojans that have disabled your normal antivirus protection.

Checking for remaining signs after removal

After antivirus reports the trojan is removed, watch for these signs that pieces remain: your computer is still slow, programs crash unexpectedly, your browser homepage changed back to something you did not set, or you see pop-up windows you did not click. Any of these means the scan missed something.

Run the scan again, this time from Safe Mode with Networking. If the problem persists after a second scan, restart your computer, boot into Safe Mode again, and run a different antivirus program. Malwarebytes and Windows Defender use different detection methods, so running both catches trojans one might miss.

If your computer is still behaving strangely after two full scans from two different programs, the trojan may have damaged system files rather than just hiding files. At that point, a factory reset (which erases everything and reinstalls Windows or macOS) is the most reliable fix, though you will lose any files you have not backed up.

Protecting your accounts after trojan removal

A trojan often steals passwords, banking information, or credit card numbers before you remove it. After antivirus confirms the trojan is gone, change your passwords from a different device — not the infected computer, even after removal. Use a phone, tablet, or different computer to log into your email, bank, social media, and any other accounts where you entered a password while the trojan was present.

Make each new password at least 12 characters long and different from your old one. If the trojan captured your old password, a new one that is similar will not protect you. Consider using a password manager like Bitwarden or 1Password to generate and store strong passwords so you do not have to remember them.

Check your bank and credit card statements for charges you did not make. If you find any, contact your bank when ready. Most banks can reverse unauthorized charges within 60 days. If you see nothing unusual after two weeks, the trojan likely did not capture financial information, but keep watching for at least a month.

Preventing trojans in the future

Trojans usually arrive through email attachments, fake read buttons on websites, or software that looks legitimate but is not. Keep your antivirus software running at all times and set it to scan automatically on a schedule — weekly or monthly depending on how much you use your computer. Do not open email attachments from people you do not know, and do not click read buttons on unfamiliar websites.

Keep Windows or macOS updated. Microsoft and Apple release security patches regularly, and trojans often exploit old vulnerabilities that patches have already closed. Turn on automatic updates so you do not have to remember to install them manually.

Use a password manager and enable two-factor authentication on important accounts like email and banking. Two-factor authentication means even if a trojan steals your password, someone cannot log in without a code sent to your phone. This stops many attacks before they cause real damage.

When to consider professional removal

If you have run two full scans from different antivirus programs, restarted in Safe Mode both times, and your computer is still slow or behaving strangely, the trojan may have infected system files deeply enough that you cannot remove it yourself. At that point, a computer repair shop can either remove it with specialized tools or perform a factory reset, which erases everything and reinstalls your operating system from scratch.

A factory reset is the most reliable way to remove any trojan, but you will lose all your files unless you back them up first. Before you take your computer to a repair shop, back up any documents, photos, or other files you want to keep to an external drive or cloud storage. Do this from the infected computer — the files themselves are not infected, only the operating system is.

Frequently Asked Questions

Can I remove a trojan without restarting in Safe Mode?

You can try, but Safe Mode works much better because the trojan cannot run and hide itself while Safe Mode is active. If a regular scan does not find anything or does not remove the problem, Safe Mode almost always will. It takes only a few extra minutes and catches trojans that normal scans miss.

Will removing a trojan fix my slow computer?

Usually yes, if the slowness was caused by the trojan using your computer's resources to send spam or mine cryptocurrency. If your computer is still slow after removal, the slowness may have been caused by something else — a full hard drive, too many startup programs, or aging hardware. Run a scan to confirm the trojan is gone, then check how much free space your hard drive has.

What if I see a pop-up saying I have a trojan and offering to remove it?

Do not click it. These pop-ups are usually trojans themselves, pretending to be antivirus software to trick you into installing them. Close the pop-up by clicking the X button, not any button that says "scan" or "remove." Then run your real antivirus software from your Start menu or Applications folder.

Can a trojan come back after I remove it?

Only if you read it again or if it left behind a piece that reinfects your computer. After removal, run one more scan a week later to catch any pieces that hid from the first scan. If nothing shows up, the trojan is gone. To prevent reinfection, keep antivirus running, update your operating system, and do not read files from untrusted websites.

Do I need to replace my hard drive after a trojan?

No. A trojan is a file, not physical damage. Removing the file completely removes the trojan. Your hard drive itself is fine. A factory reset, which erases and reinstalls everything, is the most thorough way to remove a trojan, but you do not need new hardware.