Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

How to Remove a Trojan from Windows Safely

Isolate a suspected Trojan infection, scan with Microsoft Defender, use Offline scan for persistent malware, review quarantine, reset credentials, and prevent reinfection.

Table of Contents

A Trojan is malware that pretends to be legitimate or is hidden inside another file or installer. The safest removal process is to isolate the computer when sensitive data may be at risk, update a trusted antivirus product, run a full scan, use an offline scan for persistent threats, and review the remediation results. Do not try to identify and delete random system files manually.

Windows 7 and Windows 8 are no longer supported by Microsoft. If a Trojan is found on one of those systems, move important data through a controlled recovery process and migrate to a supported operating system. Installing antivirus cannot replace missing operating-system security updates.

Trojan malware disguised as legitimate software

What a Trojan can do

“Trojan” describes the delivery method rather than one fixed behavior. Depending on the payload, a Trojan may:

  • open remote access to the computer;
  • steal passwords, browser cookies, documents, or payment information;
  • download additional malware;
  • display fake antivirus warnings or advertising;
  • join the PC to a botnet;
  • record keystrokes or screen activity;
  • encrypt or destroy files;
  • disable security settings and hide its components.

A slow PC, pop-ups, redirects, or crashes can have non-malware causes. Treat them as signs to investigate, not proof of a Trojan.

Immediate steps when a Trojan is suspected

  1. Disconnect from untrusted networks if you see credential theft, remote control, ransomware, or security tools being disabled. Unplug Ethernet and turn off Wi-Fi.
  2. Do not log in to important accounts on the affected computer.
  3. Disconnect external drives after stopping any active file transfer.
  4. Record what happened: the alert name, file path, time, suspicious download, email, or website.
  5. In a workplace, contact IT or security before changing the system or deleting evidence.

Scan with Microsoft Defender

If Microsoft Defender Antivirus is the active security provider:

  1. Open Windows Security > Virus & threat protection.
  2. Open Protection updates and check for current security intelligence.
  3. Select Scan options > Full scan > Scan now.
  4. When the scan finishes, open Protection history and expand each detection.
  5. Choose Quarantine when you are unsure. Remove an item after confirming it is malicious; do not select Allow simply to make an alert disappear.

TipsMake provides more ways to run a full Microsoft Defender scan. If another reputable antivirus is active, use that product's update, full-scan, and quarantine functions instead of enabling a second real-time scanner.

Use Microsoft Defender Offline for persistent malware

If the same detection returns after a restart or malware interferes with normal scanning, save open work and run Microsoft Defender Offline from Scan options. Windows restarts into a recovery environment and scans before normal Windows and most malware components load.

After the PC restarts, open Protection history to review the result. Microsoft's Virus & threat protection guide explains the current scan options.

Verify the computer after remediation

  1. Restart Windows and update the antivirus again.
  2. Repeat a Quick or Full scan.
  3. Check startup apps, browser extensions, scheduled tasks, and installed programs for entries related to the infection.
  4. Install Windows and application updates.
  5. Confirm that real-time protection, the firewall, and browser reputation protection are active.
  6. Monitor accounts and the computer for renewed alerts or unusual sessions.

If security settings immediately turn off, the same Trojan returns, an unknown administrator account appears, or sensitive business data was accessible, rebuilding Windows from trusted media may be safer than continuing to trust the installation.

Reset credentials from a clean device

An information-stealing Trojan can copy passwords and session cookies before it is detected. From a different, known-clean device:

  • change the email password first, then financial, work, cloud, and social accounts;
  • revoke active sessions and unknown devices;
  • enable multi-factor authentication;
  • replace reused passwords with unique ones;
  • contact the relevant provider if unauthorized activity occurred.

Why the old Group Policy method does not remove Trojans

Some legacy guides open gpedit.msc, enable Removable Disks: Deny execute access, and run gpupdate /force. This policy can prevent executable files from launching from removable disks on supported Windows editions. It does not scan the computer, identify malware, delete a Trojan, reverse stolen credentials, or clean an infected USB drive.

Opening the legacy Local Group Policy Editor

Legacy Removable Storage Access policy location

Enabling removable-disk execute restrictions in Group Policy

Opening Command Prompt in an older Windows version

Applying Group Policy changes with gpupdate in a legacy guide

Restarting an older Windows computer after a policy change

Use removable-media restrictions as an optional prevention control in a managed environment, not as malware removal. Blocking all removable storage can also interrupt legitimate devices and workflows, so administrators should test the policy and document exceptions.

Be cautious with dedicated “Trojan remover” utilities

The following screenshot shows an older standalone Trojan-removal product. A familiar name or an old review does not establish that a utility is currently maintained or safe.

Legacy standalone Trojan Remover interface

Download a second-opinion scanner only from the security vendor's official site, verify its digital signature, and do not install another full real-time antivirus alongside the active one. To check a non-confidential file or URL, compare TipsMake's online malware scanners.

Prevent another Trojan infection

  • Keep Windows, browsers, office applications, and internet-facing tools updated.
  • Download software from the developer or official app store, not a repack or crack site.
  • Keep internet-sourced macros and scripts blocked unless their source is verified.
  • Use a standard user account for daily work where practical.
  • Maintain offline or versioned backups and test restoration.
  • Use multi-factor authentication and a password manager.
  • Scan removable media and disable unnecessary autorun behavior.

A computer can already have built-in protection even when no third-party antivirus is installed. Read what happens when a PC has no active antivirus protection and confirm the provider status in Windows Security.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.