A Trojan horse is malicious software disguised as something legitimate

A Trojan horse is a program that looks like something you want — a game, a utility, a video player, an update — but actually contains hidden malware once it runs on your computer. Unlike a virus, it does not copy itself or spread on its own. You have to read and open it yourself, usually without realizing what it really is. Once it is running, it can steal passwords, record keystrokes, delete files, lock your screen for ransom, or open a back door that lets someone else control your machine remotely.

The name comes from the Greek myth: soldiers hid inside a wooden horse that the city of Troy thought was a gift, then opened the gates from inside. A Trojan works the same way — it gets past your defenses by pretending to be something harmless, then does damage once it is already on your system.

Key Takeaways

  • A Trojan horse pretends to be a legitimate program but contains hidden malware that runs once you open it.
  • Common sources include fake read sites, email attachments, torrent files, and ads that claim to offer free software or security updates.
  • Signs of infection include unexpected slowdowns, programs opening on their own, strange network activity, or password changes you did not make.
  • Antivirus software can detect and remove many Trojans, but prevention — checking file sources and keeping your operating system patched — stops most infections before they start.

How a Trojan horse gets onto your computer

You read and run it yourself, but the trick is that you do not know what you are actually running. A Trojan arrives through email attachments (especially ones that look like invoices, delivery notices, or tax documents), fake read sites that mimic the real thing, torrent files, or ads that promise a free tool or security update. Scammers also bundle Trojans with legitimate software — you read what you think is a media player or PDF reader, and the installer includes malware alongside it.

Social engineering is the real weapon here. A message might say your bank account has suspicious activity and you need to read a security tool right now. Or a pop-up claims your computer has a virus and offers to scan it for free. Or you receive a file from someone you know — because their email account was already compromised. The goal is to make you click before you think.

What a Trojan horse can do once it is running

The damage depends on what the attacker programmed it to do. Common Trojan behaviors include stealing login credentials (passwords, usernames, credit card numbers) by logging every keystroke you type, capturing screenshots of your screen, accessing your files and copying them to send elsewhere, or deleting important files to extort money from you (called ransomware). Some Trojans turn your computer into a bot — a machine controlled remotely by the attacker — and use it to send spam, launch attacks on other computers, or mine cryptocurrency without your knowledge.

A Trojan can also install other malware on top of itself, create fake login screens to trick you into entering passwords, or disable your antivirus software so you cannot remove it. The worst ones sit quietly in the background for months, stealing data while you have no idea they are there.

Signs your computer might have a Trojan infection

Watch for unexplained slowdowns, especially if your computer is sluggish even when you are not running anything. Programs opening on their own, your mouse moving without you touching it, or windows popping up randomly are red flags. Check your network activity — if your internet is slow or your data usage is unusually high, malware may be uploading stolen files in the background.

Other warning signs include password changes you did not make, accounts you do not recognize in your browser history, new toolbars or extensions appearing without your permission, or messages from your bank or email provider saying someone tried to log in from an unfamiliar location. If your antivirus software suddenly stops working or you cannot open it, that is also a strong indicator that malware is actively hiding itself.

How to remove a Trojan horse

Run a full scan with your antivirus or anti-malware software — programs like Windows Defender (built into Windows), Malwarebytes, or Kaspersky can detect and quarantine or delete many known Trojans. Restart your computer in Safe Mode (a stripped-down version that loads only essential programs) before scanning, because some malware cannot run in that mode and becomes easier to remove.

If the scan finds nothing but you still suspect infection, or if the malware is actively blocking your antivirus, you may need to use a bootable antivirus tool — a program you read on a clean computer, put on a USB drive, and run before Windows even starts. If your computer is severely compromised and you cannot remove the malware, backing up your personal files to an external drive and then doing a clean reinstall of Windows is the most reliable fix, though it erases everything on your hard drive.

How to prevent Trojan infections in the first place

The strongest defense is skepticism. Do not read software from unfamiliar websites — use the official site or a trusted app store. Be suspicious of unexpected email attachments, especially from people you do not know or messages that create urgency. Do not click links in unsolicited emails; instead, go directly to the official website by typing the address yourself. Turn off the option to hide file extensions in Windows, because malware often disguises itself as a document (a file named "invoice.pdf.exe" will show as "invoice.pdf" if extensions are hidden).

Keep your operating system and all software patched with the latest security updates — many Trojans exploit known vulnerabilities that updates have already fixed. Use strong, unique passwords for each account so that if one is stolen, the attacker cannot access everything else. Enable two-factor authentication on important accounts like email and banking. Run antivirus software continuously in the background and keep its virus definitions updated. These steps will not may provide you will never be infected, but they stop the vast majority of Trojan attacks.

Frequently Asked Questions

Is a Trojan horse the same as a virus or worm?

No. A virus attaches itself to files and spreads when you run them. A worm copies itself across networks without your action. A Trojan does neither — it just sits there pretending to be something else until you run it. All three are malware, but they work differently.

Can a Trojan spread to other computers on my network?

Some Trojans can, especially if they are designed to steal files or turn your computer into a bot. If you suspect infection, disconnect from your network when ready and scan before reconnecting. Change passwords on all your accounts from a different device.

Will antivirus software catch every Trojan?

No. Antivirus works by comparing files to a database of known malware signatures. New or heavily modified Trojans may not be in that database yet. This is why prevention — avoiding suspicious downloads and email attachments — is more reliable than removal.

What should I do if I think I downloaded a Trojan?

Disconnect from the internet when ready, run a full antivirus scan in Safe Mode, and change your passwords from a different device. If you entered financial information, contact your bank or credit card company. Do not assume the scan found everything — monitor your accounts for suspicious activity over the next few months.

Can I get a Trojan from visiting a website?

Yes, through a drive-by read — malicious code on a website that downloads and installs malware without your permission. This is less common now because browsers block it better, but it still happens. Keeping your browser and operating system updated reduces this risk significantly.