Trojan Scanner
A trojan is malware disguised as something legitimate — a cracked game installer, a fake system utility, an email attachment labeled as an invoice. Unlike a worm, it doesn't self-replicate; it relies entirely on a person choosing to run it. A trojan scanner focuses on catching that disguise before or immediately after execution.
Common trojan types
- Downloader trojans — small initial payloads that fetch additional malware after installation
- Banking trojans — designed to intercept credentials on financial sites
- Remote access trojans (RATs) — give an attacker ongoing control of the infected PC
- Fake antivirus trojans — pose as security software while disabling real protection
How scanning catches a disguise
Since a trojan's file name and icon are deliberately misleading, effective scanning relies on behavior rather than appearance: does the program attempt to modify registry Run keys, spawn hidden processes, or reach out to unfamiliar network addresses immediately after launch? This behavioral layer is what separates modern anti-malware tools from older signature-only antivirus, and it's central to how Malwarebytes for Windows approaches detection.
If a trojan is already installed
- Disconnect from the network if a remote access trojan is suspected
- Run a full scan rather than a quick scan, since trojans often drop secondary files
- Quarantine everything flagged, including files the trojan downloaded after installation
- Change passwords for accounts accessed on the infected machine, from a separate device
- Check Task Scheduler and registry Run keys manually if symptoms persist after a clean scan
Prevention habits worth building
Most trojan infections trace back to pirated software, cracked installers, or attachments opened without verifying the sender — the same entry points covered in our broader malware guide. Avoiding those sources prevents more infections than any scanner catches after the fact.
Frequently asked questions
How is a trojan different from a virus?
A virus attaches to and modifies other files to spread itself, while a trojan is a standalone program that relies entirely on being run voluntarily, usually under a false identity.
Can a trojan hide from Task Manager?
Some trojans use misleading process names or inject into legitimate processes to blend in, though few fully hide from Task Manager the way a kernel-mode rootkit can.
Is it safe to just delete a suspected trojan file manually?
Manual deletion can miss secondary payloads or persistence mechanisms the trojan already installed, so a full scan is generally more reliable than deleting the original file alone.
Malware-Bytes.net is an independent information resource about malware protection for Windows. We are not Malwarebytes, and this site is not the official Malwarebytes website or support channel. Malwarebytes is a trademark of Malwarebytes Inc.