What Is a Trojan Virus, and Why It Is Not a Virus

September 19, 2026

A person typing on a laptop with focus on hands and keyboard

Photo: pexels · PEXELS

Published Updated 4 min read

A trojan is a harmful program wearing the costume of a useful one, and strictly speaking it is not a virus at all. It does not copy itself or spread on its own. It waits for a person to download and open it, so the disguise is the entire product.

The name is a clue to how it works

The label comes from the wooden horse story, and the parallel is precise. Nothing forced its way through the gate. The defenders carried the threat inside because it looked like something they wanted.

Malicious code that behaves this way has one job before anything else, which is to look legitimate long enough to be run. It might genuinely install the photo editor or the game cheat you were after, while quietly doing its real work in the background. The visible function is not a decoy layered on top. It is often the actual software, repackaged with an extra passenger.

Once running, what happens next varies enormously. Some open a hidden door so an outsider can control the machine later. Some sit and log what you type, waiting for a banking login. Some do nothing but fetch and install further programs, which is why one bad download so often turns into several problems at once.

Hand inserting USB drive into laptop. Modern tech connection concept
Photo via Pexels

Virus, worm, and trojan are three different things

People use the word virus for all hostile software, and that is fine in conversation, though the distinctions matter once you are trying to work out how something got in.

Virus Worm Trojan
Copies itself Yes, by attaching to files or programs Yes, on its own No
Needs a person to act Yes, to open the infected file No Yes, to download and run it
How it travels Rides along inside something else Crawls networks looking for weaknesses Gets invited in
Main defense Scanning and patching Patching and firewalls Caution about what you run

The practical takeaway sits in that last row. A worm exploits a flaw in software, so keeping systems updated blunts it. A trojan exploits a decision made by a person, so no update will ever close that gap completely.

The disguises that keep working

  1. Cracked paid software and license key generators, which are the classic carrier because the download already asks you to ignore warnings.
  2. Fake update prompts on a web page, usually for a media player, a browser or a video codec.
  3. Email attachments dressed as invoices, delivery notices or resumes, where opening the file is the natural response.
  4. Phone apps outside official stores that copy the name and icon of a popular one.
  5. Pop ups claiming your device is already infected and offering a cleanup tool.
  6. Game mods, cheats and trainers shared through chat channels rather than a storefront.

The thread running through all of them is urgency paired with a reason to bypass the usual checks. A warning that demands immediate action deserves more suspicion than a quiet one, not less.

What to do, in order, if you think one is running

Sequence matters more than speed here, because the wrong first move can hand over the very credentials you are trying to protect.

  1. Disconnect the device from the internet. That cuts the link to whoever is on the other end and stops anything further being sent out.
  2. Stop logging into accounts on that machine. Every password typed while it is compromised is a password given away.
  3. Run a full scan with security software that was already installed, not something you rush to download in a panic.
  4. Change passwords from a different device you trust, starting with the email account, since that one can reset all the others.
  5. Turn on two factor authentication wherever it is offered, which blocks a stolen password from being enough.
  6. Watch bank and card statements closely for a while, and report anything unfamiliar to the institution directly.

If symptoms persist after a clean scan result, the reliable fix is wiping the drive and reinstalling the operating system. Copy documents and photos off first, never programs or installers, since those are what carried the problem in.

Frequently asked questions

Can a trojan spread from one computer to another by itself?

No, and that is the defining trait. It has no mechanism for copying itself across a network or onto a drive. Spread happens only when people pass the file along, which is why a single bad download shared in a group chat can reach many machines.

Does a factory reset remove a trojan?

Usually yes, because a reset wipes the storage the program lives on. The catch is restoring from a backup made after the infection, which can carry it straight back. Restore documents and photos rather than applications, and set the device up fresh where you can.

How can you tell if a download is hiding a trojan?

Check where it came from before you check the file. Official stores and vendor sites are the safest sources, while cracked software, unexpected attachments and pop up update prompts are the riskiest. A program asking for administrator access it has no reason to need is another warning.

Related reading