Windows Defender recently detected Trojan:Win32/Leonem!rfn, which is known for stealing credentials. I initially suspected it might be a false positive related to a modding tool, but I reset Windows anyway. After signing back in, Defender detected another copy in Microsoft Edge's cache. I'm worried because my passwords are saved in Edge and I don't understand how malware could appear after a reset. I disconnected the Ethernet cable and removed the detection with Defender. I'm also running full and Microsoft Defender Offline scans. Could this simply be a cached file synced from a website or Microsoft account, or should I assume the Trojan executed? What should I do to make sure the computer and my saved logins are safe?
4 Answers
If repeated offline scans are clean and the detection was only an unexecuted cache file, it may have been a false positive or a malicious download that never ran. Unfortunately, scans cannot prove with certainty that a credential stealer never executed, so changing passwords and reviewing account sign-in activity is still the safest response.
Assume the saved browser passwords may have been exposed. From a different, trusted device, change your email, Microsoft account, banking, and other important passwords, enable two-factor authentication, and sign out other sessions. Do not reuse passwords. After reinstalling, avoid importing the old Edge profile or restoring saved passwords until the system is known to be clean.
A normal Windows reset is not always the same as completely wiping the drive. For the highest confidence, create Windows installation media on a known-clean computer, boot from it, delete the existing Windows partitions, recreate them, and perform a clean installation. Back up only personal documents that you have scanned first—do not restore programs, installers, browser profiles, or suspicious files.
Disconnecting the computer was the right first step. Keep it offline while scanning, and check Protection History to confirm whether Defender quarantined or removed the file. Run a full scan and Microsoft Defender Offline, and consider a second-opinion scanner such as Malwarebytes. A detection in a browser cache does not automatically prove it executed; it may only be a downloaded or cached file, but it should still be treated seriously.

I removed the detection and both the full and offline scans came back clean. I’ll change my important passwords from another device and avoid restoring the old browser data.