I recently found a Trojan detection on my Windows PC while using a modding program, although it seemed likely to be a false positive. I reset Windows using the built-in reset option, but after signing back in I received another detection: Trojan:Win32/Leonem!rfn, reportedly found in Microsoft Edge's cache. I'm worried because the detection is associated with credential stealing, and I had passwords saved in Edge. I disconnected the Ethernet cable and removed the detected file with Windows Security. Could the file have been restored through Microsoft account or Edge synchronization after the reset, or does this suggest the malware survived? Should I reinstall Windows from a USB drive, and what steps should I take to protect my accounts?
4 Answers
Disconnecting the computer was sensible. Keep it offline while you run Microsoft Defender Offline, then run a reputable second-opinion scanner such as Malwarebytes after reconnecting. A detection in Edge’s cache does not automatically mean the file executed; browsers can cache a malicious download or page, and synchronization may restore browser data after a reset. Still, treat the detection seriously until the scans are clean.
Save the detection details from Protection History, including the file path and whether Defender says it was blocked, quarantined, or removed. If it was only inside the Edge cache and Defender reports no execution or additional threats, it may have been a blocked cached download or false positive. If the same detection returns after a clean reinstall, investigate the downloaded modding software, browser extensions, and synced Edge data rather than assuming a firmware infection.
Because this detection can involve credential theft, change important passwords from a separate known-clean device, starting with your email and Microsoft account. Turn on two-factor authentication, review account sign-in activity, revoke unfamiliar sessions, and avoid reusing passwords. Don’t assume deleting one cached file proves every account is safe.
A built-in Windows reset is not always the same as completely erasing the disk. For the highest confidence, create Windows installation media on a different, trusted computer, boot from it, delete the existing Windows partitions during setup, and install Windows fresh. Back up only personal documents you have checked first—don’t restore programs or unknown executable files.
I used the deepest reset option in Windows but did not reinstall from USB, so I’ll use installation media if the detections continue.

Defender removed the file, and both a full scan and an offline scan found nothing else. I’m still unsure whether it ever ran.