I was checking my school email in Chrome when I clicked what looked like a job opportunity. It turned out to be an RTF attachment rather than a normal link. A window appeared briefly and then closed immediately. I disconnected the laptop from the internet, ran a Microsoft Defender Offline scan, checked Windows security events, searched for the file, and confirmed that Chrome showed no download. I also changed my email and school-account passwords using a separate desktop computer. What else should I check, and how can I tell whether opening the file actually did anything?
3 Answers
You’ve already taken several sensible steps. A window flashing open and closing doesn’t necessarily mean the file successfully executed anything. RTF files are mainly risky when they’re opened by vulnerable, outdated document software, so make sure Windows, Microsoft Office, and your document viewer are fully updated. As an extra check, look in Downloads and `%temp%` for files created around that time, review Startup apps and Task Scheduler for unfamiliar entries, and run a reputable second-opinion scanner such as Malwarebytes. Forward the message to your school’s IT department so they can inspect it and check whether other accounts received it. If those checks are clean and your software was patched, a complete wipe probably isn’t necessary.
For a high-confidence response, you could back up only personal documents, then perform a clean Windows reinstall. That’s the most thorough option, but it may be excessive if Defender, a second scanner, account reviews, and the school’s IT checks all come back clean. Don’t reconnect the laptop until you’ve finished the scans and installed pending security updates.
Changing passwords from a different, trusted device was the right approach. Also sign out existing sessions, enable multifactor authentication where available, and review recent account sign-ins for anything unfamiliar. You don’t need to assume every account is compromised, but accounts accessed on the laptop deserve extra attention if the file turns out to be malicious.

I kept the laptop offline and changed the passwords from my desktop computer, so the password changes weren’t made on the potentially affected machine.