Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
If Microsoft Defender detected and quarantined Trojan:Win32/Egairtigado!rfn, that is reassuring—but it does not prove that no credentials were exposed before detection or that every trace of a threat is gone. Stop using the affected PC for sensitive logins, secure your email and other accounts from a known-clean device, then review Defender’s Protection History and run a full scan followed by Microsoft Defender Offline. If detections return or you find signs of persistence, plan a Windows reset or clean reinstall.
Handle any account takeovers as a separate urgent problem. A detection and account activity occurring around the same time do not, by themselves, prove that this Trojan caused the account compromises.
What the detection tells you—and what it does not
Trojan:Win32: identifies a Microsoft Defender detection in the Trojan category for Windows. The !rfn portion is a detection suffix; it is not enough to establish a particular malware family or exactly what the file did. Public details about this exact detection are limited, so do not assume it is a confirmed password stealer—or assume it was harmless.
In a BleepingComputer removal-help thread started October 12, 2025, a user reported the detection at C:ProgramDatac2fdedzcl.dll, along with unauthorized activity on Instagram, Reddit, and X. The user said subsequent Defender Offline and Malwarebytes scans found no active malware. Those reports describe that case; they do not establish that the detection caused the account activity or prove that credentials were never exposed.
#1 Best Overall
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
A file in ProgramData is not automatically malicious—legitimate programs also use that folder—but an unexpected DLL there warrants checking the detection details. Manually deleting the containing folder is not a complete response: it may not address another component, persistence mechanism, or information already copied.
Understand the Defender action
- Quarantined: Defender isolated the detected item and blocked it from running. This is not proof that no other component exists or that information was not exposed earlier. See Microsoft’s quarantine and Protection History guidance.
- Removed: Defender says it deleted the item. That addresses the detected item, not necessarily every possible consequence of an earlier compromise.
- Allowed or restored: The item may be permitted to run or returned to its original location. Do not restore it simply because a later scan is clean; do so only if you can establish it is a false positive.
- Recurring or active detection: Treat this more seriously. Microsoft notes that repeat detections can mean an undetected component is reinstalling the threat.
- No detections on follow-up scans: This lowers concern about malware currently detectable by those scans, but it cannot establish that passwords, cookies, or files were never accessed.
First: contain the PC and secure your accounts
- Stop entering passwords on the affected PC. Do not use it for email, banking, social media, work accounts, or password-manager access while you assess it.
- Disconnect it from the network if the detection is active or recurring, the computer is behaving suspiciously, or you are unsure whether the threat is contained. Turn off Wi-Fi or unplug Ethernet. Do not keep a potentially active threat online just to run scans.
- Use a known-clean phone or computer to secure accounts. Begin with your primary email account, which can often reset access to many others. Change its password to a unique one, then secure financial, cloud-storage, password-manager, social-media, and work accounts. Do not reuse the new password across services.
- Revoke access, not just passwords. Sign out other sessions and remove unknown devices, connected apps, app passwords, browser sessions, and recovery methods. Review account activity and security alerts. Turn on multifactor authentication (MFA)—prefer a passkey or security key where available, otherwise an authenticator app when practical.
- Contact your bank or payment provider if financial accounts, card details, tax records, or identity documents may have been accessible from the PC. Act promptly if you see transactions or changes you did not make.
- Save useful evidence before any reset. Keep the detection name, file path, time, action taken, Protection History screenshots, account alerts, and records of unknown sign-ins. If you may need forensic help, avoid wiping the device until you have spoken to a qualified incident-response professional.
Microsoft’s incident-response guidance emphasizes containing suspected systems and resetting compromised users’ passwords. A clean device matters: changing passwords from the suspected PC could expose the replacements too.
Investigate account takeovers separately
Several accounts showing unauthorized activity is strong reason to assume that credentials or sessions were exposed somewhere. It does not identify the source. Possibilities include the PC, a phone, phishing, password reuse, a stolen browser session, a breached service, or another device.
For each affected service, review recent sign-ins and security alerts; end unfamiliar sessions; remove unknown connected applications; check recovery email addresses, phone numbers, passkeys, and app passwords; and inspect settings for changes. For email, also check forwarding rules, filters, and delegated access. On social platforms, review connected apps and profile or recovery changes, remove unauthorized posts, and report the takeover to the platform. Save timestamps and screenshots in case you need to dispute activity.
Rank #2
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
Changing a password alone may not invalidate active sessions or tokens, so use each service’s sign-out-everywhere or session-revocation controls where available. Microsoft warns that reusing passwords can let an attacker use one exposed password to access other services.
Scan Windows in a deliberate order
1. Check Protection History
Open Windows Security → Virus & threat protection → Protection history. Depending on the Windows interface, the page may be labelled Threat history. Record the detection name, path, date and time, action, and any related alerts. Check whether the item was quarantined, removed, allowed, or restored. Do not restore it just to see whether it works.
2. Update Windows and Defender
Install pending Windows updates and make sure Defender security intelligence is current. Keep cloud-delivered protection and automatic sample submission enabled unless a specific privacy requirement or organizational policy says otherwise. Microsoft recommends current protection updates and describes these settings in its malware detection and removal guidance.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →3. Run a full scan
In Windows Security, select Virus & threat protection → Scan options → Full scan. A full scan examines files and programs across the device and can take a long time, particularly on a large drive. Follow Defender’s recommended action for any findings, then note the result in Protection History. Microsoft explains scan types in its Windows Security guide.
Rank #3
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
4. Run Microsoft Defender Offline
Save open work, then select Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus (offline scan) → Scan now. The PC restarts and scans before normal Windows processes load, which can make it harder for some persistent malware to hide or interfere. Review the result afterward in Protection History. See Microsoft’s instructions for Defender Offline and malware troubleshooting.
5. Consider a compatible second opinion
A reputable on-demand scanner can add useful evidence, but a clean second-opinion scan is not proof that the PC was never compromised. Avoid running multiple real-time antivirus products at once, since they can conflict; use additional products only in a compatible on-demand mode. The original forum poster reported using Malwarebytes, but that result applies to the reported scan, not to every system with this detection.
Keep Windows, reset it, or reinstall?
There is no need to wipe every PC after one quarantined detection. The decision depends on what happens next and how much confidence you need in the system.
| Situation | Reasonable next step |
|---|---|
| The item was quarantined or removed; updated Defender, an Offline scan, and any compatible second-opinion scan find nothing; no suspicious behavior or persistence is apparent. | You may keep the installation, complete account recovery, install updates, and monitor Protection History. A clean result lowers concern about a currently detectable threat but cannot rule out past exposure. |
| The same or related detection returns, particularly after a reboot; suspicious startup items, scheduled tasks, services, browser extensions, or administrator accounts appear; or security tools are disabled or obstructed. | Disconnect if the threat appears active. Do not rely on repeated quick scans; consider a reset or clean reinstall, or get qualified help. |
| You cannot establish what happened, the PC holds highly sensitive data, or you need a high-confidence clean state. | A reset or clean reinstall may be the more proportionate way to regain confidence. Consider professional incident response if evidence must be preserved. |
Microsoft says a reset, restore, or reinstall may be necessary if malware caused irreversible changes, and cautions that backups kept on an infected PC may have been altered. Prefer a backup made before the incident and kept externally or with trustworthy version history; see its recovery guidance.
Rank #4
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
Before a reset or reinstall
- Preserve detection and account evidence, and decide whether forensic help is needed before erasing anything.
- Back up only necessary personal files, such as documents and photos, and scan them. Avoid executable files, scripts, unknown installers, cracked software, browser profiles, and entire
AppDatafolders. - From a clean device, save recovery codes and confirm you can access the Microsoft account needed for Windows sign-in or reactivation. Record important application licenses and settings.
- Have a clean Windows installation source available if you plan a clean installation.
After reinstalling
Apply Windows updates before restoring files. Install applications from official sources, restore only necessary personal data, and do not copy the old browser profile wholesale. From a clean device, change important passwords again if you entered them on the old installation, and revoke old sessions and tokens. Re-enable MFA and other security controls.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Could saved browser passwords have been stolen?
Possibly—but the detection name alone cannot tell you whether that happened. Malware may target saved browser passwords, cookies and active sessions, autofill information, wallets, messaging accounts, or files containing credentials. Access depends on the malware’s capabilities, Windows and browser protections, the user’s session, and other factors. A browser asking for a click or authentication before revealing a password is not proof that stored credentials or session cookies were safe.
As a precaution, treat passwords stored or typed on the possibly affected PC as exposed: replace them from a clean device with unique passwords, starting with email. Revoke active sessions and tokens as well, because a stolen session can sometimes remain usable even after a password changes. Then remove unknown recovery methods and connected apps.
Recommended Free Tools
Does an Android phone need a factory reset?
Not automatically. A Windows detection does not prove a linked Android phone is infected. Connecting by Bluetooth, USB, Phone Link, or a shared account does not, by itself, transfer a Windows infection to the phone.
Best Value
- AWARD WINNING Antivirus, anti-malware, anti-spyware & more
- 24/7 REAL TIME PROTECTION against emerging malware threats, including ransomware and viruses- without slowing you down.
- PROTECTS YOUR DEVICES ON MULTIPLE PLATFORMS: Get cyber protection for your computers, smartphones, or tablets- Compatible with Windows, Mac, Android, iOS
- DOWNLOAD AND INSTALL INSTANTLY
- UNMATCHED THREAT DETECTION: We found malware on 40 percent of devices that already had a third-party antivirus installed.
Assess the phone on its own: remove unfamiliar apps; inspect accessibility services, device-admin apps, VPNs, notification access, and permission to install unknown apps; install Android and app updates; and run Google Play Protect. From a clean device, review Google-account security events and sessions, change the account password if appropriate, and remove unknown connected apps or devices. Do not blindly restore suspicious APKs or a complete backup.
A factory reset is a reasonable high-confidence response if there is credible evidence of phone compromise—such as unexplained activity originating from the phone, an unknown administrator or accessibility service, or persistent suspicious behavior. Back up only essential personal data first, then reinstall apps from official stores. A related forum thread received case-specific advice to reset an Android device; that is not evidence every linked phone must be reset. Microsoft’s Defender scanning guidance also covers Android, though features can vary by product and account configuration.
What not to do
- Do not log in to sensitive accounts from the suspected PC while investigating.
- Do not assume quarantine proves there was no credential exposure, or that a clean scan disproves a prior compromise.
- Do not restore a quarantined file because its name looks familiar, or delete random system files and registry entries.
- Do not follow generic Farbar Recovery Scan Tool (FRST) fix lists. FRST logs and fixes are machine-specific and can cause damage if misapplied; the original forum helper requested logs before giving tailored steps.
- Do not install random “registry cleaners” or stack aggressive removal tools.
- Do not restore the entire old browser profile, suspicious executables, or pirated software into a fresh installation.
- Do not reset only the phone while leaving email, cloud accounts, and active sessions exposed.
When to get professional help
Seek qualified incident-response or forensic help if the device contains business, medical, legal, financial, or government data; you see signs of ransomware or remote access; an attacker retains access after passwords and sessions are reset; the PC is used for cryptocurrency or privileged administration; or you need evidence preserved. Ordinary computer repair may simply reinstall Windows without investigating the compromise, so ask what the service will actually do and how it handles evidence.
If the detection was a one-off, Defender removed or quarantined it, follow-up scans are clean, and there are no signs of persistence, the built-in Windows Security tools and careful account recovery are sensible first steps. Buying another security product is not a substitute for revoking sessions, changing exposed passwords from a clean device, and deciding whether the current Windows installation can be trusted.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

