Long story short, I noticed my WIndows Defender wasnt working yesterday. The icon was green and said “no action needed”, but within the app it said “AV status unknown”. Neither Defender nor Malwarebytes detected anything in a scan (after running RKill).
I then downloaded KVRT which apparently detected a trojan script in my browser extensions.
The file detected by KVRT was HEUR:Trojan.Script.Generic in C:Users[redacted]AppDataLocalBraveSoftwareBrave-BrowserUser DataDefaultExtensionsadahebendgkgacfmpnmoddebbnfpfkcd1.7_0jsbackground.js, which is apprently this extension: https://chrome.google.com/webstore/detail/video-downloader-professi/adahebendgkgacfmpnmoddebbnfpfkcd. Is it false positive or a legit threat?
I then downloaded Kaspersky Internet Security because I dont feel safe with defender anymore and let it run another scan. No more threats found. Is there a difference between the KVRT tool and the built-in scan in KIS? If so, what is the difference)?
Defender still doesnt work btw (when i switch KIS off), so maybe that problem wasn’t related. OR i am still infected somehow?
Am I in the clear? 🙁