Trojan:JS/Malgent!MSR Windows Defender

I have a concern for something that has just happened with my system. I recently just came back from a two month holiday so I have not used my home desktop for these past two months. However, when I booted it up for the first time right now, I noticed a warning from Windows Defender notifying me about a security threat that is Trojan:JS/Malgent!MSR. When I tried to look into it further, the notification tray disappeared and it seemed like the threat disappeared. I went into my protection history and found that it was a Severe threat that was quarantined affecting the following items:

file: C:\Users\Anthony Le\AppData\Local\Google\Chrome\User Data\Default\Extensions\llimhhconnjiflfimocjggfjdlmlhblm\1.5.7_0\javascripts\background.js

file: C:\Users\Anthony Le\AppData\Local\Google\Chrome\User Data\Default\Extensions\llimhhconnjiflfimocjggfjdlmlhblm\1.5.7_0\javascripts\libs\safe-browsing.js

What should I do to make sure that my system is safe and nothing has been compromised? There is an action button to remove or restore so I assume I should remove. I also downloaded Malwarebytes to run a full system scan but I have not gotten the results back as of yet. Any help and steps towards cleaning my system will be appreciated as I get easily anxious about security and privacy.



Update:
I did some research regarding my chrome extensions and this might be something to do with a Reader Mode extension. This is odd as I don't remember installing this chrome extension and apparently it was involved in a phishing incident so now I am not sure what to do to fully secure all of my accounts. Is there a way to see install history so I can backtrack what happened? I'm not really too sure what to do so would like some help.

Update 2:
Looked through my my google account history and found that at 1:44am on March 18 2024 I visited Miro, reader mode, Miro, then this website https://offer.shoppermeet.net/monetizex?queryid=iqg2c7aw4nmzhndrvahv72nrym&b=miro (did not open the website to inspect), then "Used Chrome". Not sure what this means but reading the history before that it looks like I was working on a uni assignment but the activity I just listed does not seem normal. Other times I visited reader mode after this was Nov 23, 2024 where I visited Visited Reader Mode - Updated! and the following day Nov 24, 2024 where I visited Visited Reader Mode - Updated! and then searched for reader mode after this. I am not sure how this happened but now I am very concerned about my account security.

|
Hi, I am Dave, I will help you with this.

1
Have oyu now removed that extension from your Chrome browser?

2
Start Windows in Safe Mode.

Open File Explorer, then on the View menu at the top, temporarily turn on 'Hidden Items'.

Navigate to this folder: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service

Delete the contents of that Service folder.

Navigate to this folder:

C:\ProgramData\Microsoft\Windows Defender\Quarantine

Delete the contents of that Quarantine folder.

Close File Explorer.


Restart Windows in normal mode.

Open Defender and select the option to perform an offline scan, your PC will restart to perform that scan.

Then check if that malware list in Defender is clear.
___________________________________________________________________

Power to the Developer!

MSI GV72 - 17.3", i7-8750H (Hex Core), 32GB DDR4, 4GB GeForce GTX 1050 Ti, 256GB NVMe M2, 2TB HDD

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Should I do this after my Malwarebytes scan as it is running right now or should I pause it and do the steps you told me to? Also wanted to make sure if you have read my updates.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Please complete the Malwarebytes scan before performing these steps.
___________________________________________________________________

Power to the Developer!

MSI GV72 - 17.3", i7-8750H (Hex Core), 32GB DDR4, 4GB GeForce GTX 1050 Ti, 256GB NVMe M2, 2TB HDD

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Thank you I will get back to you after I complete your steps

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Glad to help!
___________________________________________________________________

Power to the Developer!

MSI GV72 - 17.3", i7-8750H (Hex Core), 32GB DDR4, 4GB GeForce GTX 1050 Ti, 256GB NVMe M2, 2TB HDD

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Hi, I am Dave, I will help you with this.

1
Have oyu now removed that extension from your Chrome browser?

2
Start Windows in Safe Mode.

Open File Explorer, then on the View menu at the top, temporarily turn on 'Hidden Items'.

Navigate to this folder: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service

Delete the contents of that Service folder.

Navigate to this folder:

C:\ProgramData\Microsoft\Windows Defender\Quarantine

Delete the contents of that Quarantine folder.

Close File Explorer.


Restart Windows in normal mode.

Open Defender and select the option to perform an offline scan, your PC will restart to perform that scan.

Then check if that malware list in Defender is clear.

I finished my malwarebytes scan and it showed no threats. What do these steps that you tell me do?

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

The Steps I provided will remove the Defender Quarantine files from your PC, reset Defender, then perform a scan to ensure your system is now clear of all malware.
___________________________________________________________________

Power to the Developer!

MSI GV72 - 17.3", i7-8750H (Hex Core), 32GB DDR4, 4GB GeForce GTX 1050 Ti, 256GB NVMe M2, 2TB HDD

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I decided to go into protection history and remove the threat from the quarantine zone. How else do I make sure that my computer isn't infected with anything and that my data is safe? Should I delete my chrome cache? I'm not too sure about the following steps to make sure my data is protected.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Download the Microsoft Safety Scanner and perform a full scan with that, if at the end of that scan your system is indicated as clear of malware, then there is nothing further you need to do.

https://learn.microsoft.com/en-us/defender-endp...
___________________________________________________________________

Power to the Developer!

MSI GV72 - 17.3", i7-8750H (Hex Core), 32GB DDR4, 4GB GeForce GTX 1050 Ti, 256GB NVMe M2, 2TB HDD

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Do you also know why this extension would have randomly installed itself or do I need to go into another forum for this?

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

 
 

Question Info


Last updated April 19, 2025 Views 261 Applies to: