A file in my Cache is getting flagged as a Trojan

Description of the issue:

After a Windows 11 update that came out a few days ago, Windows Defender is flagging a file in the Brave Cache as a trojan. But upon deleting my cache, the issue is resolved again.

How can this issue be reproduced?

  1. Let Brave run for a little while.
  2. Check the BraveSoftware folder on your device with Windows Defender

Expected result:

A random file from the Cache that starts with the letter F and six digits (example: f_000038) gets flagged as malware

Brave Version( check About Brave):


Version 1.73.101 Chromium: 131.0.6778.139 (Offizieller Build) (64-Bit)

@Amir3.0 have you run full scans on your device? Double check to make sure you’re using legitimate extensions?

Keep in mind just because a trojan ends up somewhere doesn’t mean that it’s the origin. Trojan viruses are ones that disguise themselves as helpful files or programs. They often get there through other types of malware that you install. So even when you remove something like a cache, if it didn’t get rid of the original offender, then it will reappear.

1 Like

@Saoiray
I do full system checks, and the only thing getting flagged are files in the cache folder.

I should also add that after activating a setting that deletes the cache upon closing Brave and doing multiple checks, nothing got found.

Edit: I also only have two extensions active, but i got them from the Google Store. I even uninstalled Brave and the extensions twice

Edit 2: I did a few scans with Malwarebytes as well, and that didn’t find anything at all.

Hi, I have had the exact same thing happen. Also updated to the latest windows 11 version as of 2 hours ago. I vet my extensions very well and block ads. I scan my entire drive daily. I didn’t delete the cache and let windows defender/win 11 anti virus quarantine it and remove it. I am currently doing a secondary full scan (with rootkit scan option on) with malwarebytes. See the screenshot for more info.

edit: yes, official brave from official website, from two (? ish) years ago, always updated to the latest version as soon as available. My malwarebytes is still busy with the secondary scan, will update with result.

edit2:malwarebytes came back clean, but defender obviously got rid of the file, so if malware, it’s left no detectable traces being picked up by def and mwb.

did you open twitch site before?, if yes… this just a false detect by windows defender.

UPDATE

After testing the theory of @NoUsernamehehe i did five full system scans. The first one i did imediatelly after starting my PC at 12:20, which was negative. The second one was after letting Brave run for 20 minutes, which was negative again. The third one was right after opening twitch, which was positive, at 13:18. The final two were right after cleaning up the cache and one hour after that, at 14:23.
This proves this theory correct. Something about the cache created when starting Twitch triggers this detection.

Edit was due to adding more screenshots

I have also checked the Brave folder itself, and it was also fine

That’s weird, but at least if it’s not appearing at any other time, it tells you the issue is kind of coming from Twitch or something. But really is strange. And you would think other people would be having the issue if it just was from Twitch. Not sure if it’s a false positive, if you have something else working in conjunction, or what?

I’m going to tag in @Mattches to see if he has any guidance to give you.

1 Like

Besides Defender, and Brave obviously, i had nothing else running.

Also thank you for the tag and the support :+1:

Update 2

I tried opening twitch with Microsoft Edge just now, and guess what. It happened again.

This pretty much proves that it’s either a problem with Defender or Twitch, and that this is browser-indipendent. I am gonna edit this once i un- and reinstall Defender.

2 Likes

Thank you for updating. Going to leave this thread open for now in case you find out any information about what caused the issue that might be helpful for other users.

1 Like

@Mattches
Edit: I had to edit this reply twice because of my findings.
First up, thank you for the fast reply!
I just fully reset Defender, and now it’s not a issue anymore
This is a check of the BraveSoftware folder, with twitch running in the background.

And this is a full system check.

Both came back negative after doing a full reset.

Edit: I did another scan just now, and it’s positive again. Looks like resetting Defender doesn’s solve things after all.

Edit 2: Yeah, the problem isn’t with Defender, it seems. I did another full reset, and i still get a positive.