Deleting this malware does not remove it. It has moved into Chrome.
Most malware wants to survive a reboot. This one wants to survive being deleted. Researchers at Ontinue published a teardown of a stealer platform called Lunex, and the detail that stands out is where it parks itself: registered with Chrome as a native messaging host, under the name com.lunex.explorer, with the ability to read and write files and run commands. Remove the program that installed it and that channel is still sitting there.
Getting in is the familiar routine. A compromised website shows what looks like a Cloudflare check, and the page tells you to copy a command and run it. We wrote about the same trick turning up on a domain used in a thousand code samples. The command fetches an installer, which quietly works around the Windows permission prompt and then does something neater than switching your antivirus off. It loads a legitimate, properly signed AMD power-delivery driver with a known hole in it, and uses that to wipe the kernel notifications that up to twenty security products rely on. Everything still appears to be running. It has simply stopped being told anything.
Then it empties the drawers: saved passwords and session cookies from seven Chromium browsers including Chrome, Edge, Brave, Opera and Vivaldi, plus desktop crypto wallets and wallet extensions.
The only part that needs you is the copy and paste. No legitimate website has ever asked anyone to paste a command into the Run box to prove they are human, and that single rule defeats this entire chain. If you think you did it, assume the cookies went too, which means changing passwords is not enough on its own, and you want to sign out of every session on the important accounts. Tendvane is not antivirus and will not clean an infection, but its safety check does list the browser add-ons and startup entries on your PC, which is where things like this prefer to live.