AI Agent scans event logs, finds trojan that top antivirus tools missed

Zealousideal_Aide787 · reddit · 2026-09-23

A Reddit user asked an AI agent (DS 4.1 flash) to investigate random crashes. Given a few screenshots, the agent scanned Windows event logs on its own and surfaced suspicious files — only then did Windows Defender trigger and quarantine them.

One suspicious process was still running, so the agent wrote a script to kill it, deleted the files, and rebooted for an offline Defender scan. The malware was identified as BAT/Killa.SIB!MTB, disguised with legitimate Windows filenames (wlanext, wmpnetwk, WinRing0x64) in a oddly named directory.

Takeaway: none of the top-tier antivirus products caught it, the agent did — but the author now realizes handing an agent that much system access is risky and plans to run it inside a VM from now on.

Original post →

More from Fun

Fun channel →