AI Agent scans event logs, finds trojan that top antivirus tools missed
Zealousideal_Aide787 · reddit · 2026-09-23
A Reddit user asked an AI agent (DS 4.1 flash) to investigate random crashes. Given a few screenshots, the agent scanned Windows event logs on its own and surfaced suspicious files — only then did Windows Defender trigger and quarantine them.
One suspicious process was still running, so the agent wrote a script to kill it, deleted the files, and rebooted for an offline Defender scan. The malware was identified as BAT/Killa.SIB!MTB, disguised with legitimate Windows filenames (wlanext, wmpnetwk, WinRing0x64) in a oddly named directory.
Takeaway: none of the top-tier antivirus products caught it, the agent did — but the author now realizes handing an agent that much system access is risky and plans to run it inside a VM from now on.
More from Fun
- Burkov skew AI hype: 'deterministic LLMs' and 'first agents' are old tricks rebranded — burkov · 2026-09-23
- Dev claims 20k more commits coming: Opus 5.5 and GPT-6 Sol supercharge his output — doodlestein · 2026-09-23
- Opus 5.5 rebuilds San Francisco in Unreal, with everything powered by Jev — emax · 2026-09-23
- Claude 5.5 (live) keeps generating user turns, reports user — BlackHC · 2026-09-23
- Opus 4.6 generates its own profile picture: "This is my face" — repligate · 2026-09-23
- A JEV-powered Wireshark classifier accidentally uncovered real backdoors on a home network — multiply_matrix · 2026-09-23