Skip to content

Windows Defender Detects Trojan #12

@kevinelwell

Description

@kevinelwell

OS: Windows 11 Pro Version 25H2 (OS Build 26200.7840)
Running the sysmon-builder.exe as non-privileged user

This looks like a very useful tool, and I would like to use it. However, after Windows Defender detected a trojan, I have reservations.

After unzipping and executing the sysmon-builder.exe, I received a prompt immediately from Windows Defender that a trojan was detected: Trojan:Win32/Bearfoos.B!ml. Defender then quarantined the sysmon-builder.exe.

Image

VirusTotal scan of sysmon-builder-windows.zip came back clean, as did the Windows Defender scan of sysmon-builder-windows.zip file.

Scanning sysmon-builder.exe with VirusTotal did show some detections.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions