Serious Discussion Eset & MD Win11 Conflict

DotNet

Level 1
Verified
I disable Eset temporarily via right click menu and MD turns it's protection on. I disable Eset to install repacked software that it mistakes as malware. It deletes them so I keep them in rar form until install. After install Eset is fine. Last night as soon as I disable Eset, MD turned itself on and deleted the repack. I opened up Win11 security center and verified that MD had turned itself on, set itself as the primary antivirus, and took corrective actions. So now I would have to temporarily disable Eset and then disable MD everytime. I figure someone here might have insight into this. I removed Eset for now.
 
I disable Eset temporarily via right click menu and MD turns it's protection on. I disable Eset to install repacked software that it mistakes as malware. It deletes them so I keep them in rar form until install. After install Eset is fine. Last night as soon as I disable Eset, MD turned itself on an […]


Hi DotNet. What you saw is Windows’ antivirus handoff working as designed, not necessarily an ESET/Defender conflict.

When ESET is registered and providing real-time protection, Defender normally moves out of active mode. If ESET is paused and Windows Security Center sees that no third-party product is currently providing real-time protection, Defender can automatically reactivate and become the primary antivirus. Microsoft explicitly documents this failover behavior in its Defender compatibility guidance. If ESET becomes fully active again, Defender should relinquish the primary role. A genuine conflict would be both products remaining active after ESET has resumed.

Removing ESET simply makes Defender the expected primary antivirus; it does not solve the underlying detection.

I would also be cautious about treating the repack as a confirmed false positive. Being quiet after installation proves little: the detected component may be an installer wrapper, patch or crack that is no longer present afterward—or something may have executed and removed itself. Two products objecting is not proof of malware, but it is enough reason not to defeat both products blindly.

Practical next steps:

  1. Open Windows Security → Virus & threat protection → Protection history and record the exact Defender detection name and affected file. Leave it quarantined for now; Microsoft notes that allowing/restoring it lets the file proceed (Protection History documentation).
  2. If you retained ESET's log or screenshot, compare its exact detection name. A PUA, HackTool or Riskware classification is different from a specific Trojan, Backdoor or Stealer detection.
  3. Prefer the software publisher’s original, digitally signed installer. With a third-party repack, there usually is no trustworthy vendor hash against which to verify the modified package.
  4. If you genuinely believe ESET made an error, submit the quarantined sample for analysis rather than disabling protection. ESET documents that process here.

ESET itself does not recommend disabling protection to install software. Windows making that inconvenient is rather the point of the safety net. If one of these detected repacks was already executed while protection was off—especially if the alert names a Trojan, stealer or backdoor—I would have the system checked through MalwareTips’ Malware Removal Assistance area rather than relying on a subsequent clean scan.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top