Page 1 of 1

Windows defender detects Trojan:Win32/Wacatac.B!ml

Posted: Sat Sep 11, 2021 11:48 am
by marimo
Hi Brad,

I"m re-investing time in our dance-club for automating the music, but encountered a problem.
When i download a 64 bit version of BallroomDJ, defender detects a Trojan:Win32/Wacatac.B!ml, and deletes the installer.

Tried to read about it on different forums, but it's mislaeding information.
One says it's a threat, another says it's a false positive.

Any recommendations??

greetings,
Mario (Marimo)

Re: Windows defender detects Trojan:Win32/Wacatac.B!ml

Posted: Sun Sep 12, 2021 6:31 am
by bll
There is no malware present in BallroomDJ.

The windows defender definitions should be updated by now.
I have included the instructions that microsoft sent to update the virus definitions.

This false positive has been reported to microsoft before.
These false positives from the anti-virus companies are a real problem, as many have no easy way to report the false positive.
Or were reported, and didn't remove the bad entry from their database.
Analyst comments:

We have removed the detection. Please follow the steps below to clear cached detection and obtain the latest malware definitions.

1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
3. Run "MpCmdRun.exe -SignatureUpdate"

Re: Windows defender detects Trojan:Win32/Wacatac.B!ml

Posted: Sun Sep 12, 2021 7:04 am
by bll
It does appear that Windows 8 at least is detecting this as malware again.
I am re-reporting this to microsoft.
These anti-virus false positives are going to kill off small software projects.

On Windows 8 32-bit. 64-bit seems ok.

Re: Windows defender detects Trojan:Win32/Wacatac.B!ml

Posted: Sun Sep 12, 2021 9:05 am
by marimo
Hi,
I've followed the instructions you added, and now everythinf went just fine from downloading till installation.

thanks!