False Positive (?) for Trojan.Script/Wacatac.B!ml


  1. Posts : 142
    10.0.19045, build 19045
       #1

    False Positive (?) for Trojan.Script/Wacatac.B!ml


    I have a Visual Basic (classic Not Net) complied program, I've run for over 20 years without a problem. If I run the program in the IDE, everything is fine. However, if the complied program is run, Windows Defender Virus (now with the latest upgrade) is saying it contains Trojan.Script/Wacatac.B!ml, and erases the EXE (complied) file. I've designated the EXE file as "Pin to StartUp" as it resides on a non-OS Win-10 partition (Drive D), and then executed Malwarebytes. Malwarebytes comes back clean. However Windows Defender Virus with a custom scan of the EXE in the non-OS drive, or if referenced as "Pin to StartUp", always thinks it is a virus and erases it.

    QUESTIONS
    I assume I am getting a false positive.
    1) Any suggestions to really confirm?
    2) How do I get Windows Defender Virus to ignore the EXE so I can use it?
    3) Is there anyway to get Malwarebytes to can just a file?

    Thanks
    David
      My Computer


  2. Posts : 6,869
    22H2 64 Bit Pro
       #2

    Just asking. Have you ever used/ installed Aura's Anti-Virus? That's not a suggestion to use it. It's just that someone else had a similar problem when that was installed alongside Defender.

    Add exclusion:

    Add or Remove Microsoft Defender Antivirus Exclusions in Windows 10

    Defender Exclusion Tool v1.3

    I've used the above but have never tested the following method.

    Add An Exclusion item to Windows Defender context menu
      My Computer


  3. Posts : 142
    10.0.19045, build 19045
    Thread Starter
       #3

    Callender THanks for responding.

    Have you ever used/ installed Aura's Anti-Virus?
    : NO

    Thanks for the info. Will check out for excluding once I double confirm system is clean.

    FWIW, the last one is a Shell Extension someone wrote that updates Explorer menus with this option.
      My Computer


  4. Posts : 6,869
    22H2 64 Bit Pro
       #4

    Possibly related.

    https://answers.microsoft.com/en-us/...d-1f69f7efdeb7

    Maybe scan with some other virus scanner. I can't recommend one.

    Also see:

    GitHub - LesFerch/ClearDefenderHistory: Clear Windows Defender History Files
      My Computer


  5. Posts : 142
    10.0.19045, build 19045
    Thread Starter
       #5

    Thanks for additional links.
    Microsoft Community link was helpful as at least someone else had a problem.
    FWIW: Rather than going with another virus checker, sent the file to M$ to check.
    Will see if I get a response.
    FWIW: Had already deleted history, and still coming up virus so didn't help this case.

    Regards,
    David
      My Computer


  6. Posts : 16,958
    Windows 10 Home x64 Version 22H2 Build 19045.4170
       #6

    David,

    You should be fine once you've added the file to Defender Exclusions as Callender suggested.
    Defender used to ignore its Exclusions a lot in the past but I've found it to be dependable for at least two years now.


    Denis
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:54.
Find Us




Windows 10 Forums