Trojan:Win32/Wacatac.B!ml >> Microsoft Safety Scanner found several infected files during scan but end result shows nothing

~OSD~ 2,131 Reputation points
2024-03-30T06:34:43.6433333+00:00

Windows Defender has detected the Trojan:Win32/Wacatac.B!ml

User's image

I started the scan with MS Safety Scanner, it took about 24 hours to complete the full scan.

During the scan, I can see that it shows about 250 infected files. However, the result, shows that everything is correct, see below.

Is it normal or a limitation of the tool?

User's image

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,818 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
0 comments No comments
{count} votes

Accepted answer
  1. Reza-Ameri 16,856 Reputation points
    2024-04-01T11:53:53.5866667+00:00

    No, if you trust this file and allow it, then Microsoft Defender will only ignore this file and it will detect and remove other .exe files if they are being detect as malware. In case you run scan and it shows everything is fine and only mark this file as allowed (which you did), then you are good to protected.
    If you believe the .exe is safe, you may submit it to Microsoft as incorrect detection, so they could check and if it consider as safe, then remove it from detection:
    https://www.microsoft.com/en-us/wdsi/filesubmission

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Reza-Ameri 16,856 Reputation points
    2024-03-30T11:46:42.9633333+00:00

    This is a known issue that during scan, it will find files which is suspicious of being malware , however as scan goes on and check those files, it will find out they are safe. The main result is the final one and if it shows you are safe, then you are good to go and you may ignore the message during scan.
    In case, you are suspect of malware infection, you may run scan with Microsoft Defender Offline too:
    https://support.microsoft.com/en-us/windows/help-protect-my-pc-with-microsoft-defender-offline-9306d528-64bf-4668-5b80-ff533f183d6c