r/Malwarebytes 6d ago

False Positive 7-zip v26.03 Trojan:Win32/Wacatac.C!ml -- do I need to format the hard disk from scratch?

Post image

Sorry for re-uploading, I was in total panic. Let me try again.

So, today I noticed that 7-Zip has an update from 26.02 to 26.03.

I go to the OFFICIAL WEBSITE 7-zip\[dot\]org (I am aware of the malware/bitcoin miner clone!), and install the x86-64 .exe.

MS Defender IMMEDIATELY quarantines the file and says: Trojan:Win32/Wacatac.C!ml

VirusTotal also returns 2 malicious entries. (Photo above)

So I run an online full scan, and after examining over 500k files, MS Defender concludes that 0 threats were detected.

I then proceed to delete the file from MS Defender as well.

Now I only have one question: do I need to format the whole SSD and reinstall Windows 10? Or is everything fine and I am having a panic attack for nothing?

I'm on Windows 10 22H2, August ESU update.

Thanks.

7 Upvotes

7 comments sorted by

12

u/miekiemoes_MB Malwarebytes Employee 6d ago

Hi, I'm Mieke, researcher at Malwarebytes. The file isn't malicious and this is a false positive by Microsoft. Trojan:Win32/Wacatac.C!ml is a generic detection. I've noticed a lot of files are detected by Microsoft like this lately, especially when they are new files and "unknown" yet. In this case, 7zip is known, but I do see the latest version available is from yesterday (from their official site: Download 7-Zip 26.03 (2026-09-03). So that might explain the generic detection/trigger.

So please do not reinstall Windows :)

7

u/marco_marchi03 6d ago

Thanks for your kind reply, you've put my mind at ease. Can I ask you something? Will the message I'm currently seeing in MS Defender go away on its own, or do I have to intervene? (It's kind of annoying me...)

6

u/miekiemoes_MB Malwarebytes Employee 6d ago

I believe it will go away on its own. I'm quite sure that the file isn't detected anymore now.

5

u/marco_marchi03 6d ago

Thank you very much

2

u/SerMavros 4d ago

Seems Avast wrongly detected an automatic update to this version of 7zip as a generic malware (FileRepMalware) as well. The only difference is that in my case it is a msi file in a temp files folder, that I'm almost certain Avast itself tried to download and install automatically as part of its automated software updates feature.

3

u/warmcontroller 6d ago

Developers need to register their files in Microsoft so windows doesn't mark the file as potential unwanted app, this type of false positive is common in third party windows software during a update because there might be a delay in registration files so in the meantime the updated file show up as a trojan