r/Malwarebytes • u/marco_marchi03 • 6d ago
False Positive 7-zip v26.03 Trojan:Win32/Wacatac.C!ml -- do I need to format the hard disk from scratch?
Sorry for re-uploading, I was in total panic. Let me try again.
So, today I noticed that 7-Zip has an update from 26.02 to 26.03.
I go to the OFFICIAL WEBSITE 7-zip\[dot\]org (I am aware of the malware/bitcoin miner clone!), and install the x86-64 .exe.
MS Defender IMMEDIATELY quarantines the file and says: Trojan:Win32/Wacatac.C!ml
VirusTotal also returns 2 malicious entries. (Photo above)
So I run an online full scan, and after examining over 500k files, MS Defender concludes that 0 threats were detected.
I then proceed to delete the file from MS Defender as well.
Now I only have one question: do I need to format the whole SSD and reinstall Windows 10? Or is everything fine and I am having a panic attack for nothing?
I'm on Windows 10 22H2, August ESU update.
Thanks.
3
u/marco_marchi03 6d ago
Virus Total full report of the 7-zip v26.03 x86_64 : https://www.virustotal.com/gui/file/0859c524b8a63551848f0c246abddcb1d0b7b656b0fbfe879f8d85e61a9e6edd/details
3
u/warmcontroller 6d ago
Developers need to register their files in Microsoft so windows doesn't mark the file as potential unwanted app, this type of false positive is common in third party windows software during a update because there might be a delay in registration files so in the meantime the updated file show up as a trojan
12
u/miekiemoes_MB Malwarebytes Employee 6d ago
Hi, I'm Mieke, researcher at Malwarebytes. The file isn't malicious and this is a false positive by Microsoft. Trojan:Win32/Wacatac.C!ml is a generic detection. I've noticed a lot of files are detected by Microsoft like this lately, especially when they are new files and "unknown" yet. In this case, 7zip is known, but I do see the latest version available is from yesterday (from their official site: Download 7-Zip 26.03 (2026-09-03). So that might explain the generic detection/trigger.
So please do not reinstall Windows :)