Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Trojan:Script/Wacatac.B!ml is a Microsoft Defender detection label, not the name of one uniquely identifiable malware sample. The alert alone cannot tell you whether the file executed, what it attempted to do, or whether your PC is still infected.

What matters most is the affected file path, whether Defender blocked it before execution, the action recorded in Windows Security, whether the alert returns, and the results of follow-up scans. A Malwarebytes forum topic marked “resolved” means the submitted cleanup case was considered complete; it is not, by itself, proof that every file, persistence mechanism, or account is safe.

What Trojan:Script/Wacatac.B!ml means

The name is built from several parts:

  • Trojan: Defender believes the item may behave maliciously while appearing to be something else.
  • Script: The object may be a script or contain script-like content, such as JavaScript, JScript, VBScript, PowerShell, batch commands, HTML active content, macros, or an installer component. It does not necessarily mean the file ends in .js or .vbs.
  • Wacatac.B: A vendor detection-t taxonomy label. It does not describe one fixed malware family with identical capabilities.
  • !ml: A marker commonly associated with Microsoft’s machine-learning, heuristic, or cloud-assisted detection logic. It can identify new or modified threats, but the suffix alone does not prove that the file is malicious.

Do not infer from this name alone that the file stole passwords, installed ransomware, opened remote access, or downloaded another payload. Those conclusions require evidence from the file, its behavior, and the scan logs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s current Windows Security guidance is available in its Windows Security documentation.

#1 Best Overall
Sale
McAfee Total Protection 2026 Antivirus Software for 1 Device | Auto-Renews
  • DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
  • SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
  • SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
  • IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
  • SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware

Does “resolved” mean the PC is clean?

There are three different meanings of “resolved” that are easy to confuse:

  1. Defender resolved the detection: Windows Security recorded an action such as blocking, quarantining, or removing the item.
  2. A Malwarebytes forum case was resolved: A volunteer helper considered the logs and cleanup steps sufficient for that specific submitted computer.
  3. The whole incident is conclusively investigated: The file, persistence, secondary payloads, browser data, and account exposure have all been ruled out.

The first or second does not automatically establish the third. A quarantined file may never have executed, but quarantine alone does not prove that it never ran. Likewise, removing one file does not prove that no scheduled task, browser extension, downloaded payload, or compromised account remains.

A cautious conclusion is appropriate: if the only detected file was blocked or removed, Full and Offline scans are clean, no suspicious persistence is present, and the alert does not return, the immediate incident is probably contained. If the file executed, the alert recurs, or the logs show persistence or credential-stealing behavior, treat the PC as potentially compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check exactly what Defender did

On current Windows 10 and Windows 11 builds, open:

Windows Security → Virus & threat protection → Protection history

Labels can vary by Windows edition, policy settings, and future updates. Open the relevant entry and record:

  • The threat name.
  • The affected file or item path.
  • The date and time.
  • The current status.
  • The action taken: blocked, quarantined, removed, or allowed.

Save a screenshot or export the report before deleting logs. Microsoft’s Virus & threat protection guidance explains the relevant Windows Security controls.

Rank #2
Sale
Norton 360 Deluxe Antivirus, 3 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

Do not restore, allow, or add an exclusion for the item merely because a familiar program is involved. If Defender says the item was allowed, investigate it immediately rather than treating the alert as resolved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The file path is often more useful than the detection name

A detection in Downloads, a browser cache, a temporary extraction directory, an email attachment folder, or a removable drive may indicate a blocked download. That is encouraging, but it is not proof that the file never executed.

More investigation is warranted when the item is in:

  • %AppData% or %LocalAppData%.
  • A Startup folder or a location associated with a Run key.
  • A newly installed application directory.
  • A browser extension directory.
  • A system folder containing an unfamiliar executable.
  • A location from which the file is repeatedly recreated.

Location is evidence, not a verdict. Legitimate applications use AppData, and malicious files can initially arrive in Downloads. Compare the path with the file’s source, signature, timestamp, and behavior.

What to do immediately

  1. Do not restore or allow the item.
  2. Disconnect temporarily if the alert is active or recurring, or if a suspicious executable was opened.
  3. Preserve evidence. Record the name, path, timestamp, action, and any Malwarebytes or FRST reports.
  4. Avoid sensitive logins on the potentially affected PC until the initial scans are complete.
  5. Remove the likely source after preserving the information: the download, archive, installer, extracted folder, attachment, or suspicious extension.

If the item came from a crack, activator, cheat, torrent, unofficial mirror, or unexpected attachment, use the more cautious response. Do not open it again to “test” whether it is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Run a staged cleanup and verification

1. Update Windows Security

Install pending Windows updates and update Defender security intelligence before scanning. A scan using outdated definitions provides weaker evidence.

Rank #3
Sale
McAfee Total Protection 2026 Antivirus Software for 3 Devices | Auto-Renews
  • DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
  • SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
  • SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
  • IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
  • SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware

2. Run a Full scan

Start a Full scan from Windows Security. Let it finish, restart the PC, and check Protection history again.

3. Run Microsoft Defender Offline when risk is higher

Use Microsoft Defender Offline if the file was opened or executed, the alert returns after reboot, security tools were disabled, or persistence is suspected. It scans outside the normal Windows environment, which can help when malware interferes with or hides from the running operating system. See Microsoft’s Defender Offline documentation.

4. Use one reputable second opinion

A second scanner is useful for heuristic or machine-learning detections, recurring alerts, suspicious downloads, browser redirects, unknown startup items, or disagreement between security products. Malwarebytes offers an official scanner download and maintains a support portal. ESET Online Scanner and Microsoft Safety Scanner are other on-demand options:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not install several products with overlapping real-time protection and assume that more is automatically better. For a second opinion, prefer an on-demand scanner while keeping one primary real-time security product configured normally.

Review persistence only when you can interpret it

If the same file returns, inspect Startup Apps, Startup folders, Scheduled Tasks, recently installed applications, suspicious services, browser extensions, proxy and DNS settings, security exclusions, and unknown administrator accounts.

Advanced users or trained malware-removal helpers may use FRST, Autoruns, or Event Viewer. Microsoft’s Autoruns documentation is an appropriate reference. Do not copy registry deletions, scheduled-task removals, or FRST fixes from another person’s Malwarebytes forum log. Those instructions are tailored to one computer, and deleting the wrong entry can damage Windows or remove a legitimate application.

Rank #4
Bitdefender Total Security 2026 – Complete Antivirus and Internet Security Suite – 5 Devices | 1 Year Subscription | PC/Mac | Activation Code by Mail
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
  • SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
  • ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
  • ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.

What recurring alerts usually mean

A repeated Wacatac alert does not necessarily mean the exact same infection is actively running. Compare the precise path and timestamp in each alert. Common explanations include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The original ZIP, RAR, 7z, ISO, or installer remains on the disk.
  • A browser or download manager is downloading the file again.
  • OneDrive, Dropbox, Google Drive, or another sync service is restoring it.
  • An installer, scheduled task, or parent application is recreating it.
  • Protection History is showing an old entry rather than a live detection.
  • A related component was missed.

Delete the source archive or installer after preserving its details, inspect browser downloads and extensions, pause or investigate synchronization, review startup and scheduled tasks, and run Defender Offline plus a second-opinion scan. Do not erase Defender’s internal history as a first-line “fix”; hiding the entry does not remove the file or persistence mechanism.

When should you change passwords?

Change passwords from a separate, known-clean device if the suspicious file was opened or executed, credentials were entered afterward, the browser behaved strangely, an infostealer or credential store was involved, or a suspicious extension was installed.

Start with the primary email account, then protect banking, password-manager, cryptocurrency, and other high-value accounts. Enable multifactor authentication and review recent sessions and recovery settings.

Changing passwords protects accounts; it does not clean an infected PC. If the computer may have captured the new password, change it again after the device is cleaned or reinstalled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Could this be a false positive?

Yes, but “the program is legitimate” is not enough. A legitimate application can be repackaged, modified, compromised, or bundled with unwanted components.

Best Value
Sale
Norton 360 Deluxe Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

False-positive review is more reasonable when the file:

  • Came directly from the official vendor.
  • Has a valid digital signature from the expected publisher.
  • Matches a checksum published by that vendor.
  • Is a known internal tool or developer build.
  • Is not detected by independent scanners.
  • Was flagged immediately after compilation or packaging.

Ask the vendor or Microsoft for confirmation before restoring it. Treat the item as malicious when it came from an unofficial source, ran from a random temporary or AppData location, is unsigned, recreates itself, or is detected by multiple tools.

Do not add an exclusion simply to stop the warning. Microsoft explains that Defender exclusions reduce protection and should be used only when the file is verified and the risk is understood.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When is reinstalling Windows justified?

A clean reinstall is usually disproportionate for a blocked download that never executed and is followed by clean scans. It becomes a reasonable high-confidence option when:

  • Malware executed with administrator privileges.
  • Security tools were disabled or settings were altered.
  • Credential theft is suspected.
  • Persistence cannot be removed confidently.
  • Symptoms continue despite scanning.
  • You need a trustworthy baseline for sensitive work.

Back up only personal documents after scanning them; do not blindly restore executables, scripts, cracked software, browser profiles, or suspicious archives. Reinstall from trusted installation media and change important passwords from a clean device.

How to interpret the outcome

Situation Best interpretation and response
Defender blocked a file in Downloads before it was opened Delete the source, update Defender, run a follow-up scan, and monitor.
The file was opened or executed Run Full and Offline scans, obtain a second opinion, review persistence, and consider password changes.
The file came from a crack, activator, cheat, or torrent Assume higher risk; remove associated software and consider a clean reinstall.
The alert appears only inside an old archive Delete or quarantine the archive; do not extract or restore it.
The same file returns after deletion Investigate sync, scheduled tasks, browser downloads, and parent installers.
Defender says resolved but symptoms remain Treat the incident as unresolved and escalate investigation or reinstall Windows.
Malwarebytes and Defender disagree Compare paths, hashes, timestamps, and actions; do not automatically trust the “clean” result.
You cannot determine whether the file ran Assume it may have run and take the more cautious path.

Do you need to buy antivirus software?

Not automatically. A single Defender detection that was blocked or quarantined, followed by clean verification scans and no recurring symptoms, does not by itself require a paid subscription.

Windows users can continue with the built-in Defender Antivirus. An optional Malwarebytes or ESET on-demand scan can provide independent confirmation. A paid security suite makes more sense when you specifically need features beyond basic malware protection, such as multi-device management, identity monitoring, VPN access, parental controls, or centralized family protection. Avoid fear-based upselling and do not buy a product solely because a generic cleanup article lists it.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Relevant official pages include Microsoft Defender and Malwarebytes pricing. Features, regions, renewal terms, and prices can change, so check the vendor directly before purchasing.

Quick Recap

SaleBestseller No. 1
McAfee Total Protection 2026 Antivirus Software for 1 Device | Auto-Renews
McAfee Total Protection 2026 Antivirus Software for 1 Device | Auto-Renews
24/7 CUSTOMER SUPPORT – available by phone or chat, helpful articles, helps troubleshoot
$22.99
SaleBestseller No. 3
McAfee Total Protection 2026 Antivirus Software for 3 Devices | Auto-Renews
McAfee Total Protection 2026 Antivirus Software for 3 Devices | Auto-Renews
24/7 CUSTOMER SUPPORT – available by phone or chat, helpful articles, helps troubleshoot
$29.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.