Jump to content

Recommended Posts

Posted

I ran a full scan with Microsoft Defender on my PC and it found the file AppData\Roaming\secure\QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml).

But before using Defender, I had run a full scan with Malwarebytes Free and Kaspersky Free and found nothing. Why did it detect this now?

Is this type of malware the kind that modifies, deletes, or corrupts files on the PC?

Posted
6 часов назад, carlos88 сказал:

QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml)

You've created too many threads on forums, don't you think? One, two, three, four, and plus one here. 🙂

Is this your file? If yes - upload this file via the link, wait for the analysis to be completed, and attach the link to the TIP's analysis here.

  • Like 1
Posted (edited)

But before using Defender, I had run a full scan with Malwarebytes Free and Kaspersky Free and found nothing. Why did it detect this now?

Is this type of malware the kind that modifies, deletes, or corrupts files on the PC?

 

QtWebKit4.dll Trojan:Win32/Wacatac.C!ml in Microsoft Defender

Edited by carlos88
Posted
1 минуту назад, carlos88 сказал:

Why did it detect this now?

Because KSN works, it analyzes new files and adds detections. But it's impossible to say for sure, maybe someone sent a sample to virlab.

By the way, someone just uploaded a file to TIP, and now there is a dynamic analysis.

  • Like 2
Posted
13 минут назад, carlos88 сказал:

this is type of malware 

You have been given a link to the Kaspersky verdict description, we don't have any other links. There are no malware analysts here, and we don't know what exactly this malware is doing. You are copying the Microsoft Defender verdict - it's some kind of general machine-learning detection.

  • Like 3
Posted

what good forum communitys malware analysts?

harlan4096
Posted

If You check carefully, both files have different hashes...

 

  • Like 1
Posted

this malware found in defender and kaspersky has modifies, deletes, or corrupts files on the PC?

harlan4096
Posted

Looks like that file was just probably a leftover, not resident in memory (detected via on demand scan).

 

We can't know it that file was once running or active, so if Your system is working fine... did You get previous detections from Defender or Kaspersky related with different files?

  • Like 2
Posted (edited)

i never used defender some recent use, i used kaspersky free, malwarebytes free, adwcleaner scan no results infections

 

i post photo folder localized file

 

 

 

virus Microsoft Defender2.png

virus Microsoft Defender.png

Edited by carlos88
  • Like 1
harlan4096
Posted

Remove manually that folder and done.

  • Like 2
Posted

@carlos88 And perform a full scan using Kaspersky and/or MS Defender. It's strange that you still don't want to delete this malicious file and carefully store it in a folder.)

  • Like 1
Posted

I deleted him

My question now is whether this file is actually malware or a false positive.
What is the real name and type of malware?
And does it modify, delete, or corrupt my personal files on my PC?

I performed a full scan with Kaspersky Free, Malwarebytes Free, and AdwCleaner a week or two ago with the software’s updated definitions database, but only Microsoft Defender found AppData\Roaming\secure\QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml)

i posted virus total result sca above

Posted
26 минут назад, carlos88 сказал:

My question now is whether this file is actually malware or a false positive.

The request has been sent successfully.)

  • Like 2
Posted
31 минуту назад, AlexeyK сказал:

whether this file is actually malware or a false positive.

The detection is correct, screenshot (browser translation). This file is malicious.

Screenshot_5.thumb.png.91292c32eec478f30fa4abca379cf4db.png

  • Like 2
Posted (edited)

because my kaspersky free, malwarebytes free, adwcleaner not detected i update definitions file AppData\Roaming\secure\QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml)
What is the real name and type of malware? in microsoft defender is Trojan:Win32/Wacatac.C!ml
And does it modify, delete, or corrupt my personal files on my PC?

Edited by carlos88
Posted
29 минут назад, carlos88 сказал:

What is the real name and type of malware?

Wacatac.C!ml - this name means almost nothing except detection using machine learning. Just a generic verdict.

You will laugh, but VirusTotal's MS engine doesn't detect this file anymore. 😄

  • Confused 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...