Said It Here

Antivirus blocking legitimate software updates and installers

Security software frequently flags valid installer downloads and software updates as false positives like Trojan:Script/Wacatac.C!ml and immediately quarantines them. This disrupts the patching process, blocks file downloads, and interferes with client updates.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Disabling or bypassing security software temporarily to allow the download and installation
  2. 2
    Checking the Defender timeline to analyze the behavior

In their words

Unedited, most upvoted first, each linked to the thread it came from.

Has anyone else received malware detections in ScreenConnect.ClientService.exe detected as Wacatac in the past day? I'm trying to determine whether this is a false positive or a potential infection.source ↗

Our third-party MDR team is saying it's malicious, ConnectWise support says it's a false positive.source ↗

__trj · r/sysadmin · 37 upvotes

Is anyone else seeing repeated false positives of Dell.TechHub.exe creating random rbf files or triggering services.exe?source ↗

terselated · r/sysadmin · 10 upvotes

When I downloaded the latest on-prem installer Windows Defender ate the download right away. Detection: Trojan:Script/Wacatac.C!mlsource ↗

jasonbwv · r/msp · 1 upvotes

Yeah same, then when i did get the installer downloaded and installed I seem to be having problems with it updating clients.source ↗

No_Lynx_2165 · r/msp · 1 upvotes

Yep same here. Never been an issue before with our security software but all the sudden with this update it's been getting quarantined.source ↗

Sea_Information6125 · r/msp · 1 upvotes

Where this came up

People with this problem also raised