Antivirus blocking legitimate software updates and installers
Security software frequently flags valid installer downloads and software updates as false positives like Trojan:Script/Wacatac.C!ml and immediately quarantines them. This disrupts the patching process, blocks file downloads, and interferes with client updates.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Disabling or bypassing security software temporarily to allow the download and installation
- 2Checking the Defender timeline to analyze the behavior
In their words
Unedited, most upvoted first, each linked to the thread it came from.
“Has anyone else received malware detections in ScreenConnect.ClientService.exe detected as Wacatac in the past day? I'm trying to determine whether this is a false positive or a potential infection.”source ↗
“Our third-party MDR team is saying it's malicious, ConnectWise support says it's a false positive.”source ↗
“Is anyone else seeing repeated false positives of Dell.TechHub.exe creating random rbf files or triggering services.exe?”source ↗
“When I downloaded the latest on-prem installer Windows Defender ate the download right away. Detection: Trojan:Script/Wacatac.C!ml”source ↗
“Yeah same, then when i did get the installer downloaded and installed I seem to be having problems with it updating clients.”source ↗
“Yep same here. Never been an issue before with our security software but all the sudden with this update it's been getting quarantined.”source ↗
Where this came up
People with this problem also raised
- 3Why is security software generating so many false alerts?
- 6Why do smoke detectors go off randomly in the middle of the night?
- 2Why does Etsy keep incorrectly flagging my items as prohibited?
- 2Low oil warning light on even though oil is full
- 3Buyer falsely claims item is fake to force a return
- 4Why does IT send fake phishing emails that stress us out?