Solved Question malware found

Status
Not open for further replies.
I discovered why the Caller.zip or rar was disappearing from the folder where the Caller.exe file is located. Microsoft Defender is quarantining it, accusing it of Trojan:Script/Wacatac.B!ml.
But the exe file remains in the folder and is not quarantined. It's very strange.
i send Caller.zip for Kaspersky specialist answer is clean file

DLL removed by Microsoft Defender:

Caller.exe:

folder files:
 

Attachments

  • virus Microsoft Defender.png
    virus Microsoft Defender.png
    69.2 KB · Views: 54
  • virus Microsoft Defender2.png
    virus Microsoft Defender2.png
    59.9 KB · Views: 52
  • Like
Reactions: Sorrento
I discovered why the Caller.zip or rar was disappearing from the folder where the Caller.exe file is located. Microsoft Defender is quarantining it, accusing it of Trojan:Script/Wacatac.B!ml.
But the exe file remains in the folder and is not quarantined. It's very strange.
i send Caller.zip for Kaspersky specialist answer is clean file

DLL removed by Microsoft Defender:

Caller.exe:

folder files:
The Caller.exe file is not malicious, only the DLL file is. The DLL file loads when you run the EXE file.

 
The DLL depends on an EXE to be malicious. The Caller was the .EXE and the DLL was the active malware? And why did my Kaspersky Free never detect this DLL when I used a complete scan? Only Defender detected it in the scan. These two files are in the same folder.
 
  • Like
Reactions: Sorrento
We don't know if there was a different exe, as You removed KF and its logs... that The Caller exe is not necessary the exe that triggers the dll...
 
Was the detection of QtWebKit4.dll Malware (Trojan:Win32/Wacatac.C!ml) by Kaspersky Free and Malwarebytes Free recently added? Is this a new malware?

If any free antivirus doesn't detect a Trojan in its scan because it lacks a signature (malware database), is real-time protection also affected, failing to detect and block it?
 
  • Like
Reactions: Sorrento
Was the detection of QtWebKit4.dll Malware (Trojan:Win32/Wacatac.C!ml) by Kaspersky Free and Malwarebytes Free recently added? Is this a new malware?

If any free antivirus doesn't detect a Trojan in its scan because it lacks a signature (malware database), is real-time protection also affected, failing to detect and block it?
Static (signature) and dynamic (post-execution) are two separate things. Even if an antivirus doesn't have a signature for a specific file, the antivirus' behaviour blocker or another module can intercept and block/delete the malware, and possibly revert its actions. For example, it can fail to delete it at first due to the lack of the signature in their database, but it can analyze the program's behaviour after executed and realise its malware.

So, all in all, it can fail at first and protect you at last.
 
Was the detection of QtWebKit4.dll Malware (Trojan:Win32/Wacatac.C!ml) by Kaspersky Free and Malwarebytes Free recently added? Is this a new malware?

If any free antivirus doesn't detect a Trojan in its scan because it lacks a signature (malware database), is real-time protection also affected, failing to detect and block it?

High chance this should be detected by Generic Detection of Kaspersky if no Folder Exclusions was done. But in your case, likely it was excluded. If it was not excluded, the Generic Detection should tag this and the file uploaded to KSN for further analysis either by automation or analyst. After that a proper name will be given or will be remove on detection.

This was only uploaded and further analyzed by Opentip on Oct 9,2025.
There were only 10 hits that it was so low to be considered for a Virus Outbreak.
 

Attachments

  • Screenshot_20251017-165218_(1).png
    Screenshot_20251017-165218_(1).png
    129.4 KB · Views: 41
So even if Kaspersky Free doesn't detect this malware in the scan, can it block and remove it in real-time protection? Does this malware have a triggering behavior?

Why didn't Malwarebytes Free detect it in the standard scan? Is this malware new?
 
  • Like
Reactions: Sorrento
So even if Kaspersky Free doesn't detect this malware in the scan, can it block and remove it in real-time protection? Does this malware have a triggering behavior?

Why didn't Malwarebytes Free detect it in the standard scan? Is this malware new?
You can read the following thread carefully with focus, it will help you :cry:
 
What are the names of types of malware that acess, modify, delete, or corrupt PC hdd and ssd files (Windows files and personal files, games, music, executables, ISO, IMG, RAR, ZIP, 7Z)? Does all malware have the potential to do this?

In this case, how are the malware QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml), Caller.exe (DrWeb detects
Trojan.DownLoader47.36298), and Caller.exe (VBA32 detects
TrojanPSW.Rhadamanthys) classified?

Caller.exe is related with QtWebKit4.dll? in same folder
 
What are the names of types of malware that acess, modify, delete, or corrupt PC hdd and ssd files (Windows files and personal files, games, music, executables, ISO, IMG, RAR, ZIP, 7Z)? Does all malware have the potential to do this?
Ransomware is the type of malware that can access, modify, delete, or damage files on your computer, which is not the case with malware on your computer.
 
If you all want to keep answering any future posts by classicaran, that's up to you, but IMO (FWIW) this thread should probably be closed as well.
Thank you for trying @icotonev

 
Thank you, friends, for sharing your malware experience. I'm learning a lot about this security world.

Trojans and viruses are the same thing?

only malware type ransomware is capable of modifying, deleting, or corrupting any type of file on my PC?

The only malware found for me was QtWebKit4.dll (Trojan:Win32/Wacatac.C!ml), Caller.exe (detects
Trojan.DownLoader47.36298), and Caller.exe (
TrojanPSW.Rhadamanthys), Trojan.Win32.Agent.xcajyl, Application.Fragtor.Generic
 
Status
Not open for further replies.