Hacked by "Trojan:Script/Wacatac.H!ml"

patrick kvaale 0 Reputation points
2026-09-12T01:16:59.7833333+00:00

I unknowingly installed a virus and windows labelled it as "Trojan:Script/Wacatac.H!ml". After the windows defender supposedly quarantined the virus my accounts got hacked anyways and started posting weird screenshots on my social media. Every time I restart I get 4 popups from something called "BlueSuite.exe" asking me to install "unbcl.dll". Windows defender can't detect anything and neither can malwarebytes. I even tracked down the "BlueSuite.exe" files and tried scanning them directly with malwarebytes but even then it did not recognize it as a virus or part of a virus. I tried a full scan, microsoft defender offline-scanning, malwarebytes scan, booting in safemode and clearing my temp folder, a quick and a full MRT scan yet nothing was found. Does anyone know any way to fix this?

Windows for home | Other | Security and privacy
0 comments No comments

2 answers

Sort by: Newest
  1. _AW_ 69,121 Reputation points Volunteer Moderator
    2026-09-12T02:13:10.18+00:00

    Please provide Farbar Recovery Scan Tool (FRST) logs for analysis.

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

    Note: If you are using Edge or Chrome, SmartScreen may initially block the download. Click on the three dots next to the warning and select Keep => Click the Delete drop arrow => Keep anyway.

    • If your computer's language is not English, rename FRST64.exe to FRST64English.exe
    • Run the tool, leave the default settings, and press Scan.
    • Zip the logs, FRST.txt and Addition.txt, then upload to a cloud storage service like OneDrive, Google Drive or gofile.io
    • Post the share link.

    https://support.microsoft.com/en-us/office/share-onedrive-files-and-folders-9fcc2f7d-de0c-4cec-93b0-a82024800c07

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-12T01:17:18.06+00:00

    If the popups return after every restart even after full scans, MRT, Safe Mode, and Microsoft Defender Offline, that matches the documented pattern where a hidden component is reinstalling malware or unwanted software at startup.

    Recommended next steps:

    1. Run Microsoft Defender Offline again if not already done from Windows Security
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
      • Select Scan options.
      • Select Windows Defender Offline scan > Scan now.
      • Save work first, because the PC restarts before the scan.
    2. Make sure Microsoft Defender protection features are enabled before scanning again
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
      • Under Virus & threat protection settings, select Manage settings.
      • Turn Cloud-delivered protection and Automatic sample submission On.
      • Then under Virus & threat protection updates, select Check for updates and update threat definitions.
    3. Remove suspicious software and browser add-ons
      • Go to Start > Settings > Apps > Apps & features.
      • Sort by install date and uninstall anything unknown or recently added around the time of infection.
      • Remove suspicious browser add-ons as well.
      • This is especially relevant because unwanted software can persist through installed apps or browser modifiers.
    4. Avoid the original download source and similar sites
      • Malware can return if the same site, download, or email attachment is used again.
      • Use official download sources or the Microsoft Store.
      • Use Microsoft Edge with SmartScreen protection when browsing.
    5. If the system still shows popups or suspicious behavior, reset the PC
      • Back up files first.
      • Restore only from backups created before the infection if possible, because backups present during infection may already be modified.
      • After reset or reinstall, update Windows and installed software immediately.

    Given the account compromise already occurred, the practical cutoff is:

    • If startup popups continue after Offline scan, updated definitions, and uninstalling suspicious apps/add-ons, treat the system as not trustworthy and reset or reinstall Windows.
    • After cleanup or reset, continue using only clean backups and updated software.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.