Hacked by "Trojan:Script/Wacatac.H!ml"

patrick kvaale 0 Reputation points
2026-09-12T01:16:59.7833333+00:00

I unknowingly installed a virus and windows labelled it as "Trojan:Script/Wacatac.H!ml". After the windows defender supposedly quarantined the virus my accounts got hacked anyways and started posting weird screenshots on my social media. Every time I restart I get 4 popups from something called "BlueSuite.exe" asking me to install "unbcl.dll". Windows defender can't detect anything and neither can malwarebytes. I even tracked down the "BlueSuite.exe" files and tried scanning them directly with malwarebytes but even then it did not recognize it as a virus or part of a virus. I tried a full scan, microsoft defender offline-scanning, malwarebytes scan, booting in safemode and clearing my temp folder, a quick and a full MRT scan yet nothing was found. Does anyone know any way to fix this?

Windows for home | Other | Security and privacy
0 comments No comments

2 answers

Sort by: Oldest
  1. AI answer

    2026-09-12T01:17:18.06+00:00

    If the popups return after every restart even after full scans, MRT, Safe Mode, and Microsoft Defender Offline, that matches the documented pattern where a hidden component is reinstalling malware or unwanted software at startup.

    Recommended next steps:

    1. Run Microsoft Defender Offline again if not already done from Windows Security
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
      • Select Scan options.
      • Select Windows Defender Offline scan > Scan now.
      • Save work first, because the PC restarts before the scan.
    2. Make sure Microsoft Defender protection features are enabled before scanning again
      • Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
      • Under Virus & threat protection settings, select Manage settings.
      • Turn Cloud-delivered protection and Automatic sample submission On.
      • Then under Virus & threat protection updates, select Check for updates and update threat definitions.
    3. Remove suspicious software and browser add-ons
      • Go to Start > Settings > Apps > Apps & features.
      • Sort by install date and uninstall anything unknown or recently added around the time of infection.
      • Remove suspicious browser add-ons as well.
      • This is especially relevant because unwanted software can persist through installed apps or browser modifiers.
    4. Avoid the original download source and similar sites
      • Malware can return if the same site, download, or email attachment is used again.
      • Use official download sources or the Microsoft Store.
      • Use Microsoft Edge with SmartScreen protection when browsing.
    5. If the system still shows popups or suspicious behavior, reset the PC
      • Back up files first.
      • Restore only from backups created before the infection if possible, because backups present during infection may already be modified.
      • After reset or reinstall, update Windows and installed software immediately.

    Given the account compromise already occurred, the practical cutoff is:

    • If startup popups continue after Offline scan, updated definitions, and uninstalling suspicious apps/add-ons, treat the system as not trustworthy and reset or reinstall Windows.
    • After cleanup or reset, continue using only clean backups and updated software.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. _AW_ 69,121 Reputation points Volunteer Moderator
    2026-09-12T02:13:10.18+00:00

    Please provide Farbar Recovery Scan Tool (FRST) logs for analysis.

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

    Note: If you are using Edge or Chrome, SmartScreen may initially block the download. Click on the three dots next to the warning and select Keep => Click the Delete drop arrow => Keep anyway.

    • If your computer's language is not English, rename FRST64.exe to FRST64English.exe
    • Run the tool, leave the default settings, and press Scan.
    • Zip the logs, FRST.txt and Addition.txt, then upload to a cloud storage service like OneDrive, Google Drive or gofile.io
    • Post the share link.

    https://support.microsoft.com/en-us/office/share-onedrive-files-and-folders-9fcc2f7d-de0c-4cec-93b0-a82024800c07

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.