SoftPerfect Network Scanner
Microsoft Windows Defender blocks Network Scanner
Started by Daniel
Daniel
Microsoft Windows Defender blocks Network Scanner 26 January 2025, 13:23 |
When I checked the file in VirusTotal, only ESET said its a virus. Microsoft and all other antivirus vendors were OK. I am aware that ESET is unreliable, but I am concerned about Windows Defender.
Then I asked my colleague to check the file on his computer. His Windows Defender showed "Win32/Wacatac" trojan, and Sophos AV also flagged the file.
Unfortunately we cannot add NetScanner to exclusions/whitelist because Windows Defender is blocking it.
|
Microsoft Windows Defender blocks Network Scanner - False Positive 26 January 2025, 13:34 |
Admin Registered: 11 years ago Posts: 1 041 |
The detection by Windows Defender as "Wacatac" is due to the limitations of machine learning algorithms used by some antivirus programs. If you search online for "Win32/Wacatac" or "Script/Wacatac", you will see that it is frequently associated with false positives.
Network scanning tools often get flagged because they have capabilities that can be misinterpreted by antivirus software. Terms such as "NetScanner", "NetScan", "NetTool", "Hacktool", "Unwanted", "PUA", "Potentially Unsafe", "Riskware" or even "Trojan" are commonly used in these cases. However these tools are instead designed to assist network administrators in maintaining secure and efficient networks. Their purpose is to help network administrators to discover and remove network vulnerabilities before any malicious actor can exploit them.
We recommend submitting netscan.exe file to Microsoft as a false positive detection. This can help improve their detection algorithms and prevent similar issues in the future. Once Microsoft fix their erroneous detection, they should remove the file block as well.
John17
Problem with Windows Defender: false positive detection of "Wacatac" trojan 14 May 2025, 00:22 |
|
Re: Problem with Windows Defender: false positive detection of "Wacatac" trojan 14 May 2025, 07:16 |
Admin Registered: 19 years ago Posts: 3 647 |
Unfortunately, some antivirus engines still flag it due to behavioural heuristics, as it includes functions like port scanning and device probing - features often misinterpreted as malicious.
If you have a specific suggestion on how to better align with security policies without removing core functionality, we will be glad to hear it. As obviously we cannot simply remove the essential network-scanning features from the Network Scanner installer, even if some antivirus engines don't like them.
Hansruedi
Re: Problem with Windows Defender: false positive detection of "Wacatac" trojan 21 June 2025, 01:36 |
|
Re: Problem with Windows Defender: false positive detection of "Wacatac" trojan 21 June 2025, 13:17 |
Admin Registered: 11 years ago Posts: 1 041 |
rmpf2
Re: Problem with Windows Defender: false positive detection of "Wacatac" trojan 22 June 2025, 21:43 |
Paul
What to do when Microsoft Defender blocks and deletes Network Scanner 25 June 2025, 11:01 |
But then I got an idea: I tried downloading the installer edition of the same Network Scanner version - and everything went well.
So my suggestion to everyone who is currently struggling with Microsoft Defender: try downloading the other edition of Network Scanner. If your Defender blocks the portable - try the installer. And if your Defender blocks the installer - try the portable. It really helped me.