data from windows themselves:
detected: Trojan:Script/Wacatac.C!ml
status: removed
a threat or app was removed from this device
date: 10/11/2025 3:28 PM
details: This program is dangerous and executes commands from an attacker.
affected items:
file: C:\Users________\Downloads\libloot-0.28.2-win64.7z
webfile: C:\Users\_______\Downloads\libloot-0.28.2-win64.7z|https://release-assets.githubusercontent.com/github-production-release-asset/81589680/2e8b217e-3620-4055-9a4a-65d773f4bb2d?sp=r&sv=2018-11-09&sr=b&spr=https&se=2025-10-11T21%3A01%3A36Z&rscd=attachment%3B+filename%3Dlibloot-0.28.2-win64.7z&rsct=application%2Foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2025-10-11T20%3A00%3A53Z&ske=2025-10-11T21%3A01%3A36Z&sks=b&skv=2018-11-09&sig=vv13gMJCds%2F72EXo64BJfl1ZF4%2FXcsJ2tFxPXQD0xjA%3D&jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmVsZWFzZS1hc3NldHMuZ2l0aHVidXNlcmNvbnRlbnQuY29tIiwia2V5Ijoia2V5MSIsImV4cCI6MTc2MDIxNjMwNSwibmJmIjoxNzYwMjE0NTA1LCJwYXRoIjoicmVsZWFzZWFzc2V0cHJvZHVjdGlvbi5ibG9iLmNvcmUud2luZG93cy5uZXQifQ.JFohI-J3emy_e_Rgu0R8otxbkGxk7vnd6p004wJI9HA&response-content-disposition=attachment%3B%20filename%3Dlibloot-0.28.2-win64.7z&response-content-type=application%2Foctet-stream|pid:4704,ProcessStart:134046881058168882