My offline antivirus stops at 93% and doesn't provide any info

Larson Lanka 0 Reputation points
2026-07-24T03:30:55.77+00:00

So I was running Microsoft's Antivirus offline's scan to catch a Trojan:Win32/Commando.A!ml type when the scan stopped at 93%. I've check C:\Windows\debug and the mrt.log file but didn't find my current scan and the malware keeps getting blocked by the system's antivirus. What happend to the scan? msrt doesn't help

I'm on "Windows 11 Home Single Language"

Moved from <Microsoft Security | Microsoft Defender | Other>

Windows for home | Windows 11 | Security and privacy
0 comments No comments

Answer accepted by question author

Lychee-Ng 25,605 Reputation points Microsoft External Staff Moderator
2026-07-29T09:36:40.1633333+00:00

Hi Larson Lanka

I understand why how concerning it is to see your scan stuck, especially since you're not sure if the Trojan was actually removed. The good news is that Defender Offline Scan stopping (particularly over 90%) doesn't always mean it failed. There have been reports on progress indicator being inaccurate in some cases (e.g. Why does my windows defender offline scans stop at 91%, and is it any way to fix it? - Microsoft Q&A). Instead of focusing there, consider: 

1 - Check Protection History 

  • Open Windows Security > Virus & threat protection
  • Select Protection history > look for Trojan:Win32/Commando.A!ml
  • Note the file path and the action taken (Blocked, Quarantined, Removed, etc.). 
  • If the detection points to a specific file > manually delete its container (folder/ZIP/...) 

2 - If Defender keeps detecting the threat but never quarantines a file: 

  • The detection may be cloud/heuristic-based and could be a false positive. 
  • Note the exact file path, process name, or archive name associated with the detection. 
  • Submit the file to Microsoft Security Intelligence for analysis. 

3 - Update Defender and run another scan 

  • Open Windows Security > Virus & threat protection
  • Under Protection updates, click Check for updates
  • Run a Full scan > Run Microsoft Defender Offline scan.

If the threat keeps returning, please let me know the exact detection path shown in Protection History, and whether the Offline scan eventually reboots normally or freezes indefinitely at 93%. That information will help determine whether the scan is actually failing or whether the malware is simply being detected repeatedly from a persistent location.


If you think the answer is helpful to you, please click "Yes" below. If you have extra questions about this answer, feel free to click "Add Comment" and ask! 

Note: Follow the steps in our documentation if you want to enable and receive the related email notifications for this thread.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.