Microsoft classifies Trojan:Win32/Commando.A!ml as malware capable of performing actions chosen by an attacker. A completed scan does not necessarily mean that the detected item was removed. Please try these steps:
- Open Windows Security > Virus & threat protection > Protection history.
- Expand the latest Commando.A!ml detection and select Actions > Remove. If it is quarantined, select Remove; do not choose Allow on device.
- Go to Virus & threat protection > Protection updates > Check for updates.
- Select Scan options > Microsoft Defender Antivirus (offline scan) > Scan now. Save your work first because the computer will restart. This scan runs outside normal Windows, making persistent malware harder to hide.
An old entry can remain in Protection History even after removal, so check whether its status says Threat blocked/removed, Quarantined, Action needed, or Remediation incomplete. If a new detection appears after restarting, please share a screenshot of the expanded alert showing its status and affected items/file path, hiding any personal information. Also mention whether it returns immediately after startup or only after opening a particular program or browser. I’ll be waiting for that information to keep helping you.