Defender detected Win32/Commando.A!ml

Kris Raymond 0 Reputation points
2026-07-29T23:56:48.4766667+00:00

I've done the full scan and Defender is still detecting Win32/Commando.A!ml. Is there a way to remove it?

Windows for home | Windows 11 | Security and privacy

1 answer

Sort by: Most helpful
  1. Jeronimo Fuerte 44,485 Reputation points Independent Advisor
    2026-07-30T00:34:32.5233333+00:00

    Microsoft classifies Trojan:Win32/Commando.A!ml as malware capable of performing actions chosen by an attacker. A completed scan does not necessarily mean that the detected item was removed. Please try these steps:

    1. Open Windows Security > Virus & threat protection > Protection history.
    2. Expand the latest Commando.A!ml detection and select Actions > Remove. If it is quarantined, select Remove; do not choose Allow on device.
    3. Go to Virus & threat protection > Protection updates > Check for updates.
    4. Select Scan options > Microsoft Defender Antivirus (offline scan) > Scan now. Save your work first because the computer will restart. This scan runs outside normal Windows, making persistent malware harder to hide.

    An old entry can remain in Protection History even after removal, so check whether its status says Threat blocked/removed, Quarantined, Action needed, or Remediation incomplete. If a new detection appears after restarting, please share a screenshot of the expanded alert showing its status and affected items/file path, hiding any personal information. Also mention whether it returns immediately after startup or only after opening a particular program or browser. I’ll be waiting for that information to keep helping you.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.