While running W10UI to integrate updates into a mounted image, this detection appears twice:
Threat blocked
2026. 06. 13.
Severe
Detected: Trojan:Win32/Commando.A!ml
Status: Removed
A threat or app was removed from this device.
Date: 2026. 06. 13.
Details:
This program is dangerous and executes commands from an attacker.
Affected items:
CmdLine: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nop -c $r='D:\W10UItemp_27723\W10UIreg.txt'; $f=[IO.File]::ReadAllText('D:\Files\W10UI.cmd') -split ':cbsreg\:.*';iex ($f[1])
The script seems to fail after this.
While running W10UI to integrate updates into a mounted image, this detection appears twice:
The script seems to fail after this.