Skip to content

W10UI triggers defender behavior detection #66

Description

@habzg

While running W10UI to integrate updates into a mounted image, this detection appears twice:

Threat blocked
2026. 06. 13.
Severe

Detected: Trojan:Win32/Commando.A!ml
Status: Removed
A threat or app was removed from this device.

Date: 2026. 06. 13.
Details:
This program is dangerous and executes commands from an attacker.

Affected items:
CmdLine: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nop -c $r='D:\W10UItemp_27723\W10UIreg.txt'; $f=[IO.File]::ReadAllText('D:\Files\W10UI.cmd') -split ':cbsreg\:.*';iex ($f[1])

The script seems to fail after this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions