Hi @Mahavir Saroj ,
Yes, Microsoft Anti-Malware deletes malicious files stored on Virtual Machines, as documented here:
"Malware remediation - automatically takes action on detected malware, such as deleting or quarantining malicious files and cleaning up malicious registry entries."
https://learn.microsoft.com/en-us/azure/security/fundamentals/antimalware
You can view the logs in your Storage Account once they are configured. As mentioned in the document, the antimalware events are collected from the Windows event system logs to your Azure Storage account. You can configure the Storage Account for your Virtual Machine to collect Antimalware events by selecting the appropriate storage account.
If you want to leverage these features, you need to enable antimalware event collection for a virtual machine using the Azure Preview Portal:
- Click any part of the Monitoring lens in the Virtual Machine blade
- Click the Diagnostics command on Metric blade
- Select Status ON and check the option for Windows event system
- . You can choose to uncheck all other options in the list, or leave them enabled per your application service needs.
- The Antimalware event categories "Error", "Warning", "Informational", etc., are captured in your Azure Storage account.
Note that the Antimalware client isn't installed by default for Virtual Machines and is available as an optional feature through the Azure portal and Visual Studio Virtual Machine configuration under Security Extensions.
https://learn.microsoft.com/en-us/azure/security/fundamentals/antimalware
Let me know if this helps and if you have further questions.
If the information helped you, please Accept the answer. This will help us and improve searchability for others in the community who may be researching similar questions.