Share via

Intune: Active malware

Anonymous
2022-09-08T12:50:13+00:00

We currently experiencing problems with removing active malware on multiple devices in Intune called (Malware name:EUS: Win32/TvmWarn). This malware is currently active on several devices that are enrolled in Intune. We updated the anti-virus signatures and ran a full scan on all devices, but this malware is still active. NB: We don't have physical access to these devices, we manage them via Intune.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Anonymous
    2022-09-14T01:41:48+00:00

    The alerts show the last 15 days I believe.

    If you have the option for advanced hunting under security.microsoft.com, you can run this, changing the date and the

    >ago(1d)

    DeviceInfo //| summarize by DeviceName| where Timestamp > startofday(datetime(2021-11-15 00:00:01))| join (AlertEvidence | where Timestamp > ago(1d)) on DeviceName| summarize count() by DeviceName

    Was this answer helpful?

    0 comments No comments
  2. Igor Leyko 111K Reputation points Independent Advisor
    2022-09-08T13:26:22+00:00

    Hi John,

    My name is Igor, I have 12 Microsoft MVP awards. It's a pleasure for me to help others and I'll do all my best to help you. I'm sorry you have a problems.

    Intune related questions it is more effective to ask at Q&A forum https://docs.microsoft.com/en-us/answers/index....

    It is oriented to admins and corporate users, and this forum - to home users so local experts may have no corresponding knowledge, sorry.

    Was this answer helpful?

    0 comments No comments