Defender for Endpoint not being able to remove detected malware.

Jan De Smet 66 Reputation points
2022-04-11T13:46:06.51+00:00

We have all our devices enrolled in MEM, and are using Defender for endpoint. On 2 devices we see reoccurring malware files. Security Center shows the files as blocked / prevented. But Defender does not seem to be able to quarantine the files. Nor remove them;
A full system scan does not clean up the files either.
How can we clean these files, without manually deleting them from the pc?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,770 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,421 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,576 Reputation points Microsoft Employee
    2022-04-11T15:22:38.22+00:00

    You may consider walking the user through an offline scan: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-offline

    Many organizations also reimage systems with persistent issues.

    0 comments No comments