Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Nov 27, 2021 | Updated Jun 07, 2023

Behavior:Win32/WmiprvseRemoteProc.B

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

WmiprvseRemoteProc is a telemetry-based signature that is triggered when wmiprvse.exe (WMI Provider Host) is remotely launched through PowerShell.

For information about WmiprvseRemoteProc and other human-operated malware campaigns, read these blog posts:

If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us