We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Behavior:Win32/WmiprvseRemoteProc.B
Aliases: No associated aliases
Summary
WmiprvseRemoteProc is a telemetry-based signature that is triggered when wmiprvse.exe (WMI Provider Host) is remotely launched through PowerShell.
For information about WmiprvseRemoteProc and other human-operated malware campaigns, read these blog posts:
If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.