๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Malware & AV

Malware detections, antivirus and EDR problems, and Huntress and Sophos incidents for every computer, active and past, in one list.

Open Malware & AV in your console

Where to find it
Devices โ€บ Computers โ€บ Malware & AV, and the Threats tab on a computer
Who can use it
Anyone who can see Computers. You see your own organization and the clients you manage.
For
MSPs and IT teams
Plan
RMM Agent (Windows; included in Grow, Professional, and Complete). See pricing

What the page is for

Malware & AV is a page in the Lavawall® console, in the Devices area. Lavawall is the RMM, security, and compliance platform from ThreeShield, built and hosted in Canada. About this feature.

It brings together what the security products on your Windows computers report: malware they found and what they did about it, and problems that leave a computer unprotected, such as antivirus turned off, out-of-date definitions or a stopped security service.

It works with Microsoft Defender and with other antivirus and EDR products, including Sophos, Bitdefender, VIPRE, Webroot, Kaspersky, ESET, Kaseya and Datto, Malwarebytes, Trend Micro and others. Products that keep their detections in their own cloud console, such as CrowdStrike and SentinelOne, show less here; Lavawall still tells you when their service stops. If you connect Huntress or Sophos Central, their incidents, alerts and cases appear in the same list.

Each new detection raises a critical notification, and each new protection problem a high one, so you hear about it through your usual notification settings. Times are shown in your local time.

What you see

  1. Filters: Status (Active, Past, All), Source, Type, Organization, Period and a Filter box. The list opens on Active when anything is active, and on All when nothing is.
  2. The list: Status, Severity, Detected, Computer, Organization, Source, Type, Threat or issue and Action taken. Every column can be sorted.
  3. Row buttons: Details shows the location, process, user and the product's message. Resolve or Reopen appears on items from the Lavawall agent, and Open on Huntress and Sophos items.
  4. Threats tab on a computer: the same list for that one computer, with a Protection on this computer summary of its antivirus products, Microsoft Defender's state and its security services. The tab appears only when the computer has something to show.

How to use Malware & AV

How to review new detections

  1. Open Malware & AV under Devices โ€บ Computers. If anything is active, the list shows Active items first.
  2. Look at Action taken. Red text means the product did not report that it removed or blocked the threat.
  3. Click Details to see the file location, the process and the user, and the product's own message.
  4. Click the computer's name to open its Threats tab, where you can connect to it remotely.

How to mark a detection resolved

  1. Confirm the threat was removed or blocked, or clean it up yourself.
  2. Click Resolve on the row, then Resolve again to confirm.
  3. The item moves to past items and its notification is closed. Use Reopen if you resolved it by mistake.

How to see past incidents

  1. In Status, choose Past or All.
  2. In Period, choose how far back to look, up to All history.

How to narrow the list

  1. Choose a Source (Lavawall agent, Huntress, Sophos alerts or Sophos cases), a Type and an Organization.
  2. Type in Filter to search threat names, computers, file paths and messages.
  3. Click any column heading to sort by it. Click it again to reverse the order.

Tips

  • A protection problem closes on its own once the computer reports that it is fixed. Resolving one yourself marks it reviewed; it stays resolved while the problem continues.
  • When a computer first reports, detections older than three days are added as past items without a notification, so you can see its history without a flood of alerts.
  • To be emailed about new detections, turn on Malware detected and AV Issue in your notification settings.
  • The Threats tab replaces the Huntress tab on the computer's page. Links to the old tab still open it.

Troubleshooting

What does "This list could not be loaded" mean?
Reload the page. If it keeps happening, contact support and say which page you were on.
Why is there no Threats tab on a computer?
The tab appears only when that computer has something to show: an open item, or anything reported in the last 90 days.
Why does a computer say antivirus status has not been reported yet?
The computer's Lavawall agent has not sent its first antivirus report. It reports a few minutes after it connects, then every few minutes.
Can I resolve a Huntress or Sophos item from Lavawall?
No. Those items are managed in Huntress or Sophos Central. Use Open to go to the matching Lavawall page for that product.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on:

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.