When malware is detected on an endpoint and an infected file is quarantined, the Trellix Endpoint Security (HX) xAgent malware protection engine attempts to clean the file by removing the malware infection. If a file cannot be cleaned, it is removed from the endpoint.
You can enable and disable the malware protection file clean setting for all of your host sets using the agent default policy. You can also enable and disable the malware protection file clean setting for specific host sets in your environment using a custom exclusion policy.
Important
Operating system permissions on the host endpoint may prevent malware protection from cleaning an infected file or application.
Malware protection processing (malware detection) and quarantine must be enabled, or file clean is ignored.
This section covers how to use the Web UI to enable and disable the malware protection file clean setting. See the Endpoint Security (HX) REST API Guide for information on using the API to enable and disable the malware protection file clean setting.