Malware Protection

Prev Next

Malware Protection defends your host endpoints against viruses, trojans, worms, spyware, adware, key loggers, rootkits, phishing software, and other potentially unwanted programs (PUP).

Note

By default, Signature and Heuristic Detection (remediation and quarantine), as well as MalwareGuard, are disabled. When these capabilities are disabled, no malware protection occurs. MalwareGuard does not require Signature and Heuristic Detection enablement, and Malware Guard can be enabled independently of Signature and Heuristic Detection. However, MalwareGuard needs to download content from avupdate.fireeye.com on port 80 when you enable it for the first time, so access to that URL must be allowed. Signature and Heuristic Detection must be enabled before malware prevention and scheduled malware scans can occur.

Malware Protection automatically detects and prevents malware in any file in your environment in real time for all file types using two detection engines.

  • Signature and Heuristic Detection (AV) engine—The AV engine scans files when they arrive on your endpoint. If malware is detected, the scan is aborted on the file, and protection actions are performed, if quarantine is enabled.

  • MalwareGuard—If the AV engine fails to detect malware, the file is submitted to MalwareGuard for scanning, when MalwareGuard is enabled. If malware is detected, the scan is aborted on the file, and protection actions are performed, if quarantine is enabled for MalwareGuard.

Supported malware scan types

Both on-access and on-demand (scheduled) malware scans are supported.

  • On-access malware scans occur when files are created, executed, or opened. Created files include files that are downloaded from an Internet browser, new files created on the host by any process, files extracted from archives, and files created by a copy-and-paste action. Executed files are files that launch a process. Opened files include existing files opened in a browser, from media such as a USB or CD/DVD drive, and from network folders.

  • On-demand (scheduled) malware scans can be scheduled by time or event. Full scans and active memory scans (which scan running processes) can be requested. New scans will not run if a previously scheduled scan is still running. Depending on how you configure your malware scan settings, end users can pause or cancel a running scheduled scan.

Scheduled scan behavior

The following table shows how scheduled scans react to certain specified events on the host machine.

Events

Scan Status

Scan Behavior

Shutdown

Scheduled

Skip this scan

Shutdown

In Progress

Skip this scan

Hibernation

Scheduled

Scan starts when system resumes

Hibernation

In Progress

Scan continues when system resumes

Sleep

Scheduled

Scan starts when system resumes

Sleep

In Progress

Scan continues when system resumes

Changing the host's local time

Scheduled

Scheduled scan honors current time setting. If the time is changed to be after the start time of the scheduled scan, then the scan is skipped. Otherwise, the scan proceeds at its scheduled time

Changing the host's local time

In Progress

Scan continues uninterrupted

File size limitations

The following table shows the default file size limitations for scanning. You can customize maximum file size via the API.

Scan type

AV engine

MalwareGuard engine

On-Access Scan

2 GB

5 MB

Scheduled Scan

2 GB

100 MB

Scan type

AV engine

MalwareGuard engine

On-Access Scan

30 MB

12 MB

Scheduled Scan

2 GB

100 MB

Malware remediation actions

When malware is detected, a malware alert is generated and is visible in the Endpoint Security (HX) Web UI. Based on your configurable malware protection settings, you can request that any of the following remediation actions can be performed.

  • The infected file is automatically quarantined in a quarantine area when you enable remediation (quarantine) actions. Quarantined files are stored in a quarantine area and are deleted after a configurable aging period. Quarantining files isolates them so they cannot spread malicious code to other files or applications on the endpoints in your environment. You can also retrieve files from quarantine for analysis.

  • If the infection appends malicious code to user files, the system attempts to clean the infection. If cleaning fails, the files remain on the endpoint and can be acquired for analysis.

  • If the infection creates new files on the endpoint, the system attempts to delete them. If the infected files are locked and require a reboot for deletion, a notification appears on the endpoint.

  • Trellix's malware protection engine can remove artifacts created by the malware and revert changes the malware made to other files or registry entries. This is referred to as removing malware traces.

  • Notification messages on the endpoint let you know when remediation actions occur.

The source malware definitions used by the Endpoint Security (HX) are downloaded from Trellix servers that require a direct Internet connection. They are not available in Trellix's Dynamic Threat Intelligence (DTI) cloud.

Note

Malware detection is supported for Endpoint Security (HX) Agents running version 24 or later in specific Windows environments, version 32 or later in macOS environments, and version 34 for Linux environments.

Malware Protection is supported for s running on Windows endpoints (On-Access Scan and On-Demand Scan). It is not supported on macOS or Linux.

Malware remediation (quarantine) is supported for Endpoint Security (HX) Agents running version 26 or later in specific Windows environments.

MalwareGuard is supported for Endpoint Security (HX) Agents running version 27 or later.

At regular intervals, false positive information for malware conditions is automatically downloaded from Trellix's Dynamic Threat Intelligence (DTI) cloud to the Endpoint Security (HX). When Endpoint Security (HX) Agents poll the server, the false positive data is automatically applied on the endpoints. Existing alerts on the Endpoint Security (HX) that match the false positive conditions are marked as false positive.

You can define policies and settings for malware protection that are specific to your organization.

Endpoint Security (HX) xAgent version 26 and later are certified to join the Microsoft Virus Initiative (MVI) and are integrated with Windows Security Center (WSC). This means that Endpoint Security (HX) is a certified and supported antivirus and anti-spyware product for specific Windows operating systems.

Trellix's malware protection engine appears in WSC only when malware detection is enabled, file quarantine is enabled, and on-access malware scans are enabled. The Turn on now button in the WSC, when it appears, is not functional for Trellix's malware protection engine because malware protection is enabled by the Endpoint Security (HX) administrator for all of your host endpoints or for select host sets using the Endpoint Security (HX) Web UI or API.