Removing Malware Traces from Quarantined Files

Prev Next

In addition to cleaning the infected file, Trellix Endpoint Security (HX) xAgent malware protection engine can remove artifacts created by the malware and revert any changes the malware infection may have made to other files or registry entries on the host endpoint. You can enable and disable the removal of malware traces through the Web UI or the API.

Important

Malware protection processing, including malware detection (Signature and Heuristic Detections), Quarantine, and Clean Infection from Files (Once Quarantined) must be enabled, or malware trace removal is ignored.

This section covers how to use the Web UI to enable and disable the malware trace removal setting. See the Endpoint Security (HX) REST API Guide for information on using the API to enable and disable the malware trace removal setting.