When the on-access or on-demand scanner detects an unwanted program, it responds with the action that you configured for that scanner.
Review the information in the activity log to decide whether to take more actions:
Fine-tune scan items.
To make scanning more efficient, exclude legitimate files and delete known threats from the quarantine.
Configure the scanner to perform actions on files.
Deny access to files — Prevents the user from accessing files with detected threats.
Clean files — Removes the threat from the detected file, if possible.
Delete files — Deletes the item that contains the threat.
If an action isn't available for the current detection, the corresponding option isn't available. For example, Clean isn't available if the file has already been deleted, or Delete isn't available if the settings don't allow it.
Configure the scanner to display a message to users when a threat is detected.
Submit a sample to Trellix Advanced Research Center for analysis.
If you find a false positive or a false negative, submit a sample of the threat to Trellix Advanced Research Center.