Comprehensive data protection for all workloads
Post Reply
rin
Enthusiast
Posts: 40
Liked: 5 times
Joined: Jun 24, 2025 6:40 am
Full Name: Rintaro Tamura
Contact:

Clarification of "New Malware Detection Event" Behavior After Mark as Clean

Post by rin »

Hello Team,

I have a question regarding Malware Detection and the behavior of "Mark as Clean".

According to the User Guide, after a workload is marked as clean, subsequent restore points are not marked as suspicious or infected unless a new malware detection event is created.

I would like to better understand what is considered a "new malware detection event" in this context.

Example scenario:
1. A file is detected as Suspicious by Malware Detection.
2. The workload and affected restore points are marked as Clean.
3. The detected file is neither removed nor excluded.
4. Subsequent backups continue to run and the same file remains present.
 
In this scenario:
- Will Malware Detection generate a new Malware Detection Event again for the same file / same detection content?

or

- Is the previous detection considered acknowledged by "Mark as Clean", and a new Malware Detection Event is only generated when different suspicious content is detected?

To clarify, I am not asking about the malware status itself (Suspicious / Infected / Clean).

I am specifically asking about the conditions under which a new Malware Detection Event is generated after Mark as Clean has been performed.

Best Regards,
Rin
Tatsuya
Influencer
Posts: 13
Liked: 1 time
Joined: Dec 05, 2025 3:20 pm
Full Name: Tatsuya Yamada
Contact:

Re: Clarification of "New Malware Detection Event" Behavior After Mark as Clean

Post by Tatsuya »

Hello Team,

I would like to kindly follow up on the question below.
We would appreciate clarification regarding the following point:

After "Mark as Clean" has been performed, under what conditions is a new Malware Detection Event generated?

Specifically, if the same suspicious file remains present and continues to be detected in subsequent backups, will Malware Detection generate a new Malware Detection Event again, or is the previous detection considered acknowledged by "Mark as Clean"?
Understanding this behavior is important for us to accurately explain the feature behavior to our customers.
We would appreciate any clarification you can provide.

Best Regards,
Tatsuya
Post Reply

Who is online

Users browsing this forum: DaStivi, gmajestix, iDeNt_5, Semrush [Bot] and 96 guests