Antivirus findings and recovery

Understand an antivirus finding and decide whether to quarantine, clean or restore the file.

Where to find it: Server > Antivirus > Findings or Quarantine; account users use Account > Antivirus > Findings, Trusted versions, or Recovery.

Available to: Root across accounts; an account user and its authorized owner within the selected account.

What this page does

Findings distinguish malware from potential vulnerabilities that need review. The reported file version matters: an old result must not silently authorize changing a file whose contents have changed.

Before you start

Keep a current backup. Read the finding type, file identity, scan report, and available evidence before cleaning, quarantining, deleting, or trusting anything.

Actions and consequences

ActionUse and consequence
View contentInspect the evidence associated with the finding.
Clean Malicious Code / Clean safelyRequest the supported safe-cleaning workflow; inspect its result rather than assuming any detected file can be cleaned.
QuarantineRemove the suspicious file from its working location while retaining a recoverable quarantined item.
DeleteRemove the selected item; use only when the recovery implications are understood.
Trust selected versionsTrust the exact reviewed file version, identified by its content hash. A later change is not automatically trusted.
Clear all findingsClear report findings; this is not the same as repairing the affected files.
Restore from Recovery/QuarantineReturn the selected recoverable item after checking why it was isolated and whether restoration is appropriate.

Progress and interrupted scans

Use the current scan progress, elapsed time, log, and history. An interrupted or stale run is not a clean bill of health. SHM preserves the supported report/recovery state; follow the status shown after a service interruption and start a new scan when required. Account views contain only their authorized findings.

How to use it

  1. Open a scan report and filter Malware or Potential vulnerabilities.
  2. Review the file and evidence, then select only the intended rows.
  3. Run the appropriate supported action and read its per-item outcome.
  4. Rescan the affected account and test the application.
  5. For a recovery, verify the restored content and application behavior before closing the incident.

Result and next check

The finding is resolved for the verified file version, the application still works, and a follow-up scan confirms the current state.

Theme color