Managing Malware Status Using Web UI
When malware detection marks workloads as Suspicious or Infected, a Malware Detection item appears in the left navigation pane of the Veeam Backup & Replication web UI under Action Required. Click it to open the Malware Detection view, which lists the flagged workloads with their Object, Type, Status, and Activity Date. When no workloads require attention, this item is hidden.
To review malware detection events at any time, open the Malware Events tab of the Logs and Events view. To configure malware detection settings, use the Configuration menu. For more information, see Configuring Malware Detection Using Web UI.
Marking Workloads as Clean
If you cleaned a workload of malware or the malware detection event was a false positive, you can mark the workload as clean. To do this, do the following in the Veeam Backup & Replication web UI:
- In the left navigation pane, click Malware Detection.
- Select one or more workloads in the list.
- Click Mark as Clean on the toolbar. Alternatively, right-click the workload and select Mark as Clean.
- In the Mark as Clean window, specify the reason. If the malware detection event was a false positive, select the Mark restore points affected by detection events as clean check box. To stop scanning the workload during subsequent sessions, select the Exclude the workload from malware detection check box.
- Click Yes.
After you mark a workload as clean, its malware status is updated. Previous restore points keep the Suspicious or Infected status unless you chose to mark them as clean, and subsequent restore points are not marked as suspicious or infected unless a new malware detection event is created.
To turn off specific detection engines or exclude paths for a machine, use per-machine exclusions. For more information, see Managing Malware Exclusions Using Web UI.

