Have you created a File policy and associated it with rule(s) in your ACP along with a Malware license being assigned to the relevant FTD devices?
If so, also keep in mind that firewall Malware policy only applies to transfer of files it can actually see - i.e., things sent via http (not https which is 95-99% of web traffic) or something like unencrypted ftp. Do you see any file events indicating the device is doing a file lookup to check for malware? These are easily filterable in the Unified Events page.