Malware Detection

You can use different malware detection methods to scan data of backups created by Veeam Agent for Microsoft Windows, Veeam Agent for Linux or Veeam Agent for Unix and get information about suspicious activity or infected objects.

Veeam Backup & Replication provides the following malware detection methods for Veeam Agents:

  • Guest Indexing Data Scan — based on the Veeam file detection engine — detects malware activity in the file system.
  • Inline Scan — based on the Veeam encryption detection engine — detects objects encrypted by malware (only for Veeam Agent for Microsoft Windows protected with backup job managed by Veeam backup server)
  • Signature-based scan — performed by Veeam Threat Hunter or third-party antivirus software of your choice — detects known malware signatures.

To learn more about the feature, see Malware Detection Methods and Signature Detection.

Note

Malware detection may report false-positive events for legitimate Oracle Solaris and IBM AIX files whose names or extensions match entries in the list of known suspicious files and extensions. If you confirm that the affected files are safe, you can exclude them directly from the event's Event Details window, or add them to Trusted objects in File Detection settings. To learn more, see Viewing Malware Detection Events Using Console and File Detection.

NOTE

Veeam Backup & Replication applies the status of an individual node to the entire Windows Server Failover Cluster backup. For example, if Veeam Backup & Replication detects malware activity on any cluster node, the backup for the whole cluster will be marked as Suspicious or Infected. Similarly, if any of the nodes becomes Clean, the backup of the entire cluster will be marked as Clean.

Related Task

Scanning Veeam Agent Backups.

Page updated 2026-08-06

Page content applies to build 13.1.0.411