Signature Detection

You can configure default engines to scan restore points. To do this, do the following:

  1. From the main menu, select Malware Detection > Signature Detection.
  2. Specify a detection engine:
  1. To additionally scan restore points marked as Suspicious after file system activity analysis or the inline scan, select the Perform signature-based scan when malware event appears check box. In this case, a Scan Backup session will run automatically:
    • If malware activity is detected, the Veeam Data Analyzer Service will create a new malware detection event and mark the restore point and the workload as Infected.
    • If malware activity is not detected, the Veeam Data Analyzer Service will create a new malware detection event with the Informative status. After that, you can mark a restore point and a workload as Clean. For more information, see Managing Malware Status.
    • If a restore point contains encrypted disks, such disks cannot be mounted and will not be scanned. In this case, a scan session will display mount errors in the log file and will be finished with Warning. The Veeam Data Analyzer Service will not create any malware detection events.

For more information on how to exclude machines with encrypted disks from the signature-based scan scope, see this KB article.

To automatically mark a restore point and a workload as Clean, select the Mark backup as clean if no threats are detected by signature-based scan check box. In this case, a malware detection event with the Informative status will not be created and a Clean event will be created instead.

Note

Consider the following when you use a proactive signature-based scan:

  • Only the following Suspicious malware detection events trigger a scan session:
    • File encryption
    • Ransomware notes and .onion files
    • Known malware extensions
    • Bulk file renaming
    • Bulk file deletion
  • For machine backups, the mount server must be compatible with the guest OS file system to properly perform a signature-based scan.
  • A maximum of 5 scan sessions can run simultaneously per mount server.
  • Scanning backups kept in object storage repositories may lead to additional costs.
  • The signature-based scan is not supported for backups kept in Cloud Connect repositories.
  • It is recommended to double-check restore points and workloads automatically marked as Clean, as these events may be false positives.
  • If you selected 3rd party antivirus software as a detection engine but it is not installed on the mount server or the configuration file contains incorrect settings, a scan session will fail. A failed session will be retried three times.

Signature Detection

Page updated 2026-08-13

Page content applies to build 13.1.1.18