Case reference 07751303
Hi all,
As requested by the Veeam Support Team, I created a new feature request aimed to improve the Malware Detection default exclusions of the VBR.
As explained in this support case, the VBR malware detection marks as infected the following component of the VBO v8 (latest version) server:
C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Veeam.Backup.Interaction.Explorer
Since this is a default embedded component of the VBO, it should not required to manually create a specific exclusion on the Malware Detection component of the VBR.
Thanks.
-
- Service Provider
- Posts: 37
- Liked: 9 times
- Joined: Feb 09, 2024 5:34 pm
- Full Name: Matteo Fringuelli
- Contact:
-
- Veeam Software
- Posts: 2873
- Liked: 660 times
- Joined: Jun 28, 2016 12:12 pm
- Contact:
Re: Feature request: Improve default malware detection exclusions
Hi iDeNt_5,
Thanks for sharing the case number. I was able to reproduce, and it's not really about the component, it's about the .Explorer part of the name which is being parsed as an extension, which is a real extension used by the Explorer ransomware, so a case of unfortunate naming + match.
Agree though that it should be handled better. Will discuss internally best way to handle, but for now please continue using the exclusion.
Thanks for sharing the case number. I was able to reproduce, and it's not really about the component, it's about the .Explorer part of the name which is being parsed as an extension, which is a real extension used by the Explorer ransomware, so a case of unfortunate naming + match.
Agree though that it should be handled better. Will discuss internally best way to handle, but for now please continue using the exclusion.
David Domask | Product Management: Principal Analyst
-
- Veeam Software
- Posts: 2873
- Liked: 660 times
- Joined: Jun 28, 2016 12:12 pm
- Contact:
Re: Feature request: Improve default malware detection exclusions
Quick update, we will be resolving this through an update for the Malware Definitions XML, and the false-positive should stop appearing soon. Thanks again for the report!
David Domask | Product Management: Principal Analyst
-
- Service Provider
- Posts: 37
- Liked: 9 times
- Joined: Feb 09, 2024 5:34 pm
- Full Name: Matteo Fringuelli
- Contact:
Re: Feature request: Improve default malware detection exclusions
Hi David,
Thank you so much for the update, really appreciated!
Thank you so much for the update, really appreciated!
Who is online
Users browsing this forum: Bing [Bot], Google [Bot], Semrush [Bot] and 13 guests