-
matteu
- Veeam Legend
- Posts: 895
- Liked: 141 times
- Joined: May 11, 2018 8:42 am
- Contact:
Malware detection
Hello,
I have on my customer an alert with potential file. I remove the parent folder because it's on a temp location, clean the alert and made a new backup.
Now I have a new detection because too much html removal were done (they were in the folder I removed).
So I clean the alert and made a new job again but this alert is still there.
Is it expected ? Do I need to wait 24h for this alert to not come back again ?
I have on my customer an alert with potential file. I remove the parent folder because it's on a temp location, clean the alert and made a new backup.
Now I have a new detection because too much html removal were done (they were in the folder I removed).
So I clean the alert and made a new job again but this alert is still there.
Is it expected ? Do I need to wait 24h for this alert to not come back again ?
-
Dima P.
- Product Manager
- Posts: 14945
- Liked: 1833 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Malware detection
Hello matteu,
No, once the file or folder is excluded from processing it should not any longer raise malware events. Can you please raise a support case and share the ID with us? We will take a look at your logs. Thank you!
No, once the file or folder is excluded from processing it should not any longer raise malware events. Can you please raise a support case and share the ID with us? We will take a look at your logs. Thank you!
-
matteu
- Veeam Legend
- Posts: 895
- Liked: 141 times
- Joined: May 11, 2018 8:42 am
- Contact:
Re: Malware detection
Hello,
Thanks for your answer.
I didn t exclude it. I marked it as clan only.
If you confirm me it s not normal I can open a case and share the number yes.
Thanks for your answer.
I didn t exclude it. I marked it as clan only.
If you confirm me it s not normal I can open a case and share the number yes.
-
Dima P.
- Product Manager
- Posts: 14945
- Liked: 1833 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Malware detection
Marking the restore point as clean unfortunately does not whitelist the suspicions file. You need to exclude such file from processing. Thank you!
-
matteu
- Veeam Legend
- Posts: 895
- Liked: 141 times
- Joined: May 11, 2018 8:42 am
- Contact:
Re: Malware detection
Thanks for your answer.
Maybe I wasn't clear enough.
The first time I saw the issue, it was a malware detection.
So I remove the entire folder with the malware. Then I clean the alarm.
On the next backup, I have a new alert "bulk file deletion" because there was lot's of files in the folder I removed.
I clean this new alert about bulk file deletion and executed a manual backup job for this VM and the alert about bulk file deletion is displayed again.
I think there is a delay because it doesn't come back as alarm because today I clean up the alert (1 week later) and now the alert don't pop up again
Maybe I wasn't clear enough.
The first time I saw the issue, it was a malware detection.
So I remove the entire folder with the malware. Then I clean the alarm.
On the next backup, I have a new alert "bulk file deletion" because there was lot's of files in the folder I removed.
I clean this new alert about bulk file deletion and executed a manual backup job for this VM and the alert about bulk file deletion is displayed again.
I think there is a delay because it doesn't come back as alarm because today I clean up the alert (1 week later) and now the alert don't pop up again
-
Dima P.
- Product Manager
- Posts: 14945
- Liked: 1833 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Malware detection
Aha, got it. For the bulk file deletion even indeed no action is required as this activity is not regular (and we compare the restore point indexes between latest restore points anyway).On the next backup, I have a new alert "bulk file deletion" because there was lot's of files in the folder I removed.
-
matteu
- Veeam Legend
- Posts: 895
- Liked: 141 times
- Joined: May 11, 2018 8:42 am
- Contact:
Re: Malware detection
Yes the test I did shows that you don t look only the latest one but several.
-
Dima P.
- Product Manager
- Posts: 14945
- Liked: 1833 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Malware detection
The time frame for the latest restore point is 24 hours. After this period, we will begin using the later index for comparison and analytics.
-
matteu
- Veeam Legend
- Posts: 895
- Liked: 141 times
- Joined: May 11, 2018 8:42 am
- Contact:
Re: Malware detection
Thanks for the explanation
Who is online
Users browsing this forum: No registered users and 13 guests