Host-based backup of VMware vSphere VMs.
Post Reply
tj818
Influencer
Posts: 23
Liked: 8 times
Joined: Oct 29, 2025 7:44 pm
Full Name: Tim Russell
Contact:

Questions Regarding Threat Hunter Scan on VM Backups

Post by tj818 »

Case #08012766

Hi Team,

I am working on configuring SureBackup Jobs that utilize Threat Hunter to scan the Restore Points.

The SureBackup Job under SureBackup's Job History shows a status as "Success"

However, if you click in the details of the Job, there is a warning in regard to other AV being detected on the Mount Host

Code: Select all

[05.03.2026 09:41:57.687]   <132>    Info (3)    [1] Enumeration complete, waiting for enqueued scans to finish...
[05.03.2026 09:41:57.857]    <96>    Info (3)    [1] All file scans complete.
[05.03.2026 09:41:57.857]   <144>    Info (3)    [1] Threat hunter session ended. Scanned: 427873 Infected: 0 Result: UnableToScanFiles
[05.03.2026 09:41:57.876]    <33>    Info (3)    Veeam Threat Hunter might be blocked by an antivirus installed on the mount host, please configure exclusions according to https://www.veeam.com/KB1999. Exit code: 256
I am looking to get AV Exclusions in place, but I had a few questions

1. Should the job be marked as success if there were files that were unable to be scanned per the logs? Can it have a status of Warning or Failure? I asked support, but we could not get confirmation on what might not have been scanned due to other AV being detected and if we didn't look at the details of the Job itself, we would not have known there might have been files not scanned.

2. Do we need to put in all the AV Exclusions for Threat Hunter per the KB or does it need to be just the Threat Hunter entry listed at the beginning of the KB.

Thanks!
Tim
Egor Yakovlev
Product Manager
Posts: 2658
Liked: 765 times
Joined: Jun 14, 2013 9:30 am
Full Name: Egor Yakovlev
Location: Prague, Czech Republic
Contact:

Re: Questions Regarding Threat Hunter Scan on VM Backups

Post by Egor Yakovlev »

Hi Tim,

Many system files are designed to be protected or restricted, and will still return “access denied” errors regardless of where or how the backup is mounted. And unfortunately, we cannot always determine whether access is denied due to a system lock or because an application like antivirus is preventing our action.
Regarding exclusions, for VTH specifically, the VTH executable folder and a mount folder (C:\VeeamFLR) exclusions are required.
tj818
Influencer
Posts: 23
Liked: 8 times
Joined: Oct 29, 2025 7:44 pm
Full Name: Tim Russell
Contact:

Re: Questions Regarding Threat Hunter Scan on VM Backups

Post by tj818 »

Thanks for the clarification Egor. I will look to add the exclusions. Does the process log which files it could not scan?

Thanks,
Tim
Post Reply

Who is online

Users browsing this forum: No registered users and 35 guests