Comprehensive data protection for all workloads
Post Reply
adam900331
Veteran
Posts: 304
Liked: 22 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Malware detection - Bulk file renaming

Post by adam900331 »

Hy!

I have a file server, and nabled the indexing during backup. Last night I ran Windows Update and installed lots of update. The veeam has been reported the following after the server update:

Type: Bulk file renaming
Details: Potential malware activity detected: too many files have had their names changed since last backup, ensure they were not encrypted by ransomware

Are there any log where I can check which files modified?
Could there be a connection between the update and the many file changes?

Thanks.
Mildur
Product Manager
Posts: 8785
Liked: 2313 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Malware detection - Bulk file renaming

Post by Mildur »

Hi Adam

There is no log yet for "bulk file renaming".
It should be added in the upcoming patch.
Could there be a connection between the update and the many file changes?
Yes, it's possible. Have you included %windir% in the guest file indexing options?

Best,
Fabian
Product Management Analyst @ Veeam Software
adam900331
Veteran
Posts: 304
Liked: 22 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: Malware detection - Bulk file renaming

Post by adam900331 »

Hello Fabian,

Thanks. The guest file indexing option is:

Indexing everything expect:
- %windir%
- %ProgramFiles%
- %ProgramFiles(x86)%
- %ProgramW6432%
- %TEMP%

Is it meean that the indexing is not apply on %windir%?

Thanks.
Gostev
Chief Product Officer
Posts: 31590
Liked: 6731 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Malware detection - Bulk file renaming

Post by Gostev »

Correct.
adam900331
Veteran
Posts: 304
Liked: 22 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: Malware detection - Bulk file renaming

Post by adam900331 »

Thanks. But how can I identify that it is a false warning (so not malware activities) or not?
Gostev
Chief Product Officer
Posts: 31590
Liked: 6731 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Malware detection - Bulk file renaming

Post by Gostev »

See the previous reply, the conventient way is coming.
Gostev
Chief Product Officer
Posts: 31590
Liked: 6731 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Malware detection - Bulk file renaming

Post by Gostev » 1 person likes this post

And until this log is available, you can use the Compare to Production functionality of the File-Level Recovery wizard to see all the changed files between the selected restore point and production environment.
adam900331
Veteran
Posts: 304
Liked: 22 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: Malware detection - Bulk file renaming

Post by adam900331 »

Thanks!
Post Reply

Who is online

Users browsing this forum: Bing [Bot], Google [Bot], Semrush [Bot], srgl and 61 guests