Configuring On-Demand Malware Scans

Prev Next

Malware protection allows you to create on-demand (scheduled) malware scans in the Web UI. Use the Malware Scans tab to configure and manage up to ten global and ten exception on-demand malware scans. You can configure on-demand malware scans to trigger at a specific time interval or after a specific event occurs. You can also set the scan depth to control which files, applications, and device components malware protection scans.

UI_Policy_MalScan_Scheduled.png

Ensure that malware detection (Signature and Heuristic Detections) is turned on before you enable scheduled scans. You can also configure scheduled scans for MalwareGuard by enabling both Signature and Heuristic and MalwareGuard Detection using the Web UI or the API. See Enabling and Disabling Malware Detection and MalwareGuard for more information.

Important

If malware detection is disabled, scheduled scans are automatically disabled.

Supported On-Demand malware scan file types

The following table shows the file types that on-demand malware scan protection supports.

File Type

Description

Native Zip Archive

Detection, cleaning, and quarantine are supported.

RAR Archive

Detection and quarantine are supported.

SFX Archive

Detection, cleaning, and quarantine are supported. The entire archive is deleted during cleaning.

SFX Archive (Extracting to a folder)

Detection is supported. Detection occurs after the malicious file is extracted.

Inno Installer

Detection is supported.

NSIS Installer

Detection is supported.

MSI Installer

Detection is supported.

ISO

Detection is supported.

CAB

Detection is supported.

WISE Installer

Detection is supported.

7ZIp Archive

Detection is supported.

DMG

Detection is supported.

Autoit Script- PE

Detection is supported.

On-Demand malware scan types

When scheduling malware scans, you can choose a time-based or event-based scan. Time-based malware scans occur daily, weekly, or monthly, based on your configuration settings. Event-based global malware scans occur when malware signatures are updated or when the host endpoint boots or reboots. Scan depth options include full scans, and active memory scans.

On-Demand Scan Depth

Description

Full Scan

Performs a memory scan and a MBR (boot sector) scan. Also scans all files on a local fixed and removable disk drives, excluding network, floppy, flash, CD/DVD, and non-disk drives. For local disk drives, a full scan identifies the required drives and scans all files present on those drives.

Active Memory

Scans all files currently opened on the system, including a process image scan (on disk and in memory) and an all-loaded modules scan (on disk and in memory).

Scheduled scan behavior

The following table shows how scheduled scans react to certain specified events on the host machine.

Events

Scan Status

Scan Behavior

Shutdown

Scheduled

Skip this scan

Shutdown

In Progress

Skip this scan

Hibernation

Scheduled

Scan starts when system resumes

Hibernation

In Progress

Scan continues when system resumes

Sleep

Scheduled

Scan starts when system resumes

Sleep

In Progress

Scan continues when system resumes

Changing the host's local time

Scheduled

Scheduled scan honors current time setting. If the time is changed to be after the start time of the scheduled scan, then the scan is skipped. Otherwise, the scan proceeds at its scheduled time.

Changing the host's local time

In progress

Scan continues uninterrupted

This section describes how to enable, create, delete and disable on-demand malware scans for all of your host endpoints or for select host sets through the Web UI.