Malware protection allows you to create on-demand (scheduled) malware scans in the Web UI. Use the Malware Scans tab to configure and manage up to ten global and ten exception on-demand malware scans. You can configure on-demand malware scans to trigger at a specific time interval or after a specific event occurs. You can also set the scan depth to control which files, applications, and device components malware protection scans.
.png)
Ensure that malware detection (Signature and Heuristic Detections) is turned on before you enable scheduled scans. You can also configured scheduled scans for MalwareGuard by enabling both Signature and Heuristic and MalwareGuard Detection using the Web UI or the API. See Enabling and Disabling Malware Detection and MalwareGuard for more information.
Important
If malware detection is disabled, scheduled scans are automatically disabled.
On-Demand Malware Scan Types
When scheduling malware scans, you can choose a time-based or event-based scan. Time-based malware scans occur daily, weekly, or monthly, based on your configuration settings. Event-based global malware scans occur when malware signatures are updated or when the host endpoint boots or reboots. Scan depth options include full scans, quick scans, and active memory scans.
On-Demand Scan Depth | Description |
|---|---|
Full Scan | Performs a memory scan, a quick scan, and a MBR (boot sector) scan. Also scans all files on a local fixed and removable disk drives, excluding network, floppy, flash, CD/DVD, and non-disk drives. For local disk drives, a full scan identifies the required drives and scans all files present on those drives. |
Quick Scan | Scans persistent malware locations, including a registry scan that scans all persistent audit keys and an MBR (boot sector) scan. |
Active Memory | Scans all files currently opened on the system, including a process image scan (on disk and in memory) and an all-loaded modules scan (on disk and in memory). |
Scheduled Scan Behavior
The following table shows how scheduled scans react to certain specified events on the host machine.
Events | Scan Status | Scan Behavior |
|---|---|---|
Shutdown | Scheduled | Skip this scan |
Shutdown | In Progress | Skip this scan |
Hibernation | Scheduled | Scan starts when system resumes |
Hibernation | In Progress | Scan continues when system resumes |
Sleep | Scheduled | Scan starts when system resumes |
Sleep | In Progress | Scan continues when system resumes |
Changing the host's local time | Scheduled | Scheduled scan honors current time setting. If the time is changed to be after the start time of the scheduled scan, then the scan is skipped. Otherwise, the scan proceeds at its scheduled time. |
Changing the host's local time | In progress | Scan continues uninterrupted |
This section describes how to enable, create, delete and disable on-demand malware scans for all of your host endpoints or for select host sets through the Web UI.