By default, the Intelligent Virtual Execution - Server appliance uses integrated antivirus tools, such as ClamWin, and signer checking, to scan submitted malware samples. This static analysis tool is called AV‑check.
The Intelligent Virtual Execution - Server appliance returns static analysis results to the originating sensor, where the information can be viewed at the Alerts > Alerts page of the sensor Web UI (or the Alerts > Web MPS > Alerts page of the Central Management System Web UI, if the sensor is under Central Management System management).