Product Version: 9.0
Last Modified: 27 September 2019
When recovering from a virus attack, the recovered virtual machine’s data must be scanned with antivirus software before getting it restored to production environment. This may be required as a precautionary measure or out of suspicion. In any case, you can apply the following scenario to ensure the recovered virtual machine is free of any malware:
Prepare an antivirus installation or portable antivirus package that will be used to scan data on a recovered virtual machine. Important! The software you plan to use must be current and contain the latest antivirus database updates.
Create a virtual machine or take an existing one and add a new virtual hard disk to it. For more information, refer to the documentation for the hypervisor you use, for example VMware vSphere.
Format the newly created disk by means of the Guest OS tools and upload your antivirus package to this disk. You will attach this disk to the restored virtual machine and run antivirus from it at a later stage.
Using the existing backup, flash boot a virtual machine you need to scan. Make sure to select the Not connect to any network option during the Destination step of the Flash VM Boot job creation wizard. Alternatively, select an isolated network from the drop-down list.
Once the virtual machine is restored from a backup, attach the existing hard disk (one with the antivirus software) to it using your hypervisor’s capabilities, for example VMware vSphere.
Power on the restored virtual machine and run/install the antivirus to scan and cure the data on that virtual machine.
After the virtual machine is scanned and freed of any malware, you need to migrate it to the production environment with the Recovering VMs Using Flash Boot functionality. Detailed description is available for VMware and Hyper-V in User Guide.