Antivirus (AV), Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), endpoint security, and firewall solutions can interfere with normal backup and recovery operations by scanning files, processes, and network communications that are actively used by BDRShield.
Failure to configure these exclusions may result in:
Backup data being quarantined or deleted
Backup or restore job failures
Product executables or services being blocked or removed
Reduced backup and recovery performance
Repository access issues
Instant Boot or File Level Recovery mount failures
Database performance degradation
False-positive malware detections
Important Note:
BDRShield Server-side Exclusions | |||
Exclusion Item | Type | Typical Location/Example | Description / Notes |
BDRShield Installation Directory | Folder | C:\Program Files\Vembu\ | Exclude the entire BDRShield installation directory. |
Backup Repository | Folder | D:\sgstorage | Exclude all backup storage locations used by BDRShield, including Local repositories, NAS repositories, SAN storage, SMB/CIFS network shares, External storage devices, and Repository Cache locations. |
PostgreSQL Data Directory | Folder | C:\PostgreSQLData | Exclude the PostgreSQL database directory. |
VembuBDR.exe | Process | <BDRShield Installation Directory>\VembuBDR\bin\VembuBDR.exe | Primary backup service process. |
VembuNFS.exe | Process | <BDRShield Installation Directory>\VembuBDR\bin\VembuNFS.exe | NFS service process. |
BDRPersistentService.exe | Process | <BDRShield Installation Directory>\VembuBDR\bin\BDRPersistentService.exe | Persistent background service. |
ImageIntegrityCheck.exe | Process | <BDRShield Installation Directory>\VembuBDR\bin\ImageIntegrityCheck.exe | Performs backup image integrity verification. |
SGTray.exe | Process | <BDRShield Installation Directory>\VembuBDR\bin\SGTray.exe | BDRShield tray application. |
VembuOffice365Agent.exe | Process | <BDRShield Installation Directory>\VembuOffice365Agent\bin\VembuOffice365Agent.exe | Microsoft 365 Backup agent process. |
VembuGSuiteAgent.exe | Process | <BDRShield Installation Directory>\VembuGSuiteAgent\bin\VembuGSuiteAgent.exe | Google Workspace Backup agent process. |
postgres.exe | Process | <BDRShield Installation Directory>\PostgreSQL\17\bin\postgres.exe | PostgreSQL database process. |
VembuBDR360Agent.exe | Process | <BDRShield Installation Directory>\VembuBDR360Agent\bin\VembuBDR360Agent.exe | BDR360 agent process (if installed). |
Driver Files | Driver | C:\Program Files\Vembu\VembuBDR\lib\dokan\ C:\Windows\System32\drivers\dokan1.sys C:\Windows\System32\dokan1.dll C:\Windows\SysWOW64\dokan1.dll | Exclude these driver and related DLLs. |
BDRShield Backup File Types | File Type | Backup Repository | Exclude the following file types: *.sgcf , *.db , *.sbc , *.blkinfo , *.bdm , *.fbm . |
Network Ports | Port | 6060 , 6061 , 32004 , 42005 , 32010 , 11211 , 9000 , 9001 , 9090 , 9091 , 443 , 80 | Ensure these ports are not blocked or inspected by antivirus or endpoint security software. |
BDRShield Agent-side Exclusions | |||
BDRShield Agent Installation Directory | Folder | C:\Program Files\Vembu\VembuIntegrationService\ -> On-Prem Management C:\Program Files\BDRCloud\BDRCloudDelegationService\ -> Cloud Management | Exclude the BDRShield Agent installation directory. |
BDRPersistentService.exe | Process | <BDRShield Agent Installation Directory>\bin\BDRPersistentService.exe | Persistent background service. |
VembuIntegrationService.exe | Process | <BDRShield Agent Installation Directory>\bin\VembuIntegrationService.exe | Integration service process. |
voltracker.sys | Driver | C:\Windows\System32\drivers\voltracker.sys | CBT driver used for Windows Disk Image Backups. |
bitmap.dat | File | C:\bitmap.dat | Exclude the bitmap.dat file on every protected volume. Applicable to Windows Disk Image Backups. |
BDRShield Offsite DR Exclusions (If you are using Offsite DR) | |||
BDRShield Offsite DR Installation Directory | Folder | C:\Program Files\Vembu\ | Exclude the entire BDRShield Offsite DR installation directory. |
Backup Repository | Folder | D:\sgstorage | Exclude all backup storage locations used by BDRShield Offsite DR. |
PostgreSQL Data Directory | Folder | C:\PostgreSQLData | Exclude the PostgreSQL database directory. |
VembuOffsiteDR.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\VembuOffsiteDR.exe | Offsite DR service process. |
VembuNFS.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\VembuNFS.exe | NFS service process. |
BDRPersistentService.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\BDRPersistentService.exe | Persistent background service. |
ImageIntegrityCheck.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\ImageIntegrityCheck.exe | Performs backup image integrity verification. |
SGTray.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\SGTray.exe | Tray application. |
VembuOffice365Agent.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuOffice365Agent\bin\VembuOffice365Agent.exe | Microsoft 365 Backup agent process. |
VembuGSuiteAgent.exe | Process | <BDRShield Offsite DR Installation Directory>\VembuGSuiteAgent\bin\VembuGSuiteAgent.exe | Google Workspace Backup agent process. |
postgres.exe | Process | <BDRShield Offsite DR Installation Directory>\PostgreSQL\17\bin\postgres.exe | PostgreSQL database process. |
Driver Files | Driver | C:\Program Files\Vembu\VembuBDR\lib\dokan\ C:\Windows\System32\drivers\dokan1.sys C:\Windows\System32\dokan1.dll C:\Windows\SysWOW64\dokan1.dll | Exclude the driver and related DLLs. |
BDRShield Backup File Types | File Type | Backup Repository | Exclude the following file types: *.sgcf , *.db , *.sbc , *.blkinfo , *.bdm , *.fbm . |
BDRShield Server Proxy Exclusions (if you are using Server Proxy) | |||
BDRShield Server Proxy Installation Directory | Folder | C:\Program Files\BDRShield\ServerProxy\ -> On-Prem Management C:\Program Files\BDRCloud\ServerProxy\ -> Cloud Management | Exclude the entire BDRShield Server Proxy installation directory. |
Backup Repository | Folder | D:\sgstorage | Exclude all backup storage locations used by the Server Proxy.
|
PostgreSQL Data Directory | Folder | C:\PostgreSQLData | Exclude the PostgreSQL database directory. |
BDRShieldServerProxy.exe | Process | <BDRShield Server Proxy Installation Directory>\bin\BDRShieldServerProxy.exe | Server Proxy service process. |
VembuNFS.exe | Process | <BDRShield Server Proxy Installation Directory>\bin\VembuNFS.exe | NFS service process. |
BDRPersistentService.exe | Process | <BDRShield Server Proxy Installation Directory>\bin\BDRPersistentService.exe | Persistent background service. |
ImageIntegrityCheck.exe | Process | <BDRShield Server Proxy Installation Directory>\bin\ImageIntegrityCheck.exe | Performs backup image integrity verification. |
SGTray.exe | Process | <BDRShield Server Proxy Installation Directory>\bin\SGTray.exe | Tray application. |
postgres.exe | Process | <BDRShield Installation Directory>\PostgreSQL\17\bin\postgres.exe | PostgreSQL database process. |
Driver Files | Driver | C:\Program Files\Vembu\VembuBDR\lib\dokan\ C:\Windows\System32\drivers\dokan1.sys C:\Windows\System32\dokan1.dll C:\Windows\SysWOW64\dokan1.dll | Exclude the Dokan driver and related DLLs used for file-level recovery. |
BDRShield Backup File Types | File Type | Backup Repository | Exclude the following file types: *.sgcf , *.db , *.sbc , *.blkinfo , *.bdm , *.fbm . |
Configure exclusions for the following components:
BDRShield installation folders
BDRShield application processes (where supported)
Backup repositories and storage locations
PostgreSQL database directory
Agent installation folders
Changed Block Tracking (CBT) bitmap files
Required BDRShield communication ports
These exclusions help prevent real-time scanning from interrupting backup, replication, restore, Instant Boot, File Level Recovery, and database operations.
Note:
These recommendations apply to traditional antivirus solutions, Microsoft Defender, EDR/XDR solutions, and other endpoint protection platforms.
BDRShield uses PostgreSQL to store:
Backup metadata
Configuration
Schedules
Repository information
Job history
System settings
Because PostgreSQL continuously reads and writes database files, antivirus scanning can negatively affect performance and database operations.
Exclude:
Component | Recommendation |
PostgreSQL Data Directory | Exclude the complete database directory Example: C:\PostgreSQLdata |
postgres.exe | Exclude the PostgreSQL process (if supported) Typical path: < BDRShield Installation Directory>\PostgreSQL\17\bin\postgres.exe |
These exclusions help prevent unnecessary scanning of transaction logs, database files, and other PostgreSQL data files.
Reference link: https://wiki.postgresql.org/wiki/Running_%26_Installing_PostgreSQL_On_Native_Windows#Antivirus_software
Ensure that your firewall allows communication through the ports required by BDRShield.
If your environment uses:
Windows Defender Firewall
Third-party firewalls
EDR/XDR network protection
Host-based firewalls
configure the required inbound and outbound rules for all BDRShield services.
Refer to the BDRShield Firewall Ports documentation for the complete list of required communication ports: https://support.bdrshield.com/portal/en/kb/articles/port-configuration
After configuring the exclusions:
Restart affected BDRShield services if required by your antivirus software.
Run a manual backup job.
Verify that backups complete successfully.
Confirm that antivirus or EDR/XDR logs do not report blocked or scanned BDRShield components.
Review backup logs to verify normal operation.
Configure exclusions on both the Backup Server and protected endpoints where applicable.
Apply the same exclusions to EDR and XDR solutions.
Configure exclusions before performing large backup or restore operations.
Keep antivirus definitions updated while maintaining the recommended exclusions.
If backup issues continue after exclusions are configured, temporarily disable antivirus or the endpoint security solution (where permitted by your organization's security policy) to determine whether endpoint protection is contributing to the issue.
Configure only the recommended exclusions. Avoid disabling antivirus protection entirely.
Whenever possible, configure exclusions for the entire BDRShield installation locations rather than just the individual executable files, DLLs etc. If your antivirus supports recursive folder exclusions, all executables, DLLs, drivers, and supporting components within those locations are typically excluded automatically, including those added in future product updates.
If your security solution does not support recursive folder exclusions, review its quarantine or detection logs for any BDRShield executables, DLLs, drivers, or other application components located within the BDRShield installation locations. Restore and allowlist those files, as appropriate, to help ensure uninterrupted backup and recovery operations.