Antivirus Exclusions for BDRShield

Antivirus Exclusions for BDRShield

Antivirus (AV), Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), endpoint security, and firewall solutions can interfere with normal backup and recovery operations by scanning files, processes, and network communications that are actively used by BDRShield.

Configure the recommended antivirus/endpoint security exclusions on Backup Server, all protected agents, and all the applicable proxy agents (for example: Server Proxy, other proxies)

Failure to configure these exclusions may result in:

  • Backup data being quarantined or deleted

  • Backup or restore job failures

  • Product executables or services being blocked or removed

  • Reduced backup and recovery performance

  • Repository access issues

  • Instant Boot or File Level Recovery mount failures

  • Database performance degradation

  • False-positive malware detections

Important Note:

The procedure for configuring exclusions varies by antivirus or endpoint security product. Refer to your security vendor's documentation for product-specific instructions.

Master Checklist 

BDRShield Server-side Exclusions

Exclusion Item
Type
Typical Location/Example
Description / Notes

BDRShield Installation Directory

Folder

C:\Program Files\Vembu\

Exclude the entire BDRShield installation directory.

Backup Repository

Folder

D:\sgstorage

Exclude all backup storage locations used by BDRShield, including Local repositories, NAS repositories, SAN storage, SMB/CIFS network shares, External storage devices, and Repository Cache locations.

PostgreSQL Data Directory

Folder

C:\PostgreSQLData

Exclude the PostgreSQL database directory.

VembuBDR.exe

Process

<BDRShield Installation Directory>\VembuBDR\bin\VembuBDR.exe

Primary backup service process.

VembuNFS.exe

Process

<BDRShield Installation Directory>\VembuBDR\bin\VembuNFS.exe

NFS service process.

BDRPersistentService.exe

Process

<BDRShield Installation Directory>\VembuBDR\bin\BDRPersistentService.exe

Persistent background service.

ImageIntegrityCheck.exe

Process

<BDRShield Installation Directory>\VembuBDR\bin\ImageIntegrityCheck.exe

Performs backup image integrity verification.

SGTray.exe

Process

<BDRShield Installation Directory>\VembuBDR\bin\SGTray.exe

BDRShield tray application.

VembuOffice365Agent.exe

Process

<BDRShield Installation Directory>\VembuOffice365Agent\bin\VembuOffice365Agent.exe

Microsoft 365 Backup agent process.

VembuGSuiteAgent.exe

Process

<BDRShield Installation Directory>\VembuGSuiteAgent\bin\VembuGSuiteAgent.exe

Google Workspace Backup agent process.

postgres.exe

Process

<BDRShield Installation Directory>\PostgreSQL\17\bin\postgres.exe

PostgreSQL database process.

VembuBDR360Agent.exe

Process

<BDRShield Installation Directory>\VembuBDR360Agent\bin\VembuBDR360Agent.exe

BDR360 agent process (if installed).

Driver Files

Driver

C:\Program Files\Vembu\VembuBDR\lib\dokan\ C:\Windows\System32\drivers\dokan1.sys C:\Windows\System32\dokan1.dll C:\Windows\SysWOW64\dokan1.dll

Exclude these driver and related DLLs.

BDRShield Backup File Types

File Type

Backup Repository

Exclude the following file types: *.sgcf , *.db , *.sbc , *.blkinfo , *.bdm , *.fbm .

Network Ports

Port

6060 , 6061 , 32004 , 42005 , 32010 , 11211 , 9000 , 9001 , 9090 , 9091 , 443 , 80

Ensure these ports are not blocked or inspected by antivirus or endpoint security software.

BDRShield Agent-side Exclusions

BDRShield Agent Installation Directory

Folder

C:\Program Files\Vembu\VembuIntegrationService\ -> On-Prem Management

C:\Program Files\BDRCloud\BDRCloudDelegationService\ -> Cloud Management

Exclude the BDRShield Agent installation directory.

BDRPersistentService.exe

Process

<BDRShield Agent Installation Directory>\bin\BDRPersistentService.exe

Persistent background service.

VembuIntegrationService.exe

Process

<BDRShield Agent Installation Directory>\bin\VembuIntegrationService.exe

Integration service process.

voltracker.sys

Driver

C:\Windows\System32\drivers\voltracker.sys

CBT driver used for Windows Disk Image Backups.

bitmap.dat

File

C:\bitmap.dat
D:\bitmap.dat
E:\bitmap.dat

Exclude the bitmap.dat file on every protected volume. Applicable to Windows Disk Image Backups.

BDRShield Offsite DR Exclusions (If you are using Offsite DR)

BDRShield Offsite DR Installation Directory

Folder

C:\Program Files\Vembu\

Exclude the entire BDRShield Offsite DR installation directory.

Backup Repository

Folder

D:\sgstorage

Exclude all backup storage locations used by BDRShield Offsite DR.

PostgreSQL Data Directory

Folder

C:\PostgreSQLData

Exclude the PostgreSQL database directory.

VembuOffsiteDR.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\VembuOffsiteDR.exe

Offsite DR service process.

VembuNFS.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\VembuNFS.exe

NFS service process.

BDRPersistentService.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\BDRPersistentService.exe

Persistent background service.

ImageIntegrityCheck.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\ImageIntegrityCheck.exe

Performs backup image integrity verification.

SGTray.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuOffsiteDR\bin\SGTray.exe

Tray application.

VembuOffice365Agent.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuOffice365Agent\bin\VembuOffice365Agent.exe

Microsoft 365 Backup agent process.

VembuGSuiteAgent.exe

Process

<BDRShield Offsite DR Installation Directory>\VembuGSuiteAgent\bin\VembuGSuiteAgent.exe

Google Workspace Backup agent process.

postgres.exe

Process

<BDRShield Offsite DR Installation Directory>\PostgreSQL\17\bin\postgres.exe

PostgreSQL database process.

Driver Files

Driver

C:\Program Files\Vembu\VembuBDR\lib\dokan\ C:\Windows\System32\drivers\dokan1.sys C:\Windows\System32\dokan1.dll C:\Windows\SysWOW64\dokan1.dll

Exclude the driver and related DLLs.

BDRShield Backup File Types

File Type

Backup Repository

Exclude the following file types: *.sgcf , *.db , *.sbc , *.blkinfo , *.bdm , *.fbm .

BDRShield Server Proxy Exclusions (if you are using Server Proxy)

BDRShield Server Proxy Installation Directory

Folder

C:\Program Files\BDRShield\ServerProxy\ -> On-Prem Management

C:\Program Files\BDRCloud\ServerProxy\ -> Cloud Management

Exclude the entire BDRShield Server Proxy installation directory.

Backup Repository

Folder

D:\sgstorage

Exclude all backup storage locations used by the Server Proxy.

 

PostgreSQL Data Directory

Folder

C:\PostgreSQLData

Exclude the PostgreSQL database directory.

BDRShieldServerProxy.exe

Process

<BDRShield Server Proxy Installation Directory>\bin\BDRShieldServerProxy.exe

Server Proxy service process.

VembuNFS.exe

Process

<BDRShield Server Proxy Installation Directory>\bin\VembuNFS.exe

NFS service process.

BDRPersistentService.exe

Process

<BDRShield Server Proxy Installation Directory>\bin\BDRPersistentService.exe

Persistent background service.

ImageIntegrityCheck.exe

Process

<BDRShield Server Proxy Installation Directory>\bin\ImageIntegrityCheck.exe

Performs backup image integrity verification.

SGTray.exe

Process

<BDRShield Server Proxy Installation Directory>\bin\SGTray.exe

Tray application.

postgres.exe

Process

<BDRShield Installation Directory>\PostgreSQL\17\bin\postgres.exe

PostgreSQL database process.

Driver Files

Driver

C:\Program Files\Vembu\VembuBDR\lib\dokan\ C:\Windows\System32\drivers\dokan1.sys C:\Windows\System32\dokan1.dll C:\Windows\SysWOW64\dokan1.dll

Exclude the Dokan driver and related DLLs used for file-level recovery.

BDRShield Backup File Types

File Type

Backup Repository

Exclude the following file types: *.sgcf , *.db , *.sbc , *.blkinfo , *.bdm , *.fbm .


General Recommendations   

Configure exclusions for the following components:

  • BDRShield installation folders

  • BDRShield application processes (where supported)

  • Backup repositories and storage locations

  • PostgreSQL database directory

  • Agent installation folders

  • Changed Block Tracking (CBT) bitmap files

  • Required BDRShield communication ports

These exclusions help prevent real-time scanning from interrupting backup, replication, restore, Instant Boot, File Level Recovery, and database operations.

Note: 

These recommendations apply to traditional antivirus solutions, Microsoft Defender, EDR/XDR solutions, and other endpoint protection platforms.

PostgreSQL Recommendations   

BDRShield uses PostgreSQL to store:

  • Backup metadata

  • Configuration

  • Schedules

  • Repository information

  • Job history

  • System settings

Because PostgreSQL continuously reads and writes database files, antivirus scanning can negatively affect performance and database operations.

Exclude:

Component

Recommendation

PostgreSQL Data Directory

Exclude the complete database directory

Example: C:\PostgreSQLdata

postgres.exe

Exclude the PostgreSQL process (if supported)

Typical path:

< BDRShield Installation Directory>\PostgreSQL\17\bin\postgres.exe

 

These exclusions help prevent unnecessary scanning of transaction logs, database files, and other PostgreSQL data files.

Reference link: https://wiki.postgresql.org/wiki/Running_%26_Installing_PostgreSQL_On_Native_Windows#Antivirus_software

Note on Firewall Port Exclusions:

Ensure that your firewall allows communication through the ports required by BDRShield.

If your environment uses:

  • Windows Defender Firewall

  • Third-party firewalls

  • EDR/XDR network protection

  • Host-based firewalls

configure the required inbound and outbound rules for all BDRShield services.

Refer to the BDRShield Firewall Ports documentation for the complete list of required communication ports: https://support.bdrshield.com/portal/en/kb/articles/port-configuration

Verification   

After configuring the exclusions:

  1. Restart affected BDRShield services if required by your antivirus software.

  2. Run a manual backup job.

  3. Verify that backups complete successfully.

  4. Confirm that antivirus or EDR/XDR logs do not report blocked or scanned BDRShield components.

  5. Review backup logs to verify normal operation. 

 Best Practices   

  • Configure exclusions on both the Backup Server and protected endpoints where applicable.

  • Apply the same exclusions to EDR and XDR solutions.

  • Configure exclusions before performing large backup or restore operations.

  • Keep antivirus definitions updated while maintaining the recommended exclusions.

  • If backup issues continue after exclusions are configured, temporarily disable antivirus or the endpoint security solution (where permitted by your organization's security policy) to determine whether endpoint protection is contributing to the issue.

  • Configure only the recommended exclusions. Avoid disabling antivirus protection entirely. 

 Important Note 

  • Whenever possible, configure exclusions for the entire BDRShield installation locations rather than just the individual executable files, DLLs etc. If your antivirus supports recursive folder exclusions, all executables, DLLs, drivers, and supporting components within those locations are typically excluded automatically, including those added in future product updates. 

  • If your security solution does not support recursive folder exclusions, review its quarantine or detection logs for any BDRShield executables, DLLs, drivers, or other application components located within the BDRShield installation locations. Restore and allowlist those files, as appropriate, to help ensure uninterrupted backup and recovery operations. 

    • Related Articles

    • Backup Configuration in BDRShield

      How do I configure a backup job in BDRShield? To configure a backup job: Log in to the BDRShield web console. Navigate to the Backup section and click Add Backup Job. Select the source (e.g., physical server, virtual machine, or endpoint). Choose the ...
    • BDRShield - Release Notes

      BDRShield v9.2.0 (Cloud) Release Date: Aug 07, 2026 Overview: BDRShield Cloud v9.2.0 introduces new enhancements focused on improving recovery flexibility, storage scalability, backup resilience, and data protection across physical and virtual ...
    • Getting Started with BDRShield

      The BDRShield Getting Started Guide provides a comprehensive walkthrough of the entire backup and recovery setup process. Covering all BDRShield modules, this guide helps users configure, manage, and optimize their data protection environment. It ...
    • BDRShield Known Issues & Limitations

      This document will provide detailed information about the known issues and limitations of each module, helping you identify potential challenges and implement effective workarounds to ensure uninterrupted operations. File & Folder Backup & Recovery ...
    • Bitmap File Not Found Error in BDRShield

      KB ID: 104028 Summary: This knowledge base article addresses the "Bitmap File Not Found" error encountered within the BDRShield application. The error may occur due to various reasons such as the absence of the VembuCBT driver, outdated software ...