Skip to main content

Active Protections "Suspicious Processes".

Thread needs solution

The latest update to True Image 2018 "active protection" does not match the help file, or the knowledge base articles that I have been able to find.   I'm not sure what to do with some of the "suspicious processes", none of which appear to be malicious.

Specifically, RunDll32.exe is a windows process that is called by many applications, and may be seen in the Resource Monitor with several instances running.  Using "Add" to Whitelist it does not seem safe, but on the other hand, it is a legitimate process that needs to be allowed to run in most instances.  Should I ignore it?

What about the DELL Wireless card process?  Or the printer "control center" for Brother printers?  Intel drivers, which a rouge program could overwrite? 

Can I ignore it all unless problems occur?

A white paper, explanation of how it all works, would be helpful.

0 Users found this helpful

Royce, welcome to these User Forums.

Please see KB 60193: Acronis True Image 2018: Active Protection blocks legitimate applications for recommended guidance on this subject.

If you are still seeing issues after whitelisting valid applications, then please open a Support Case direct with Acronis and let their developers investigate the issue further with you.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 250
Comments: 7092

Just to add, RunDll32.exe might be considered as suspicious if it is trying to launch the app, which is showing the behavior similar to the malicious patterns. 

Note: the valid process is normally located at \Windows\System32\rundll32.exe, but sometimes spyware uses the same filename and runs from a different directory in order to disguise itself. That is also the reason why we cannot exclude rundll32.exe and other valid parts of Windows\common vendors from the scan.

The product team is thinking of the ways how to provide more information to a user why the process is called suspicious or why it was blocked by Acronis Active Protection.

How do you advice us to use it at best then ?

We can identify about our software that we install for example but what about the process from microsoft?

 

Because in theory, the location, the name and also the certificate can be false no?

By the way some of the exe I can't make them appear on the explorer window when I open it when I push the add button ....

like conhost.exe from microsoft in windows/system32

and IPROSetMonitor.exe from in tel same location

Welcome to these User Forums.

I have not needed to whitelist any Windows OS programs such as conhost.exe and do not have the Intel IPROSetMonitor.exe program on my computer, but if you are finding that AAP is wanting to block both of these programs, then I would suggest several actions:

  1. Run a full antivirus scan to ensure that there is not any malware infection involved here - a common tactic is for such malware to mascerade as valid MS or other similar programs.
  2. Open a Support Case directly with Acronis and provide them with a copy of the C:\ProgramData\Acronis\ActiveProtection\Logs\anti_ransomware.0.log or other logs from the same folder that cover the period of time where the issue was reported.

then what about rundll32 ?

AAP is blocking it at several occasion, I have no virus on this host since it s a new installation + scan several times with several AV, so bad behaviour from AAP does exist.

And It's not the end-goal of my question:

What would be a good way then to identify manually a windows process at the good location with the good certificate as a threat?

 

rundll32 is called by a wide variety of programs in order to launch their functions, so AAP doesn't block AAP purely based on rundll32 being invoked, but based on the behaviour it is exhibiting.

To repeat the advice I gave to another user in this topic earlier:

Please see KB 60193: Acronis True Image 2018: Active Protection blocks legitimate applications for recommended guidance on this subject.

If you are still seeing issues after whitelisting valid applications, then please open a Support Case direct with Acronis and let their developers investigate the issue further with you.

yeah i did look at that, but your link wasn't really guidance. IT was to resolve an issue of a blocked applications. I don't notice any really big issue here. I just notice in the logs of AAP that rundll32 got blocked several times and no other app... That's my problem and since I m pretty sure I m not infected by anything, I can't know why AAP have blocked it.... IT's the lack of information on this subject which is not great.

 

And that doesn't answer to my question either of how to identify manually if one of our windows process is bad... Do you understand why what I m saying? OR isn't clear enough ?

Charles, have you downloaded / used the MVP Log Viewer tool to look at the AntiRansomware logs that are created by the AAP process?

Example from my own system:

2018-04-17 12_05_40 AAP Activity.png

The log file shows the following entries matching the above activity:

12/04/2018 18:36:45 :307  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] has started (parent PID = 26 (internal))
12/04/2018 18:36:45 :308  Setting the trust status of [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] to 'not trusted': success
12/04/2018 18:36:45 :314  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :614  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :615  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :615  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :616  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :616  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :617  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :618  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :618  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :618  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :619  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :619  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :619  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :620  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :620  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :620  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :621  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :622  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :622  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :622  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :623  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :624  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :624  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :625  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :625  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :625  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :626  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :626  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :626  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :626  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :627  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :627  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :628  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :628  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :637  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :638  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :638  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :639  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :639  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :640  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :640  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :641  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :641  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :642  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :642  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :642  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :643  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :643  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :643  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :644  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :644  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :645  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :645  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :645  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :645  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :646  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :646  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :646  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :647  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :647  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :647  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :648  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :648  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :648  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :649  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :649  "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :649  Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:46 :163  [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] has stopped (parent PID = 0 (internal))