Skip to main content

notice of possible ransomware!

Thread solved

Acronis True Image 2019 informs me of a possible ransomware. False positive? It's with process powershell.exe and the files in folder C:ProgramData\Lenovo\ImController...

For bitdefender it's all ok.

 

1 Users found this helpful

I would check with Lenovo tech support concerning the flagged app/files and question there use of PowerShell on your PC.  I can think of no legitimate reason for an OEM app to do so and I have not heard or seen any of this before. 

I would lean toward this possibly being an accurate detection of ransomware until I could find out differently.  Having said that I would encourage you to block the Lenovo app and flagged files until such time as you verify they are OK.

I blocked them but they are activated when they restart. How can I verify if it is a false positive?

Maxwell, the first recommendation here would be to run any software update tools provided by Lenovo for your computer and ensure that you have the very latest versions of the Lenovo tools that are found in your Lenovo\ImController folders (battery meter etc).

If you are satisfied that there is no malware involved here, i.e. have run scans of the folders being reported by AAP, then follow the instructions in KB 60193: Acronis True Image 2018 and 2019: Active Protection blocks legitimate applications - to whitelist these Lenovo applications.

Hi Steve, well, Lenovo software was already updated. I have update bitdefender again, restar pc and I have performed new scan with bitdefender: unit C is clean, no problem.

After rebooting it did not appear acronis notice for pobbible ransomware. This "situation" is strange.

To create an exception with ATI I would like to be very sure.

Thanks.

As an additional step to verify that the files are not compromised contact Lenovo support and ask.  If their software is triggering other security software like AAP then they need to know that so that it can be remedied either by them or Acronis which ever is appropriate.

I reported the problem on the Lenovo forum. I await your reply. I don't understand how to contact Lenovo support directly. It's very strange.

 

Attachment Size
496999-166839.jpg 78.06 KB

I am providing a link to the Global Lenovo Support site.  It is English however, you can change the language at the top right side of the page.

Click on the PC, laptop, etc. option on this page then, on the next page which is the Contact Us page click on Consumer Products.  Now look below and you will see 2 options.  They are "We call you" or "You call us"  Take your pick.

Hope this helps :)

Lenovo Support

Look below the Products that you see.  There are 2 sections below that and the third section is the Contact Us section that I referenced.

Ok, so here's the number 877-453-6686.  I have no idea why you cannot navigate to it.

The Imcontroller is definitely not ransomware. Its something that Lenovo includes as part of the software preload on their machines. Its exact purpose is somewhat fuzzy to me. I searched the Lenovo forums and most of the references where about 3 years old. The major complaint about it seemed to be the excessive use of resources. I ran task manager on my Lenovo Ideapad and 5 instances running and none of them was using excessive resources. I did see the ransom ware flag from AAP and told it to ignore the process. THis thread explains how to disable it Modern.Imcontroller