Active Protections "Suspicious Processes".
The latest update to True Image 2018 "active protection" does not match the help file, or the knowledge base articles that I have been able to find. I'm not sure what to do with some of the "suspicious processes", none of which appear to be malicious.
Specifically, RunDll32.exe is a windows process that is called by many applications, and may be seen in the Resource Monitor with several instances running. Using "Add" to Whitelist it does not seem safe, but on the other hand, it is a legitimate process that needs to be allowed to run in most instances. Should I ignore it?
What about the DELL Wireless card process? Or the printer "control center" for Brother printers? Intel drivers, which a rouge program could overwrite?
Can I ignore it all unless problems occur?
A white paper, explanation of how it all works, would be helpful.


- Anmelden, um Kommentare verfassen zu können

Just to add, RunDll32.exe might be considered as suspicious if it is trying to launch the app, which is showing the behavior similar to the malicious patterns.
Note: the valid process is normally located at \Windows\System32\rundll32.exe, but sometimes spyware uses the same filename and runs from a different directory in order to disguise itself. That is also the reason why we cannot exclude rundll32.exe and other valid parts of Windows\common vendors from the scan.
The product team is thinking of the ways how to provide more information to a user why the process is called suspicious or why it was blocked by Acronis Active Protection.
- Anmelden, um Kommentare verfassen zu können

How do you advice us to use it at best then ?
We can identify about our software that we install for example but what about the process from microsoft?
Because in theory, the location, the name and also the certificate can be false no?
By the way some of the exe I can't make them appear on the explorer window when I open it when I push the add button ....
like conhost.exe from microsoft in windows/system32
and IPROSetMonitor.exe from in tel same location
- Anmelden, um Kommentare verfassen zu können

Welcome to these User Forums.
I have not needed to whitelist any Windows OS programs such as conhost.exe and do not have the Intel IPROSetMonitor.exe program on my computer, but if you are finding that AAP is wanting to block both of these programs, then I would suggest several actions:
- Run a full antivirus scan to ensure that there is not any malware infection involved here - a common tactic is for such malware to mascerade as valid MS or other similar programs.
- Open a Support Case directly with Acronis and provide them with a copy of the C:\ProgramData\Acronis\ActiveProtection\Logs\anti_ransomware.0.log or other logs from the same folder that cover the period of time where the issue was reported.
- Anmelden, um Kommentare verfassen zu können

then what about rundll32 ?
AAP is blocking it at several occasion, I have no virus on this host since it s a new installation + scan several times with several AV, so bad behaviour from AAP does exist.
And It's not the end-goal of my question:
What would be a good way then to identify manually a windows process at the good location with the good certificate as a threat?
- Anmelden, um Kommentare verfassen zu können

rundll32 is called by a wide variety of programs in order to launch their functions, so AAP doesn't block AAP purely based on rundll32 being invoked, but based on the behaviour it is exhibiting.
To repeat the advice I gave to another user in this topic earlier:
Please see KB 60193: Acronis True Image 2018: Active Protection blocks legitimate applications for recommended guidance on this subject.
If you are still seeing issues after whitelisting valid applications, then please open a Support Case direct with Acronis and let their developers investigate the issue further with you.
- Anmelden, um Kommentare verfassen zu können

yeah i did look at that, but your link wasn't really guidance. IT was to resolve an issue of a blocked applications. I don't notice any really big issue here. I just notice in the logs of AAP that rundll32 got blocked several times and no other app... That's my problem and since I m pretty sure I m not infected by anything, I can't know why AAP have blocked it.... IT's the lack of information on this subject which is not great.
And that doesn't answer to my question either of how to identify manually if one of our windows process is bad... Do you understand why what I m saying? OR isn't clear enough ?
- Anmelden, um Kommentare verfassen zu können

Charles, have you downloaded / used the MVP Log Viewer tool to look at the AntiRansomware logs that are created by the AAP process?
Example from my own system:
The log file shows the following entries matching the above activity:
12/04/2018 18:36:45 :307 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] has started (parent PID = 26 (internal))
12/04/2018 18:36:45 :308 Setting the trust status of [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] to 'not trusted': success
12/04/2018 18:36:45 :314 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :614 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :615 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :615 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :616 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :616 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :617 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :618 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :618 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :618 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :619 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :619 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :619 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :620 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :620 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :620 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :621 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :622 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :622 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :622 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :623 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :624 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :624 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :625 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :625 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :625 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :626 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :626 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :626 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :626 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :627 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :627 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :628 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :628 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :637 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :638 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :638 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run'
12/04/2018 18:36:45 :639 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :639 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :640 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :640 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :641 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :641 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :642 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :642 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :642 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :643 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :643 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :643 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :644 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :644 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :645 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :645 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :645 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :645 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :646 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :646 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :646 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :647 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :647 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :647 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :648 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :648 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :648 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:45 :649 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] is trying to create registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32' with access mask = 3 [ KEY_QUERY_VALUE KEY_SET_VALUE ]
12/04/2018 18:36:45 :649 "C:\Windows\System32\rundll32.exe" can be trusted (cache)
12/04/2018 18:36:45 :649 Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] prevented from accessing registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32'
12/04/2018 18:36:46 :163 [driver] Process [601 (internal); 10944 (system-wide); "C:\Windows\System32\rundll32.exe"] has stopped (parent PID = 0 (internal))
- Anmelden, um Kommentare verfassen zu können