Direkt zum Inhalt

Attempt to modify MBR

Thread needs solution

I use Acronis True Image 2018 and this morning I started getting this popup message:

Acronis Active Protection

An attempt by process 'C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe' to modify MBR of your disk was successfully blocked.

 

So far I get the message about once per boot (occurs about 1-2 minutes after the Windows desktop starts).

IAStorDataMgrSvc.exe and my whole drive scans clean by Trend Micro.  Is this a real problem or a false positive?  It seems like the Intel process might have entirely legitimate reasons to write the MBR.

0 Users found this helpful

Yesterday I installed the latest Intel Graphics Driver (for the I7 7700K integrated GPU).  No reason, just updating to the latest.  Looking at the install log, idoing that also installed Intel Extreme Tuning Utility, Intel Management Components, and Intel Rapid Storage Technology 15.7.1.1015.  So that is probably why this popup error started occurring today.  A new version of IRST.

 

It seems unlikely that I am infected so I believe Acronis is treating the new IRST version as a false positive.

 

BTW, the error pops up not just at boot time but also periodically long after boot.  Please confirm it is a false positive.

Looking at the Acronis log, it also blocked registry access from program C:\Program Files (x86)\AMD\Performance Profile Client\AMDPPCM.exe

 

And registry access from C:Program Files\DiskLED\DiskLED.exe

 

All legitimate sounding apps that scan clean by Trend Micro.  Looks like I'm going to have to disable Acronis Active Protection.

 

Bruce, you will need to whitelist these Intel RST applications.

See KB 60193: Acronis True Image 2018: Active Protection blocks legitimate applications for more information.

Thanks, but it's flagging too many apps for me to trust the feature.  It obviously wasn't well thought out.

Bruce, please open a Support Case direct with Acronis for this issue as this is still only version 2.0 of AAP and I would guess that Acronis are still learning in terms of the very broad list of possible known/trusted applications that they shouldn't need to be flagging up.

Fyi too... you don't have to install the entire IRST package. Just download the drivers which are in the flpyx64.zip in the same download area on the intel page. Extract the zip and use device manager to update your storage controller driver by pointing the path to the extracted folder. 

I never run the full IRST package, but that's just me.