Active Protection errors
Hello,
After upgrading to build 8690, I started to receive a lot of Active Protection errors regarding rundll32.exe process:
"Self-protection detected suspicious process 'C:\Windows\System32\rundll32.exe'".How do I troubleshoot that? How do I know which rundll32 target Active Protection complains on and why? I checked running rundll32 threads and see no suspicious targets, only legitimate Microsoft process are involved (like perfos.dll, pla.dll and ntdll.dll).
Thank you in advance.
Leonid.

- Log in to post comments

Leots,
Acronis Active Protection can mark C:\Windows\System32\rundll32.exe as suspicious in case it is attempting to execute a .dll, which behavior looks similar to the malicious behavior patterns. This works that way because we do not monitor every .dll, but the processes calling the .dll files. You may want checking the log files in C:\ProgramData\Acronis\ActiveProtection\Logs\ for more details about this alert.
Ibrahim, I don't think this alert is actually the cause for the issue with backup. Have you checked the Activities tab for errors? Are there any clues?
Thank you,
- Log in to post comments