Skip to main content

Active Protection errors

Thread needs solution

Hello,

After upgrading to build 8690, I started to receive a lot of Active Protection errors regarding rundll32.exe process:
"Self-protection detected suspicious process 'C:\Windows\System32\rundll32.exe'".How do I troubleshoot that? How do I know which rundll32 target Active Protection complains on and why? I checked running rundll32 threads and see no suspicious targets, only legitimate Microsoft process are involved (like perfos.dll, pla.dll and ntdll.dll).

Thank you in advance.
Leonid.

 

0 Users found this helpful

Hi,

 

We have the same issue

 

09:34:25 AM — 09:34:25 AM

Self-protection detected suspicious process 'C:\Windows\System32\rundll32.exe'

 

Backup did not start.

 

even after trying to run the backup button is disabled and cannot run it.

 

thanks.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 250
Comments: 7092

Leots,

Acronis Active Protection can mark C:\Windows\System32\rundll32.exe as suspicious in case it is attempting to execute a .dll, which behavior looks similar to the malicious behavior patterns. This works that way because we do not monitor every .dll, but the processes calling the .dll files.  You may want checking the log files in C:\ProgramData\Acronis\ActiveProtection\Logs\  for more details about this alert. 

Ibrahim, I don't think this alert is actually the cause for the issue with backup. Have you checked the Activities tab for errors? Are there any clues? 

Thank you,