Skip to main content

Possible Ransomeware injection detected - Acronis True Image 2021

Thread needs solution

I can't find a forum for ATI 2021 - so  i ended up here. I keep getting Possible Ransomeware injection detected with any number of files from 40 to 80 affected which I stop the process and reset by recovering files. These are always Adobe Creative Suite file (latest edition as of 10/2022). This software was directly installed from Adobe's site - no hooky stuff. I have done this so many times that I'm starting to get Critical Process Died errors and believe ATI is damaging the Windows install. The root problem always seems to be Core.exe but accompanied by a stream of other CS files.

I ahve seen a similar comment re Outlook in 69593: Acronis True Image 2021: Outlook.exe is detected as ransomware by Active Protection. Is the same issue in that I'm getting a false positive from CS. I have check the whole machine with Defender for Ransomeware and it comes up clean. In the meantime I have removed all Adobe products and I don't seem to have the problem since.

Can anyone confirm this is a false positive and that I could just stick Core.exe in the protection exclusions. Have to say dissapointed in Acronis withdrawing support on a product only a year or so old and also removing perpetual licenses.

Cheers

Brad

 

0 Users found this helpful

Paul, welcome to these public User Forums.

If the flagged files are all related to your Adobe application and you are confident that they are all safe, i.e. checked with your antivirus program scan, then whitelist the application using those files in Acronis Active Protection.

See KB 60193: Acronis True Image 2018, 2019 and 2020: Active Protection blocks legitimate applications which also applies to 2021.

Hi Steve, 

Thanks for taking the time to respond to this query. I am confident it is always CS files triggering this and I believe Node.exe to be the main issue. I also believe but have no way of checking that CS is automatically updating files through the Creative Cloud app and this is triggering ATI. Other than suspicions I have no way of checking this is happening.

I was hoping that another user was using this version of ATI and Creative Suite, or Acronis could confirm that this is an outstanding issue. The only other solution I could think of is using the 30-day full access trial in the Protection section of ATI and re-installing CS to see how that handles the issue. There are no current detected vulnerabilities.

All the recovered files are CS related files - one other odd thing is that it may find say 79 affected files but it recovers only 40 files another time it may be 35 files but it recovers 29 files...

Cheers

Brad

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 488

Dear Paul Bradbeer,
Thank you for reaching out. In addition to what Steve has already said, we would suggest checking prerequisites in Product's official documentation: Acronis True Image 2021 Help

Hi Daria

I've had look at those pages - thanks for the links.

Can you tell whether any other user has logged issues with the Adobe Creative Suite and ATI 2021 (I had the same issue earlier this year when I had installed the previous version of Creative Suite).

Also if I install the option for the 30 day Advanced Protection for free in the protection option - has Acronis updated the software to recognise the issue with Creative Suite?

Cheers

Brad

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 488

Dear Paul Bradbeer,
Thank you for the response. Yes, there are several other cases with Adobe Creative Suite and some cases were successfully resolved because the issue was checking all necessary prerequisites, but some issues were on Adobe's site and customers contacted Adobe's support. We can recommend the following: make sure you have the latest build, add Adobe to whitelist of Active Protection. If it does not help, please deactivate Active protection, collect sysreport and contact the Acronis support.