Skip to main content

Build 6559 update generates virus warning

Thread needs solution

Hi,

I just wanted to inform the forum about a virus warning that appear during update to build 6559.

The infected file is located in c:\program files\common files\acronis\vssrequestor\vss_requestor.exe. Virus name Gen:Variant Graftor.30964.

My antivirus program is Bitdefender total security.

I don't know if this is a false alarm or not or if the file behaves as a virus but it might be the reason why so many have problems installing the new build.

Hope this information is helpful.

 

0 Users found this helpful

Hello Lars,

I have uploaded a copy of the C:\Program Files (x86)\Common Files\Acronis\Vssrequestor\vss_requestor.exe file from my ATIH 2016 build 6559 system to the VirusTotal website and had this scanned by 55 virus engines where they all gave the file a clean bill of health - no virus found, including for Bitdefender.

https://www.virustotal.com/en/file/12a8b2149420da0a5216d26fdb97bd99010f311d8873d5c383d224ff96ea0416/analysis/1461058056/

SHA256: 12a8b2149420da0a5216d26fdb97bd99010f311d8873d5c383d224ff96ea0416
File name: vss_requestor.exe
Detection ratio: 0 / 56
Analysis date: 2016-04-19 09:27:36 UTC ( 0 minutes ago )

This would suggest either a local problem on your system with this file or your Bitdefender is not upto date? 

Hello Steve,

My Bitdefender Total Security is updated. I have a high security level set, might it be that this file is trying to access system files during update to build 6559 that are protected and therefore generates this alarm? I have tried to install this update to another computer with Kaspersky antivirus but it fails with the message access denied, so something is not right with this update. I have never had any problems earlier with the acronis software.

Hello Lars,

I have upgraded two different computers to the latest build 6559 version without hitting any issues and with two different security packages, so this is puzzling.

How did you get the upgrade software installer?  Was it directly within the ATIH 2016 GUI with the Download button that is shown when you start the application, or did you download the latest version from your Acronis Account?

I would suggest downloading a copy of the upgrade installer from your Acronis Account and carefully check that the checksum for this matches the file after the download has completed.  See screen shot from my account showing the MD5 checksum and file size, plus there is a link to KB document https://kb.acronis.com/content/1855 for how to verify the checksum.

Once you have the new copy of the installer, then uninstall the current software, run the Acronis Cleanup Tool (link in my signature below), restart your system, then do a clean install using the new installer.

If you have any backup tasks that you have already created and you want to keep, then copy the C:\ProgramData\Acronis\TrueImageHome\Scripts folder to a safe place - this and the other folders will be removed by the cleanup tool.

Attachment Size
350060-128083.png 15.62 KB

Anti-virus software will often flag low level disk access by applications that are not on their exclusion or whitelist as threats.  Acronis True Image by its very nature must gain such low level disk access upon install and operation.  It is best to disable such software during installation and to insure that applications are on the whitelists of such security applications.

Hi

I too have had this issue with the latest build 6559. My antivirus software (BullGuard) quarantined the vss_requestor.exe file during the upgrade installation. I have yet to run a backup since the upgrade so do not know if it will run correctly. My OS is Windows 10. Any further advice would be much appreciated.

Philip, I uploaded a copy of the vss_requestor.exe file to the Virus Total web site where it was scanned and declared clean by 55 different Antivirus products.  See my original response in post #1 above

If you want to confirm that the vss_requestor.exe file on your own system is safe to use, then you are free to upload a copy of it to the same Virus Total web site and check that you get the same results.

Once confirmed it is a false/positive - not a threat, it is recommended to whitelist Acronis in your AV software.  It does need low level windows access to take hold of VSS and lock system files for online backups on a routine basis so perhaps this is what is flagging in your particular AV applications.  I use Microsoft Defender, Symatec SEP12, Malwarebytes and a few others and Acronis is not an issue in those, but I still whitelist it anyway to ensure the best functionality.

36429: Acronis Software: Exclude Program Folders and Executables from Security Programs

Hello,

First I want to thank you all for your help with this issue, I really appreciate it. I have not had time the last days to test the solutions that have been proposed, but as soon as I have done that I will post the result.

Have a nice day