Skip to main content

active "protection" suspicious list STILL SAME ISSUE with rundll32

Thread needs solution
0 Users found this helpful

You should open an Admin command prompt and type tasklist /m /fi "imagename eq rundll32.exe"

You can copy and paste that command as well.  It will produce a list of the services being running rundll32.exe.  You should not find many but you should find the service that is being flagged by Active Protection.  My suspicion is  CTAudSvc.exe will be the service.  If that is correct add that to the Exclusions whitelist to remedy the warning.

If you find it is something else then you need to investigate that.  Could be a malicious activity. 

Understand that Active Protection does not have an internal whitelist.  It works on known behavior patterns of ransomware.  It is the service or app in which runs rundll32.exe that is triggering a known behavior pattern in Active Protection that causes the warning.

I have the same issue
But i dont find what is the cause.
This is not old, i never see this before (last time maybe before windows update for this build)

TrueImage_2018-08-17_17-38-05.png

 

Any idea ?

cmd_2018-08-17_17-23-06.png

After one reboot, this is change to this...
Hum many process of Windows

TrueImage_2018-08-17_18-10-03.png

Something notable to know (possible that this is the cause?) :
I changed the name of the user folder.
windows named this folder after my name and first name, and I changed this following a procedure described by Microsoft, everything works fine, registry entries are correctly pointed to the new name but I wonder why Acronis detecte bcp of Windows processes as suspicious (this is a legal version without modification)

Antivirus: Kaspersky Total Security 19

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 250
Comments: 7092

Hello ReActif,

The status Suspicious doesn't in fact means the process is harmful, only that we start monitoring it. Such components like rundll32.exe and cmd.exe are always in the list of the monitored processes, as they can potentially execute malicious programs. In case of a real threat Active Protection throws a different warning and blocks the malicious program. In Acronis True Image 2019 we changed the status Suspicious to Monitored in order not to confuse a user.