Skip to main content

Active Protection warning legitimate?

Thread needs solution

How do I know if an Active Protection warning is legitimate or false positive? 

Using most current version of Acronis. Also, running Avast Pro on Windows 10  64.

A scheduled backup was running but not completing.  Re-started the PC and got this message when I opened the Acronis program.

Thank you,

kristin

Attachment Size
acronis active protection.JPG 73.71 KB
0 Users found this helpful

Kristin, on the face of things, this looks to be a 'false positive' warning given the involvement of SVCHOST and the Microsoft\Diagnosis folder hosting these .XML files, but in this uncertain world of malware etc, I would not recommend whitelisting SVCHOST.EXE  as this is just a program that facilitates other activities such as Windows Update etc.

Perhaps the more pertinent question here is to ask if this AAP action, assuming that you take the Block option, has any impact on anything running on your system, or whether the same is true if you take the Allow option here?  Do you get any warnings from Avast about any suspicious activity here?

If you are worried about this scenario, then raise a Support Case with Acronis and have them look at the detailed messages that should be present in the associated AAP log files.

You can download / use the MVP Log Viewer tool (from the Community Tools link below) and use this to take a look at the Anti Ransomware logs yourself.

More information, in particular from the task logs, would be needed to offer any advice on the second issue you mentioned: "A scheduled backup was running but not completing."

Hello Kristin Wheeler,

The easiest way to check whether the detect is legitimate is to open the folder where the "encrypted" files are. If these files are still .xml, you can open it and check whether the content is readable.

In case they are not .xml or the content is unreadable, this is most probably a legitimate detection.

 

It would be great if you could attach the system report http://kb.acronis.com/content/2707. In this case we could check the logs for any suspicious activity.

In reply to by truwrikodrorow…

Hi Renata Gubaydullina, I just had three instances of the same error after a reboot - svchost.exe modifying files in C:\ProgramData\Microsoft\Diagnosis\SoftLanding.  I selected Allow - the files in the folder still have an .xml extension.  I cannot display the contents ('Access denied') even from an admin command prompt.

I have a system report - where can I send it?

Thanks, Norbert

Hi Renata Gubaydullina, I have had to disable Active Protection.  Even through c:\Windows\system32\svchost.exe is in the Trusted 'Manage permission list', I am getting repeated alerts.  I also see numerous activity entries where rundll32.exe was blocked from accessing the registry without any associated alerts.  This may be a good thing or Acronis may be blocking a valid operation.  

I have read https://kb.acronis.com/content/60193 - what is missing is information on why Active Protection believes rundll32.exe is suspicious.  At a minimum, pop up an alert so I can link the activity with an application.

Thanks, Norbert

Norbert, as I understand, both svchost.exe and rundll32.exe are simply facilitator programs to run processes for something else, including Windows processes such as Update, so whitelisting these processes would not help here if there is any form of malware activity causing their use.

I would recommend opening a Support Case with Acronis and sending in your System Report to allow the Acronis developers to review the logs associated with AAP.

Was this false positive resolved? I am in the same situation as Kristin Wheeler and Norbert nh905.

Thx,

 

Stephen, welcome to these public User Forums.

This post is now heading towards 2 years old and relates to ATI 2018 which is now 2 versions back.  If you are using ATI 2018 then please check you have build 15470 which was the final build released.

Beyond having the final build installed, then you would need to demonstrate that any issues exist in the current supported ATI 2020 version for Acronis to take any further actions for it.