Active Protection warning legitimate?
How do I know if an Active Protection warning is legitimate or false positive?
Using most current version of Acronis. Also, running Avast Pro on Windows 10 64.
A scheduled backup was running but not completing. Re-started the PC and got this message when I opened the Acronis program.
Thank you,
kristin
Attachment | Size |
---|---|
acronis active protection.JPG | 73.71 KB |

- Log in to post comments

Kristin, on the face of things, this looks to be a 'false positive' warning given the involvement of SVCHOST and the Microsoft\Diagnosis folder hosting these .XML files, but in this uncertain world of malware etc, I would not recommend whitelisting SVCHOST.EXE as this is just a program that facilitates other activities such as Windows Update etc.
Perhaps the more pertinent question here is to ask if this AAP action, assuming that you take the Block option, has any impact on anything running on your system, or whether the same is true if you take the Allow option here? Do you get any warnings from Avast about any suspicious activity here?
If you are worried about this scenario, then raise a Support Case with Acronis and have them look at the detailed messages that should be present in the associated AAP log files.
You can download / use the MVP Log Viewer tool (from the Community Tools link below) and use this to take a look at the Anti Ransomware logs yourself.
More information, in particular from the task logs, would be needed to offer any advice on the second issue you mentioned: "A scheduled backup was running but not completing."
- Log in to post comments

Hello Kristin Wheeler,
The easiest way to check whether the detect is legitimate is to open the folder where the "encrypted" files are. If these files are still .xml, you can open it and check whether the content is readable.
In case they are not .xml or the content is unreadable, this is most probably a legitimate detection.
It would be great if you could attach the system report http://kb.acronis.com/content/2707. In this case we could check the logs for any suspicious activity.
- Log in to post comments
In reply to Hello Kristin Wheeler,… by truwrikodrorow…

Hi Renata Gubaydullina, I just had three instances of the same error after a reboot - svchost.exe modifying files in C:\ProgramData\Microsoft\Diagnosis\SoftLanding. I selected Allow - the files in the folder still have an .xml extension. I cannot display the contents ('Access denied') even from an admin command prompt.
I have a system report - where can I send it?
Thanks, Norbert
- Log in to post comments

Hi Renata Gubaydullina, I have had to disable Active Protection. Even through c:\Windows\system32\svchost.exe is in the Trusted 'Manage permission list', I am getting repeated alerts. I also see numerous activity entries where rundll32.exe was blocked from accessing the registry without any associated alerts. This may be a good thing or Acronis may be blocking a valid operation.
I have read https://kb.acronis.com/content/60193 - what is missing is information on why Active Protection believes rundll32.exe is suspicious. At a minimum, pop up an alert so I can link the activity with an application.
Thanks, Norbert
- Log in to post comments

Norbert, as I understand, both svchost.exe and rundll32.exe are simply facilitator programs to run processes for something else, including Windows processes such as Update, so whitelisting these processes would not help here if there is any form of malware activity causing their use.
I would recommend opening a Support Case with Acronis and sending in your System Report to allow the Acronis developers to review the logs associated with AAP.
- Log in to post comments


Was this false positive resolved? I am in the same situation as Kristin Wheeler and Norbert nh905.
Thx,
- Log in to post comments

Stephen, welcome to these public User Forums.
This post is now heading towards 2 years old and relates to ATI 2018 which is now 2 versions back. If you are using ATI 2018 then please check you have build 15470 which was the final build released.
Beyond having the final build installed, then you would need to demonstrate that any issues exist in the current supported ATI 2020 version for Acronis to take any further actions for it.
- Log in to post comments