Active Protection warning on trusted app.
I have cmd.exe as a trusted app in Active Protection. When I run a batch file the Active Protection warning message still displays and prompts me to block or ignore. I need this batch to run without user interaction. The batch file deletes a ".tib" file.
Thanks for any help.

- Log in to post comments

Jim, have you tried unchecking the Active Protection setting to protect Acronis True Image files?
- Log in to post comments

Clearing the check mark in Active Protection Settings to protect True Image files will allow you to delete tib files using Explorer and I suspect a batch file as well. It also allows ransomware to modify, overwrite, delete, tib files as well. Use at your own discretion.
- Log in to post comments

There is a setting for excluding anti-ransomware monitoring for folders or files. I excluded the folder but still received the warning message. So it seems this setting is not working properly.
- Log in to post comments

Jim, any issues with AAP should be reported to Acronis by opening a Support Case to allow them to investigate the matter more fully using the step by step details of what you are doing.
- Log in to post comments


Thanks Jim, please let us know how you get on. I have just submitted a support case for a different issue with AAP in this forum.
- Log in to post comments

Jim, I tried what you did and also specified in the exclusion list to exclude the .tib files by mask. It too failed.
All this got me to thinking about how easy it should be. After all, we want a system that cannot be overridden easily. On the one hand, we are trying to exclude a folder from ransomware monitoring, but the other hand is saying to protect .tib files.
These seem to be considered two separate issues in the program. One issue is monitoring for ransomware while the other is protecting ATI files. At this point, the only way to delete the .tib is through a manual response, which is fully understandable so as not to open up the possibility of malicious software doing that.
Sounds like there should perhaps be a separate type of exclusion to handle removing .tib files.
- Log in to post comments

I suspect that what we are seeing is by design (I noticed it some time back). It may be that there are two prongs to Active Protection, one is monitored folders and the other is for monitored applications - if an application is not white listed then it cannot operate on files in a folder that is not monitored.
- Log in to post comments

Well, I think that there are conflicting design elements at play. The exclude list identifies folders and files that are excluded from anti-ransomware monitoring. If the system prevents the deletion from the specified folder, then it is still monitoring that folder. If there are exceptions to the exclude list, i.e., ".tib" files are always monitored, the exceptions should be in the description at the top of the exclude list page. Just a thought.
- Log in to post comments

I see there was a new build released (9850) in the last 24 hours, things may have changed with that build - you never know your luck.
Ian
- Log in to post comments

FYI, I worked with the first tier support. The issue has been escalated. I'll let you know when it has been resolved.
Jim
- Log in to post comments

As it turns out, AP will not allow "tib" files to be deleted. Support on this issue was great. They were very responsive. I suggested that they add a note on the file and folder exclusion dialog that certain files and file types will not be excluded from AP protection.
- Log in to post comments

Jim, thanks for passing on your feedback from your Support Case. It makes sense that AAP will want to exclude Acronis .TIB files from being added to the file/folder exclusions list, as they are the principle focus of the protection mechanism. I agree that there should be some more help information in this area.
- Log in to post comments