Skip to main content

Got an Alert; Not Sure What to Do ??

Thread needs solution

  Hi,

  I'm running True Image 2018, W-10, FireFox browser 63.0.3  I just closed my browser after a fairly long session and got a Ransomware Alert.  It said it was FireFox.exe and it was trying to do something with 20 files/folders.  It gave me a choice to "block" or "trust".  Anyway, it caught me by such surprise I chose "block" and did not check the box to "always recover".  My backups are on a portable USB drive so that can't even be in play as it's not plugged in.  I'm still trying to figure out just what happened and where I am at this point ?  I've restarted my PC and everything seems to be working as normal like nothing happened.  When I look at my TI Settings, it shows that "one" block process has happened but I don't see anyway to get any more info about it.  I'm also wondering if I ever have to use my backup, if the 20 FireFox folders/files will be "blocked" from being restored if I need to do a recovery.  Maybe I'm making too much of of this ?  Any explanation would be appreciated and also any action I might have to take.

0 Users found this helpful

Don, If all looks to be Ok after restarting the computer then it doesn't seem to be an immediate cause for concern.

If you want to try to dig a little deeper into this issue, then please download the MVP Log Viewer tool (link below) and use this to take a browse through the Anti Ransomware logs created by Acronis for around the time when the alert was given and you took the block option.

The logs are not the easiest to understand but may give you a better idea of what was happening if you can find the right time area.

  Steve, thanks for getting back to me.  I opened my "settings" tab and clicked on "activity".  There was only one entry at the time I closed my browser which said, "The process was blocked: C:\Program Files\Mozilla Firefox\firefox.exe".  Everything is still working as "usual", so that's a good thing.  What concerns me is if my backups and any future recovery operations will still be working OK ?  Like I said before, I use a USB portable hard drive to contain my backups, where I do a full backup of the system and then after that, 3 differential system backups, then a full backup to start a new cycle.  I just want to be comfortable that nothing will change with my backup and recovery process with Acronis.  Years ago, on an older system, I had to do a full recovery "manually" as I didn't have any recovery SW and I never want to have to go through that again.  Since getting Acronis back in 2012, I've had to do recoveries several times and they worked great with no issues. Since my backup drive was not even connected, I know it's OK right now, but the next time I connect it to do a backup, will the blocked log make any changes to future backup and recovery activity ?  Thanks in advance for any tips you can give me.

Don, any blocking done by AAP will not affect your backup and recovery capability here, especially as you say that Firefox is still working normally for you too.

If you open the AAP page in the main ATI GUI, then look at the top of the main panel, you should see 3 page tab options, Protection | Activity | Manage processes

If you open the Manage processes tab, you should then see the blocked Firefox process listed, and when you hover your mouse over the entry, you should then see an option allowing you to remove that entry if you want to, and therefore see if AAP will post any further alerts for it later?