Skip to main content

MalwareBytes Premium Identifies Acronis True Image's update as malicious site, blocking access

Thread needs solution

MalwareBytes Premium, version 4.5.12 always Identifies Acronis (True Image 2021 Build 39287), one of my purchased products, as malicious, blocking that program's update.

A few days ago, it blocked 194.26.29.195 and 91.240.118.77. It has also blocked other Acronis sites. These blockages are a few times a month. Is it legitimate, and should I unblock \Acronis\agent\bin\updater.exe permanently?

0 Users found this helpful
frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 488

Dear Alan,

Add the following files/folders to the exclusions/white list of the antivirus/security software (for Windows Defender see instructions here):

1) the path to the installation file of Acronis Cyber Protect Home Office/Acronis True Image, if the problem is with installing the software

2) the folders where the program's executable and configuration files are located. 

Note that the folder C:\ProgramData is hidden in Windows Explorer by default. In order to see it you need to enable displaying of hidden files and folders under Start - Control Panel - Appearance and Personalization - File Explorer Options - View - Show hidden files, folders and drives.

64-bit Windows 7, 8, 10:

C:\Program Files (x86)\Acronis
C:\Program Files (x86)\Common Files\Acronis
C:\Program Files (x86)\Common Files\Acronis\TrueImageHome
C:\ProgramData\Acronis

32-bit Windows 7, 8, 10:

C:\Program Files\Acronis
C:\Program Files\Common Files\Acronis
C:\ProgramData\Acronis

32-bit Window XP SP3:

C:\Program Files\Acronis
C:\Program Files\Common Files\Acronis
C:\Documents and Settings\All Users\Application Data\Acronis

Windows Vista and 64-bit Windows XP:

N/A (these operating systems are not supported by Acronis True Image)

3) If the security software still blocks Acronis True Image functionality after adding folders to exclusions, you also need to whitelist the product executables located in these folders. 

You can learn more in the article:
Acronis Software: exclude program folders and executables from antivirus and other security programs | Knowledge Base

Check out this feedback I received from MalwareBytes Tech support, in the attached file.  When I explored the links they showed, it appears that the servers that Acronis is attempting to access are compromised.  They're recommending that I do NOT unblock those specific sites.

Let me know if you concur that this could be a "hidden" issue with Acronis updates, and what if anything I should do knowing this "risk".

Note that this forum won't allow hyperlinks to be pasted, so I provided an "image" of the note that Malwarebytes sent me as an attachment.

Thanks, Alan Chinnici

Attachment Size
608655-346569.docx 51.29 KB
frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 0
Comments: 488

Dear Alan Chinnici,
Thank you for the update.
We have check the IP addresses from your first message they have nothing to do with Acronis.