Skip to main content

Acronis Detecting Ransomware Attack - Is It a False Positive?

Thread solved

I am using an application called Local.  It is used to develop websites on a local computer (not on the web).  I use to setup my computer as a server, download Wordpress and related programs, apps and plugins which are very common and typical for a Wordpress website.  when running the Local program recently, Acronis reported an attack, placed several files in quarantine, and ultimately my system crashed.  I lost all websites and the Local application is no longer working.  This is ok if the attack was a real attack, but not OK if it was a false positive.  

In my research, I discovered several others who have had similar experiences, but with Malwarebytes.  Assuming that the ransomware protection by Malwarebytes and Acronis work in a similar fashion, it is possible that there is some activity on the Local server which might be impacting this.  

The problem is that I do not understand if it was a real attack or a false positive.  to me (and I am no expert), it seems possible that it was false positive.  an intruder would need to get into my computer and then get into the Local server.  it seems more difficult and also there is less at risk within the server environment.  

I would like to know if anyone else has had similar experiences.

I would also like to hear from Acronis.  I attempted to get phone support and then instant chat and none of that worked for me.  (instant chat never provided me with the popup button to begin the chat - this was the same problem with Safari, Chrome or FF).

thanks for your interest and thoughts.

Steve

0 Users found this helpful

Steve,

I have never seen any report here like yours.  Not many users here have need for the types of software that you mention here.  I have dabbled with Wordpress a bit but have little experience with it.  Likewise, the Cyber protection offered in True Image is very new to the product and most users to date believe it is unproven and therefore not reliable and prefer other third party apps for that purpose.  I personally do not have an opinion one way or the other.

With respect to if you did indeed suffer an attack only Acronis support would be able to answer that.  I can only encourage you to continue your efforts to make contact with Support to address your concerns.

Steve, in addition to the comments already given by Enchantech, have you tried adding the main 'Local' application executables to the Protect Exclusions list in ATI 2021?

See KB 65499: Acronis True Image 2021: Advanced Antimalware Protection FAQ for some general information.

KB 63409: Information required for investigation of a Ransomware attack

thanks to Enchantech and Steve Smith for your suggestions

Acronis now has relevant files from me (quarantined file) and will work to review and determine whether false positive or real Ransomware attack.  No guarantees that I will know anything soon or at all. 

 

My application is still not working and I hope to spend some time this week fixing that application.

 

thanks for your advice - BTW Acronis also suggested I consider using the Exclusion List.