Salta al contenuto principale

False ransomware detection?

Thread needs solution

I recently upgraded to True Image 2020. One of the first surprises I got from this new version was a report about ransomware when I tried to run HexChat, the IRC client on my machine. False positive? One of the "affected files" was the hexchat.conf file. What is it about this file that would cause True Image to flag it as "affected" or the program itself as ransomware?

Another file that was affected was the servlist.conf file, in addition to a couple of log files from what is mostly programming channels. Does that mean that any text file that contains source code and is stored in the AppData folder is detected as possible ransomware by True Image 2020? What a silly thing. I feel safer already... not. I would have expected the detection to be a little more sophisticated than that.

0 Users found this helpful

Samir, please see KB 60193: Acronis True Image 2018, 2019 and 2020: Active Protection blocks legitimate applications - for help in dealing with this type of issue.

Thanks! That covers how to deal with it. But I have already dealt with it. It's been whitelisted.

I am more keen to know the reason why this program was detected as ransomware? If anyone could shed some light on that. I certainly hope I won't have to click through these dialogs a million times once it finds my software projects. I am assuming that it is only triggered if the code files are cloaked as config, log, or other such files that don't have a file name extension that's common for a code file, and only when they are found in the AppData folder.

 

Sorry but impossible to tell you why that particular program was identified as potential ransomware, which is likely to be based on the behaviour it uses etc.  Acronis do not publish the details of the inner working of their products and for any security product there is never any such details published.

Hey everyone,

We are posting the possible detection reason in the Active Protection Dashboard. 

I would start from there - it is in the Acronis True Image console in the "Active Protection" and "Manage processes" section.

Most probably this process does not have a valid certificate/signature and started to modify files.

Thanks Renata, guess I haven't encountered such issues to see this yet (and hopefully will continue to not find such items!).

The main issue I have is for an app that does not have a valid certificate, which I am aware of. I do not get any warning if the app is not white listed, it just slows down to about 10% of the usual speed due to the monitoring of what it is doing.

Ian

Modifying what files? System files? Isn't that more of a concern for Windows OS rather than Acronis True Image? As far as I understand Active Protection is not a replacement for your Anti-Virus software. What's so special about this anyway? Don't all Anti-Virus software have the so called "real-time protection engine"? If so, then Active Protection in the Acronis product should be concerned with protecting the integrity of the backups that are made and the Acronis True Image software itself. Otherwise, if it's here to do-it-all then it should be sold as a separate product (or offered for free).

Besides, HexChat is as simple as Windows programs get. The only thing it modifies is its own files, such as log files each time it starts, and possibly the config file.

The program in question is not digitally signed. Is that why it's being treated as ransomware? But then what is Firefox doing in the list of managed processes in True Image? It looks like like it's one of the Firefox EXE files I downloaded to the desktop some time ago (it's an irrelevant and obsolete entry and should not be in the list at all). Sadly I can't expand the column width so I can't read the full path. (Could Acronis do something about that please?)

I also have Explorer and DLL Host in the list of managed processes, and I didn't add those. I didn't add any of these except HexChat. None of these should be assumed to be safe just because they are part of the larger operating system. Explorer has been infected a number of times in the past, and several viruses are masqueraded as Explorer.

There is no additional information in True Image about why some process was marked as ransomware. It doesn't tell me more than I already know. It just says that HexChat was "manually added to the whitelist".

For a rundown on what Active Protection is and does please review the link below:

Active Protection

Active Protection is available for Free but is included in the True Image and Acronis Backup products.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Messaggi: 250
Commenti: 7092

Samir wrote:

There is no additional information in True Image about why some process was marked as ransomware. It doesn't tell me more than I already know. It just says that HexChat was "manually added to the whitelist".

Hello Samir,

Actually, there should be more details displayed in the pop-up window regarding the reason why the process is considered as suspicious. May I ask you to send Acronis system report from the PC in question via Feedback? I'll pass this info to the development for investigation.

Sadly I can't expand the column width so I can't read the full path. (Could Acronis do something about that please?)

I've created a change request for this in our internal system, thank you! 

 also have Explorer and DLL Host in the list of managed processes, and I didn't add those. 

If you tried to manually move\delete backups, Acronis Self-Protection should have offered you to allow the operation. In this case, explorer.exe is granted permission to modify files, see https://kb.acronis.com/content/59857.

Generally, Acronis Active Protection module uses behavioral heuristics and analyzes chains of actions done by a program (a process), which is then compared with the chain of events in a database of malicious behavior patterns. If the program acts similar to ransomware behavior, it is considered as suspicious. Please also refer to the article https://kb.acronis.com/content/62113

Regular Poster
Messaggi: 198
Commenti: 120

I have used Acronis True Image for several years with only minor issues. I recently upgraded to the 2021 version. Now I am starting to get the Possible ransomware injection detected, Acronis Active Protection dialogue box with the message Acronis Active Protection detected the process that modified your files and then Injection process within program Outlook.exe. My biggest problem is that when this dialogue box pops up, my whole computer locks up. I can't select any thing in popup box. I can't shut the computer down except by doing a hard shutdown (power button). I don't like doing that for several obvious reasons mainly that I lose anything I am currently working on. 

So when I get the popup, what do I do? Is there anyway to control this takeover by Acronis or to at least gracefully exit it? I am about to abandon Acronis and look for something else. Thanks for any insight/help.

This feature is obviously not ready for prime time.

It keeps jacking my system up.

VERY disappointing for a company that I have trusted for so many years

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Messaggi: 250
Commenti: 7092

Robert D wrote:

This feature is obviously not ready for prime time.

It keeps jacking my system up.

VERY disappointing for a company that I have trusted for so many years 

Hello Robert,

would you mind sending us Acronis system report from the affected machine along with the issue description via the in-product feedback tool? 

Ekaterina,

I have been having the same problem and I opened a support ticket.  Acronis support instructed me to whitelist the path and I did that.  I am STILL getting the pop-up warning.  It now happens frequently.  

 

I've attached a screenshot that shows the same process was Trusted and BLOCKED within seconds several times.

Upgrading to the new product, as you suggested to another forum member, is not an option.  I purchased Acronis true image 2021 as a perpetual license and I do not see  a perpetual option for the Cyber protect product.

This issue has been around a long time and Acronis released True Image 2021 without fixing it.  Please let us all know twhat the plans are to support customers who are having this issue.

 

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Messaggi: 250
Commenti: 7092

Hello Stephen,

I'm afraid such issues can be investigated on the latest versions only. Usually, in case of a confirmed issue in the product Acronis might offer a free upgrade. 

Free upgrade to a recurring subscription plan of "Cyber Protect Home Office" I'm afraid. Not interested.