Direkt zum Inhalt

dasHost - potential Ransomware-Code ?

Thread needs solution

Hello,

Acronis True Image 2021 detects since yesterday a potential ransomware code in the Windows System file "dasHost.exe". It states after every Windows start that 14 files have been changed. These files, however, lie in a System folder which I cannot access, even not as Windows Admin (see screenshot).

I cannot rename the Windows System file "dasHost.exe" to replace it afterwards by an backup file version.

Stopping the process has no effect. Starting Windows again, the message pops up again, but with another 14 files.

A system check with Antivirus Bitdefender and, in addition, a check of the Windows System file "dasHost.exe" on the VirusTotal website was both negative!

Does anybody has a similar detection right now?
Is the behavoir of "dasHost.exe" correct?

What should I do further on?
a) ignore the detection (because the Antivirus checks were negative)
b) replace the file by a backup version (is this possible by Acronis backup even if the file is protected by the system)
c) what else...

Thanks in advance

Anhang Größe
Acronis Ransomware Identifikation.docx 116.73 KB
0 Users found this helpful

Notwix, welcome to these public User Forums.

Do you have Antivirus Bitdefender enabled / running on your system in addition to having Acronis Active Protection enabled & running?

See KB 67117: Acronis True Image 2021: using two or more antivirus solutions on the same computer is not recommended

If you have checked your system for virus / malware and it comes back as clean plus have run the recommended system integrity checks below, then it should be safe to add dasHost.exe to the exclusions for AAP to prevent further actions.

DISM /Online /Cleanup-Image /RestoreHealth
SFC /scannow

Hi Steve,

thank you for your comment. Indeed, I use Bitdefender, and a full malware screen didn´t detect any suspicious file on my PC.

I replaced the file "dasHost.exe", which was identified by Acronis as root cause, by a version from a previous backup. However, the Acronis agent detects again some obviously suspicious file changes by "dasHost.exe", always immediately after reboot / start of the PC.

The "modified" files are always picture files in the same folder
      C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\
Checking these files revealed no hint for any malware.

Then I tried to add the file "dasHost.exe", which I can easily find with the windows explorer in "C:\Windows\System32" to the exception list of Acronis Protection. The file is not hidden or something else. However, it is not visible in the file selection dialog of Acronis program. Therefore, I cannot add it to the exclusion list.
This is somehow strange to me. I am sure, that before doing the backup replacement, the file "dasHost.exe" was listed in the Acronis file list to select the exclusions.

Do you have any idea how to make the file "dasHost.exe" visible in the Acronis exclusion file list, again? And thus, add it to the exclusions...

Generally, I use Acronis Protection and Bitdefender on several Windows 10 Clients - so far without any problems. Somehow it seems, the one effected PC got an update or a software which causes this interference.

Thank you in advance.

Can we clarify a point here please?

What edition of ATI 2021 do you have?  Is it a subscription edition with Acronis Cyber Protection enabled, or is it either the perpetual 'Standard' or subscription 'Essential' edition where only Active Protection is provided unless you take either a 30-day trial of Cyber Protection or commit to a subscription for the same?

If you only have AAP without Cyber Protection then I would suggest opening the Protection Settings panels and try turning off the Vulnerability scan to see if that is where this report is coming from?

If you have both Cyber Protection and BitDefender active on the system, then this is neither recommended or supported.  Cyber Protection also uses a version of BitDefender under the covers, and having two different versions of antivirus active can cause many problems and conflicts!

Notwix,

Have no idea if this will help you or not but am passing it along to you anyway. 

Look Here

If you find this file to appear safe then I recommend you open a support case on this issue.

Hi Steve,

I am using ATI for several years. My current license is in German: “True Image 2021 Standard 5 PC/MAC, Dauerlizenz – ESD”. I assume it is equivalent to perpetual 'Standard'. It is not a subscription edition. Active Protection is on, but not the advanced protection (Acronis Cyber Protection), see pictures 1 and 2.

A current scan with ESET (Thank to Enchantech for the hint) revealed again no malware match.

Thus, I deactivated the Active Protection manually, and so far, no further detection by the Acronis Agent was mentioned after reboot oder during runtime.

Summarizing your statements, I will let Active Protection be deactivated in future on this PC.
I am just wondering, how suddenly such potential malware detections could happen – after several years with the same combination with Acronis and Bitdefender. Maybe a windows or other software update caused this change.
My other PCs with both Acronis and Bitdefender are still inconspicuous. But I will watching them carefully…

Anhang Größe
596590-305312.JPG 12 KB
596590-305313.JPG 22.78 KB