dasHost - potential Ransomware-Code ?
Hello,
Acronis True Image 2021 detects since yesterday a potential ransomware code in the Windows System file "dasHost.exe". It states after every Windows start that 14 files have been changed. These files, however, lie in a System folder which I cannot access, even not as Windows Admin (see screenshot).
I cannot rename the Windows System file "dasHost.exe" to replace it afterwards by an backup file version.
Stopping the process has no effect. Starting Windows again, the message pops up again, but with another 14 files.
A system check with Antivirus Bitdefender and, in addition, a check of the Windows System file "dasHost.exe" on the VirusTotal website was both negative!
Does anybody has a similar detection right now?
Is the behavoir of "dasHost.exe" correct?
What should I do further on?
a) ignore the detection (because the Antivirus checks were negative)
b) replace the file by a backup version (is this possible by Acronis backup even if the file is protected by the system)
c) what else...
Thanks in advance
Attachment | Size |
---|---|
Acronis Ransomware Identifikation.docx | 116.73 KB |


- Log in to post comments

Hi Steve,
thank you for your comment. Indeed, I use Bitdefender, and a full malware screen didn´t detect any suspicious file on my PC.
I replaced the file "dasHost.exe", which was identified by Acronis as root cause, by a version from a previous backup. However, the Acronis agent detects again some obviously suspicious file changes by "dasHost.exe", always immediately after reboot / start of the PC.
The "modified" files are always picture files in the same folder
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\
Checking these files revealed no hint for any malware.
Then I tried to add the file "dasHost.exe", which I can easily find with the windows explorer in "C:\Windows\System32" to the exception list of Acronis Protection. The file is not hidden or something else. However, it is not visible in the file selection dialog of Acronis program. Therefore, I cannot add it to the exclusion list.
This is somehow strange to me. I am sure, that before doing the backup replacement, the file "dasHost.exe" was listed in the Acronis file list to select the exclusions.
Do you have any idea how to make the file "dasHost.exe" visible in the Acronis exclusion file list, again? And thus, add it to the exclusions...
Generally, I use Acronis Protection and Bitdefender on several Windows 10 Clients - so far without any problems. Somehow it seems, the one effected PC got an update or a software which causes this interference.
Thank you in advance.
- Log in to post comments

Can we clarify a point here please?
What edition of ATI 2021 do you have? Is it a subscription edition with Acronis Cyber Protection enabled, or is it either the perpetual 'Standard' or subscription 'Essential' edition where only Active Protection is provided unless you take either a 30-day trial of Cyber Protection or commit to a subscription for the same?
If you only have AAP without Cyber Protection then I would suggest opening the Protection Settings panels and try turning off the Vulnerability scan to see if that is where this report is coming from?
If you have both Cyber Protection and BitDefender active on the system, then this is neither recommended or supported. Cyber Protection also uses a version of BitDefender under the covers, and having two different versions of antivirus active can cause many problems and conflicts!
- Log in to post comments

Notwix,
Have no idea if this will help you or not but am passing it along to you anyway.
If you find this file to appear safe then I recommend you open a support case on this issue.
- Log in to post comments

Hi Steve,
I am using ATI for several years. My current license is in German: “True Image 2021 Standard 5 PC/MAC, Dauerlizenz – ESD”. I assume it is equivalent to perpetual 'Standard'. It is not a subscription edition. Active Protection is on, but not the advanced protection (Acronis Cyber Protection), see pictures 1 and 2.
A current scan with ESET (Thank to Enchantech for the hint) revealed again no malware match.
Thus, I deactivated the Active Protection manually, and so far, no further detection by the Acronis Agent was mentioned after reboot oder during runtime.
Summarizing your statements, I will let Active Protection be deactivated in future on this PC.
I am just wondering, how suddenly such potential malware detections could happen – after several years with the same combination with Acronis and Bitdefender. Maybe a windows or other software update caused this change.
My other PCs with both Acronis and Bitdefender are still inconspicuous. But I will watching them carefully…
Attachment | Size |
---|---|
596590-305312.JPG | 12 KB |
596590-305313.JPG | 22.78 KB |
- Log in to post comments