taskhostw.exe on windows 10

Anonymous
2018-06-06T01:01:32+00:00

"Controlled folder access blocks taskhostw.exe from making changes to memory." -- Windows Defender reports this all the time now....what has changed?

Is this a malware or what?

Thanks!

If taskhostw.exe is MALWARE, why doesn't WINDOWS DEFENDER block or remove it?

Windows for home | Windows 10 | Files, folders, and storage

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

DaveM121 902.2K Reputation points Independent Advisor
2018-06-06T07:37:40+00:00

Hi dauds, this is caused by a new feature in Windows - Controlled Folder Access, while this feature will be a great plus in Windows, it is currently very buggy, I would turn off this feature until it matures . . .

Open Windows Defender Security Center

Go to Virus & threat protection - Virus & threat protection settings

Scroll down to Controlled folder access

Toggle that option off

Was this answer helpful?

30+ people found this answer helpful.
0 comments No comments

Answer accepted by question author

Kapil Arya 37,956 Reputation points Volunteer Moderator
2018-06-06T03:39:36+00:00

Hello,

  1. On the taskbar, click on Windows Defender Security Center icon.
  2. Next, in the Windows Defender Security Center window, click on Virus & threat protection tile.
  3. Then click on Ransomware protection on next screen.
  4. Moving on, in Ransomware protection screen, under Controlled folder access section, you can toggle the option to Off to disable this feature.

Let us know if this helps!

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments

26 additional answers

Sort by: Most helpful
  1. Anonymous
    2018-07-28T17:24:41+00:00

    I have now looked around more, and I do see many saying that malware does use the very same name, with the w. But it also gave sized of the correct file and the malware one, and the malware is much larger than the correct file.

    It listed three varying sizes for the correct file:

    •71,792 bytes

    •71,280 bytes

    •71,848 bytes.

    And it said the malware by the same name in a subfolder in Program Files is 1,113,088 bytes. And the malware file by the same name in a subfolder in the user profile folder is 1,3792,328 bytes.

    Mine doesn't match any of those numbers! Mine comes in at:

    •Size: 87,904 bytes

    •Size on disk: 90,112 bytes

    So, since there are so many subfolders on my computer in the specified locations for the malware, I decided to just take the advice and run Malwarebytes -- I got the free, 14-day trial and ran it.

    Malwarbytes did not produce any notice about taskhostw.exe. So, I guess mine cleared that hurdle and is probably the correct one.

    So, I now have what I think is a better approach to stop this notice than fully turning off that function, which is supposed to be designed to avoid ransomware. You do not have to turn it off, you can selectively protect a folder or file, in this case a file. I have done that on my computer now. To do that:

    •Open Windows Defender

    •Go to the "Virus & threat protection" page

         •At bottom of that page, click into "Ransomware protection"

    •On the "Ransomware protection" page, toward the bottom, under "Controlled folder access," select the second option: "Allow an app through controlled folder access"

    •Now navigate to and select the correct taskhostw.exe file at:

    C:\Windows\System32\taskhostw.exe

    Once selected, it will be added to a list of protected files and you should not get that message any more -- and I presume if you do start getting it again, that would be because you then have gotten the real malware file, so good thing you stopped this selectively instead of turning the entire function off!

    (Malwarebytes did find a number of things it questioned and left it to me to decide -- I hate that, how am I supposed to know!  Anyway, I did know one was fine, but the others I could not tell, but the names left me wondering if yes, they are a problem, even though Windows Defender has not identified them as a problem. So, I quarantined them. I restarted, tested a couple applications to see if they would still open after that, but I will just have to await the test of time, I suppose -- but better delete them or restore them  before the 14-day trial end.)

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-07-28T13:52:13+00:00

    Time Lady, I am back to looking into this issue -- I looked into it months ago but got too buried under all the info, did not have a ton of time to get it all figured out -- and if this is malware, as dauds asks, why has Windows Defender in all this time not yet picked up on it and done something? And secondly, if this is a a bug in the new Windows process, then how can Microsoft allow this to keep doing this for the past 10 months without at least addressing this one bug!?

    But I learned something specific to what you just wrote.

    When I previously looked into this, yes, there is a malware out there  -- by a very similar name, not the same name. The correct file is actually named taskhostw.exe -- note the w. The malware file is named taskhost.exe -- note the lack of a w. But there were so many people posting all kinds of things, and contradictory about this of these is the malware, that I never considered it final. I'm not back to try to get the final.

    But the information from everyone posting, and so many postings as if they knew for certain, and a lot of people saying the opposite as if they knew for certain, it would be scary to proceed and do something one way or the other, because this is an actual OS file and deleting it could create troubles for some things, but unblocking it could too.

    I don't know, I'm a bit reluctant to start getting third party anti-malware and let it do what Microsoft does not want to do for some reason -- I don't want that anti-malware to take out a proper file that we should have in the OS, there is probably a very good reason Microsoft Windows Defender is not just getting rid of this file.

    In the end, all the third party anti-malware is going to know is the name of the file and if that in the list of bad files it looks for. If that is all it is, we can delete it manually ourselves. But I am so reluctant to delete, or let a third party software delete, an OS file. We need Microsoft to address this -- and about 10 months ago, much less now!

    If what you have is the malware, the last thing you would want to do first is to turn off this process that is blocking it. If you have the proper file, the last thing you want to do is what some other posts in a search turn up, to delete the file.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  3. Virginia M 41,285 Reputation points Independent Advisor
    2018-06-06T12:04:35+00:00

    Unfortunately while there is a genuine windows file with that name it can also be a virus:

    https://www.bleepingcomputer.com/virus-removal/...

    To double check:

    Try running these programs:

    MBAM: https://www.malwarebytes.com/

    Eset: http://www.eset.com/us/online-scanner/

    Adwcleaner: https://toolslib.net/downloads/viewdownload/1-a...

    If these do not fully remove the virus/malware then it will be wise to register with a malware removal site to receive dedicated malware removal instructions, an expert will remain with you throughout the process until confirmation that your PC is 100% clean.

    Malwarebytes virus/malware removal forum:

    https://forums.malwarebytes.com/forum/7-windows...

    Bleeping computer malware/virus removal forum:

    https://www.bleepingcomputer.com/forums/forum22...

    If all is clear then you can follow Dave M’s excellent advice to allow it to run.

    Disclaimer - This post contains reference to non-Microsoft websites and there may be ads on the page for products & services including products frequently classified as a PUP (Potentially Unwanted Product). Please thoroughly research any product / service advertised on the page before you decide to use them. Your discretion is very much advised.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments