I have now looked around more, and I do see many saying that malware does use the very same name, with the w. But it also gave sized of the correct file and the malware one, and the malware is much larger than the correct file.
It listed three varying sizes for the correct file:
•71,792 bytes
•71,280 bytes
•71,848 bytes.
And it said the malware by the same name in a subfolder in Program Files is 1,113,088 bytes. And the malware file by the same name in a subfolder in the user profile folder is 1,3792,328 bytes.
Mine doesn't match any of those numbers! Mine comes in at:
•Size: 87,904 bytes
•Size on disk: 90,112 bytes
So, since there are so many subfolders on my computer in the specified locations for the malware, I decided to just take the advice and run Malwarebytes -- I got the free, 14-day trial and ran it.
Malwarbytes did not produce any notice about taskhostw.exe. So, I guess mine cleared that hurdle and is probably the correct one.
So, I now have what I think is a better approach to stop this notice than fully turning off that function, which is supposed to be designed to avoid ransomware. You do not have to turn it off, you can selectively protect a folder or file, in this case a
file. I have done that on my computer now. To do that:
•Open Windows Defender
•Go to the "Virus & threat protection" page
•At bottom of that page, click into "Ransomware protection"
•On the "Ransomware protection" page, toward the bottom, under "Controlled folder access," select the second option: "Allow an app through controlled folder access"
•Now navigate to and select the correct taskhostw.exe file at:
C:\Windows\System32\taskhostw.exe
Once selected, it will be added to a list of protected files and you should not get that message any more -- and I presume if you do start getting it again, that would be because you then have gotten the real malware file, so good thing you stopped this
selectively instead of turning the entire function off!
(Malwarebytes did find a number of things it questioned and left it to me to decide -- I hate that, how am I supposed to know! Anyway, I did know one was fine, but the others I could not tell, but the names left me wondering if yes, they are a problem,
even though Windows Defender has not identified them as a problem. So, I quarantined them. I restarted, tested a couple applications to see if they would still open after that, but I will just have to await the test of time, I suppose -- but better delete
them or restore them before the 14-day trial end.)