Skip to content

OwlyShield detect taskhostw.exe or svchost.exe like Ransomware activity during Windows Update execution #57

@mostonet

Description

@mostonet

Type: BUG/False positive
Tested on: Windows 10, Server 2016, Windows 11
Workaround: Exclusion in exclusions.txt

Dear OwlyShield Team
I would like to inform you of the problem in question.
How is it possible to whitelist the two files: taskhostw.exe and svchost.exe inside the exclusions.txt file
With what syntax should the TXT file be compiled?
Can you post a concrete example while waiting for a resolution to the problem?
A thousand thanks.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions