All Discussions > Steam Forums > Off Topic > Topic Details
Noah Jul 15, 2017 @ 10:24pm
I seek Help! Mshta.exe virus.
Ive been getting this windows 7 style update popup when i have windows 10. when i trace it back through task manger to the file location it leads me to this file. link for screenshot. Ive also ran windows defender and malware bytes and nothing is found. Ive even scanned this file alone on both.

https://gyazo.com/3a44699aca5027d4f4df4154b3869bde
< >
Showing 1-15 of 15 comments
start fresh, clean install windows 10?
install all windows updates and reboot.
install all motherboard chipset drivers and reboot.
install antivirus/antimalware/antispyware, update, and reboot.
Run your virus and malware scanner in safe mode, where they actually work.
Noah Jul 15, 2017 @ 10:29pm 
Originally posted by chiefputsi✖✖✖:
start fresh, clean install windows 10?
install all windows updates and reboot.
install all motherboard chipset drivers and reboot.
install antivirus/antimalware/antispyware, update, and reboot.

This makes me sad. i have over 1tbs of games installed.
DarkCrystalMethod Jul 15, 2017 @ 10:29pm 
Boot from the Norton360 CD/DVD/USBstick that you can make(or any other legit free scan AND REPAIR software that can boot from its own media). Obviously within the operation of your current os lurks the virus which cannot be removed from a running system, not comlpletely anyway. You've chosen (or have been chosen) to get one of the more nasty viruses.
You would want to have it do the deepest scan on each drive which would take hours, but you need to make sure its gone. Avoid booting from your windows disks until you've cleared each one. one at a time is best so something doesn't travel from one bad disk to one you've just cleaned.
-V- Jul 15, 2017 @ 10:30pm 
Buy a decent protection suite. For money.
DarkCrystalMethod Jul 15, 2017 @ 10:34pm 
Oh, and if you're doing a clean install of windows have that driver disk, because most of the time it just won't have the driver for your internet card... and it would need to get online to retrieve that driver.
Have fun.
Last edited by DarkCrystalMethod; Jul 15, 2017 @ 10:34pm
-V- Jul 15, 2017 @ 10:35pm 
Originally posted by Anna Kist:
Download and install Malwarebytes. The paid version is best, but the free version is perfectly adequate. Run a scan using that... It should remove the virus. I run it alongside my main anti-virus software.
Originally posted by Noah:
Ive also ran windows defender and malware bytes and nothing is found. Ive even scanned this file alone on both.
Originally posted by -V-:
Buy a decent protection suite. For money.
Last edited by -V-; Jul 15, 2017 @ 10:35pm
Noah Jul 15, 2017 @ 10:36pm 
Originally posted by Anna Kist:
Download and install Malwarebytes. The paid version is best, but the free version is perfectly adequate. Run a scan using that... It should remove the virus. I run it alongside my main anti-virus software.

i have the paid version
Originally posted by -V-:
Originally posted by Anna Kist:
Download and install Malwarebytes. The paid version is best, but the free version is perfectly adequate. Run a scan using that... It should remove the virus. I run it alongside my main anti-virus software.
Originally posted by Noah:
Ive also ran windows defender and malware bytes and nothing is found. Ive even scanned this file alone on both.
Originally posted by -V-:
Buy a decent protection suite. For money.
And RUN them in safe mode!

DarkCrystalMethod Jul 15, 2017 @ 10:39pm 
Did a legit antivirus program tell you that mshta.exe was a problem? Its a legitimate Windows service: "Microsoft (R) HTML Application host"
While its good to do a comprehensive (everything) scan regularly it just wouldn't be for this unless a trustworthy scanner detected a problem.
Noah Jul 15, 2017 @ 10:43pm 
Originally posted by DarkCrystalMethod:
Did a legit antivirus program tell you that mshta.exe was a problem? Its a legitimate Windows service: "Microsoft (R) HTML Application host"
While its good to do a comprehensive (everything) scan regularly it just wouldn't be for this unless a trustworthy scanner detected a problem.

Its not comming up as a virus at allin malwarebutes pro or windows defender. However i am getting a windows 7 style popup telling me to upgrade or update. when i trase it through taskmanger it takes me to mshta.exe
Fajita Jim Jul 15, 2017 @ 10:51pm 
Look at the Date Modified. It was installed at the same time as most other files on that screenshot. Plus, mshta.exe is an actual MS app. Whatever is causing the popups is using mshta.exe, but the .exe file isn't what's causing it.

I would have to dig into your registry to see what's going on.
DarkCrystalMethod Jul 15, 2017 @ 10:54pm 
Then it seems like someone is playing with you.
The msg command is a way for another computer to send you messages that seem like they're from a system administrator for your office. They might be. If this is a home computer then its someone in your house sending it.

msg %username% "you have a virus in mshta.exe"
This will work if you somehow still have Windows Messaging turned on.
A dialog box would simply appear on your screen with an ok button to acknowledge.
If you got something different then check your Programs/Features list. Also launch the "Windows features" (options) window to turn off the stuff you don't need.
Sin Jul 15, 2017 @ 11:42pm 
Originally posted by Noah:
Originally posted by DarkCrystalMethod:
Did a legit antivirus program tell you that mshta.exe was a problem? Its a legitimate Windows service: "Microsoft (R) HTML Application host"
While its good to do a comprehensive (everything) scan regularly it just wouldn't be for this unless a trustworthy scanner detected a problem.

Its not comming up as a virus at allin malwarebutes pro or windows defender. However i am getting a windows 7 style popup telling me to upgrade or update. when i trase it through taskmanger it takes me to mshta.exe

Still could be a virus and can't knock out the possibility, I've seen nasty Trojans that can also bind themselves to legit processes in windows to leave the user unsuspecting of what's going on "behind the scenes" prime example that I remember is svchost.exe. idk man I'd just hit that nuclear button and call it a day with a fresh format, I wouldn't risk it.
😼Studio Cat😼 Jul 16, 2017 @ 12:47am 
Run av and mal in safe boot then open commañd prompt and run SFC /scannow
Wait.
Pc fixed

< >
Showing 1-15 of 15 comments
Per page: 1530 50

All Discussions > Steam Forums > Off Topic > Topic Details
Date Posted: Jul 15, 2017 @ 10:24pm
Posts: 15