Multiple Mshta.exe Processes Running in Task Mnager, What Are They??

Started by Ricamundo, September 15, 2010, 08:51:33 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Ricamundo

Thanks Art. I did try it and its still reproducing. :( Oh well back to the drawing board.
Are you listening to the wind now? Tell the wind to bring me some beer. F*ck the beer, we need women!

Art Blade

[titlebar]Vision without action is a daydream. Action without vision is a nightmare.[/titlebar]What doesn't kill us, makes us weirder.

PZ

That's not a bad idea - delete mshta.exe and then see what error pops up when your system tries to run the hta files.  Of course, you'd want to keep a backup copy so you can put it back into it's original folder after the test.  The error will probably be something along the lines of not being able to run an hta file, but you might get an idea what program is trying to run those files to see what you might inactivate/uninstall.  You can always add the mshta.exe back again.

Ricamundo

I did take out the mshta.exe from my windows/system32 folder, and put it, and my original(renamed xx.bak) in a folder on my desktop. I rebooted and sure enough, a little while later, they started to re apppear 1 by 1. ::)
Are you listening to the wind now? Tell the wind to bring me some beer. F*ck the beer, we need women!

JRD

Quote from: Ricamundo on October 19, 2010, 03:59:16 AM
I rebooted and sure enough, a little while later, they started to re apppear 1 by 1. ::)

In that case someone is feeding them after midnight or getting them wet... in any case, you better run!  ;D ;D ;D
Artificial Intelligence is no match for Natural Stupidity

Art Blade

 ??? :o

Now if you deleted (renamed and moved) your original mshta.exe but still got to see it reappear, it cannot be the same mshta.exe. It has to be something else which pretends to be that file. Try to find out where it is located.. check processes etc..

that sounds alarming to me.
[titlebar]Vision without action is a daydream. Action without vision is a nightmare.[/titlebar]What doesn't kill us, makes us weirder.

Dweller_Benthos

Yes, if it's automatically reappearing by itself with no complaints from the OS, then it's a trojan or something loaded in memory that is recreating the file for it's own nefarious purposes. You definitely have a critter running around.
"You've read it, you can't un-read it."
D_B

Ricamundo

Guys, i think i've cracked it. ;D I had looked at the schedualed task folder before, and noticed a large number of tasks that didnt seem to do anything. There were almost 100 of them all identical, named simply "At1" to At95" or so. They were schedualed to start up 7 days a week, but each had thier own specific time to run.

This time, i actually right clicked on one and went to its properties. And there, greyed out but still visible in the name was "mshta.exe" followed by a weird url like "oiebu.com" or something. I simply started deleting them, and once i had cleared everything out, i rebbooted, and ran all my ant virus, and anti malware programs.

That was yesterday, and to my relief, no more mshta's. 8)
Are you listening to the wind now? Tell the wind to bring me some beer. F*ck the beer, we need women!

Art Blade

Well done :) Let's just hope that whatever caused those entries isn't on board any more.

Since you had had deleted the original mshta.exe, did you find out where that mshta.exe was located? You should delete that version. And, using windows firewall or whatever you use, block that url so it can't reload anything.
[titlebar]Vision without action is a daydream. Action without vision is a nightmare.[/titlebar]What doesn't kill us, makes us weirder.

Tags:
🡱 🡳