iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
mshta.exe is the Windows executable for Microsoft HTML Application Host. It opens .hta files—HTML-based applications that can run Windows scripting and access local system resources. That makes it useful for some older tools, but also attractive to malware.
The correct fix depends on what is failing: a stuck process, a damaged Windows file, a broken .hta association, or a legitimate mshta.exe being used to launch a malicious script. Do not start by deleting the file. First check its location, command line, parent process, and digital signature.
What is mshta.exe?
mshta.exe is a legitimate Microsoft component that runs Microsoft HTML Applications. Unlike an ordinary web page opened in a browser, an HTA can execute Windows scripting and interact with files and other local resources.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →On a 64-bit Windows installation, normal copies are usually found in:
#1 Best Overall
C:WindowsSystem32mshta.exeC:WindowsSysWOW64mshta.exe
A copy in Downloads, %AppData%, %Temp%, or another user-writable folder is not the normal Windows component and should be investigated. However, the path alone does not prove that an instance is safe: malware can use the genuine Microsoft executable to run a malicious HTA or script.
1. Check the process location and command line
Use Task Manager to identify which file is running and what it was asked to open.
- Press Ctrl+Shift+Esc.
- Select More details if Task Manager is in its compact view.
- Open Processes or Details, then locate
mshta.exeor Microsoft HTML Application Host. - Right-click it and select Open file location.
In the Details tab, expose the command line:
- Right-click a column heading.
- Select Select columns.
- Enable Command line, then select OK.
Review the command line and, where possible, the process that launched it. These are important because a genuine file in System32 can still be executing something dangerous.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Pay particular attention to command lines containing:
- A remote URL
- A file under a temporary or user-writable directory
javascript:orvbscript:- Long encoded or obfuscated script content
- PowerShell, Windows Script Host, or another unusual parent process
2. Verify the digital signature
For a copy in the normal Windows directory, verify that Windows recognizes its publisher:
- Right-click
mshta.exein File Explorer and select Properties. - Open Digital Signatures.
- Select the listed signature and choose Details.
- Check that the signature status says the digital signature is valid.
An invalid signature, an unexpected publisher, or a file outside the Windows directories is a reason to treat the executable as suspicious. Do not replace it with an executable downloaded from a random website.
3. End a stuck or high-CPU mshta.exe process
If the process is frozen, consuming excessive CPU, or displaying an unwanted HTA window, terminate the current instance:
- Open Task Manager with Ctrl+Shift+Esc.
- Select
mshta.exeor Microsoft HTML Application Host. - Select End task.
This only stops the current process. If mshta.exe immediately returns, something is launching it again. Check startup entries, scheduled tasks, the parent process shown in diagnostic tools, and possible malware persistence instead of repeatedly ending the task.
4. Scan Windows with Microsoft Defender
An unexpected Defender alert involving mshta.exe does not necessarily mean that the Microsoft executable itself is infected. It may be a legitimate binary being abused to run a malicious HTA. Scan the computer and investigate the command that triggered the alert.
Run a full scan in Windows 11
- Open Settings.
- Go to Privacy & security > Windows Security.
- Select Virus & threat protection.
- Select Scan options.
- Choose Full scan, then select Scan now.
Run Microsoft Defender Offline
Use an offline scan if the process returns after removal attempts or you suspect persistence:
- Open Windows Security.
- Select Virus & threat protection > Scan options.
- Choose Microsoft Defender Antivirus (offline scan).
- Select Scan now.
Windows restarts and scans before the normal Windows session fully loads, which can make it harder for persistent malware to interfere with the scan.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
5. Inspect startup entries and scheduled tasks
Startup apps
In Windows 11, open Settings > Apps > Startup. Turn off an unfamiliar entry that launches mshta.exe, an HTA file, or a script from %AppData% or %Temp%. You can also use Task Manager > Startup apps.
Rank #3
Check the per-user Startup folder by pressing Windows+R, entering:
shell:startup
Inspect shortcuts for suspicious targets. Also check the all-users Startup folder:
shell:common startup
Do not remove an entry solely because it uses an HTA. Confirm what program installed it and where its target points.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsScheduled tasks
- Press Windows+R, enter
taskschd.msc, and press Enter. - Open Task Scheduler Library.
- Select suspicious tasks and inspect the Actions tab.
Look for actions that invoke mshta.exe, an .hta file, PowerShell, Windows Script Host, or a file in a user-writable directory. To test a task safely, right-click it and select Disable rather than deleting it immediately. Restart Windows. If the behavior stops, return to Task Scheduler and delete the confirmed malicious task.
6. Repair Windows files with DISM and SFC
Use the following sequence for missing-file errors, crashes, or suspected Windows component corruption. Open Terminal (Admin) or Windows PowerShell (Admin) from the Start menu, then run:
DISM /Online /Cleanup-Image /RestoreHealth
Wait for it to finish. Then run:
sfc /scannow
DISM repairs the Windows component store that SFC uses as a source. Running SFC first can leave it unable to repair files if that source is damaged, so keep the order shown above. Restart Windows after the scans complete and test the application again.
Rank #4
7. Repair the .hta file association
If HTA files no longer open, or they open with the wrong program, check the association from Command Prompt:
assoc .hta
A typical result is:
.hta=htafile
Then check the command associated with that file type:
ftype htafile
A typical result points to:
htafile="%SystemRoot%System32mshta.exe" "%1" %*
If the values are wrong, open an elevated Command Prompt and run:
assoc .hta=htafile
ftype htafile="%SystemRoot%System32mshta.exe" "%1" %*
If the association changes back after repair, another program, malware, or management policy may be modifying it. Treat that as an investigation clue rather than repeatedly resetting the association.
8. Restrict mshta.exe without deleting it
Do not delete C:WindowsSystem32mshta.exe or C:WindowsSysWOW64mshta.exe. Removing a protected Windows component can break legacy applications, servicing, or system repair, and Windows may restore it.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →On managed Windows editions, application control is the safer administrative approach. AppLocker supports Windows 10, Windows 11, and supported Windows Server releases. To open its policy console, run:
Best Value
secpol.msc
Then open Application Control Policies > AppLocker > Executable Rules and create an appropriate policy.
Use Audit only first. It allows execution while recording affected binaries, so you can identify older printer utilities, enterprise tools, installers, or internal applications that depend on HTA interfaces. Switch to Enforce rules only after testing. AppLocker executable rules apply to portable executable files based on their PE format, not simply the filename extension, so renaming an executable is not a dependable bypass.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which fix should you use?
| Symptom | Best first action |
|---|---|
| One instance is frozen or using high CPU | End the task, then investigate what relaunches it. |
| The file is outside System32 or SysWOW64 | Check its signature, command line, parent process, and run a Defender scan. |
| It returns after being ended | Inspect Startup folders, Startup apps, scheduled tasks, and persistence. |
| Windows reports a missing or damaged file | Run DISM first, followed by sfc /scannow. |
| HTA files open incorrectly | Check and repair assoc and ftype. |
| You want to prevent HTA execution across an organization | Test an AppLocker policy in Audit only, then enforce it if compatible. |
Windows 10 note
Windows 10 reached end of support on October 14, 2025. Normal free Windows Update software updates, technical assistance, and security fixes are no longer provided after that date. If this problem occurs on Windows 10, moving to a supported operating system is part of the security remedy; it does not, however, change the need to investigate a suspicious HTA launch.
FAQ
Is mshta.exe a virus?
No. It is a legitimate Microsoft HTML Application Host executable. Malware can abuse the genuine file, so check its location, digital signature, command line, parent process, and the HTA or script it launches.
Can I delete mshta.exe?
No. Do not delete the copies in System32 or SysWOW64. Deleting a Windows component can break older software and system repair. Use Defender and, where appropriate, application-control policies such as AppLocker.
Why does mshta.exe come back after I end it?
A startup item, Startup-folder shortcut, scheduled task, parent process, or malware persistence mechanism may be relaunching it. Inspect those locations and run a full or offline Microsoft Defender scan.
How do I stop HTA files from opening?
For managed computers, test an AppLocker executable policy in Audit only and then enforce it if no required software breaks. Do not delete mshta.exe as a workaround.
Recommended Free Tools
What should the .hta association be?
Typically, assoc .hta returns .hta=htafile, and ftype htafile points to %SystemRoot%System32mshta.exe with the selected file as an argument.
The Bottom Line
mshta.exe is not automatically malware, but an unexpected launch deserves inspection. Confirm the path and signature, expose the command line, identify what launched the process, scan with Microsoft Defender, and check startup persistence if it returns. Repair Windows with DISM and SFC for corruption symptoms, repair the HTA association for file-opening problems, and use AppLocker rather than deleting the Windows executable when execution must be restricted.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

