Process Ancestry Validation
Is this process ancestry legitimate for TeamViewer?
Process Ancestry: wininit.exe -> services.exe -> TeamViewer_Service.exe -> TeamViewer.exe-> mshta.exe
Thanks!
Best Answer
-
Hello @SecurityGiraffe,
Thank you for your message. ?
Yes, this is a false positive and a safe file. ?
HTA is an (old) HTML-based application technology supported only by Internet Explorer
– https://en.wikipedia.org/wiki/HTML_ApplicationThe behaviour might seem suspicious to the antivirus because the TeamViewer executable generates a temporary .hta file and launches it with the Windows built-in mshta.exe runner, which runs it as a trusted application.
I hope this could help. ?
Best regards
Jean
Community Manager
6
Answers
-
Hello @SecurityGiraffe,
Thank you for your message. ?
Yes, this is a false positive and a safe file. ?
HTA is an (old) HTML-based application technology supported only by Internet Explorer
– https://en.wikipedia.org/wiki/HTML_ApplicationThe behaviour might seem suspicious to the antivirus because the TeamViewer executable generates a temporary .hta file and launches it with the Windows built-in mshta.exe runner, which runs it as a trusted application.
I hope this could help. ?
Best regards
Jean
Community Manager
6 -
That's very helpful, thank you so much!
1 -
@SecurityGiraffe very glad we could help! ?
Hope to see you soon posting in the Community. ?
Best regards
Jean
Community Manager
0