slowfox: Slowfox' default icon (Default)
[personal profile] slowfox
Y'know, I've often wondered, whilst watching the Microsoft Updates download to the work PC (for Castle Fox is a Linux domain), what on Earth is that 'Malicious Software Removal Tool' that seems to be a perennial feature?

Well, it turns out, it's a user startable program... indeed, I'm not wholly clear if this thing runs by itself at all.

So, assuming that you've been over to Windows Update, and your machine is fully patched and whatever (caveat: I only have XP, can't speak for Vista), you can then launch the Malicious Software Removal Tool from the 'Run' option off the start menu.

Here's the sneaky bit. You or I, dear reader, might assume that the program would be called something helpful - like, 'MaliciousSoftwareRemovalTool.exe', or MSRT.exe to keep it short. Helpfully, however, MS have dropped the 'S' from the abbreviation, so you need to be thinking gold jewellery, Bad Attitude and souped up GMC minivans: MrT.exe (if I'm allowed to be liberal with capitalisation for the mnemonic advantage):

launching the Malicious Software Removal Tool from the Start Menu

This bothers me slightly - typing 'mrt.exe' in the 'Run' dialogue box will run the first file of that name it comes across within the system's PATH (a definition of which directories Windows will scan when trying to launch a program whose filename hasn't been fully specified {in this case: C:\Windows\System32\mrt.exe}). What's to stop some enterprising malware artist constructing a trojan horse called mrt.exe that either overwrites the MS version, or manages to install itself in a location higher up the PATH hierarchy?).

Anyway, qualms aside (and remember, this is my work PC, so I'm Qualm Free™), this will bring up the Welcome screen:

Check the date in the window's title bar - it should be reasonably current!

The thing to check here is that the date, in the window's title bar up there at the top, is reasonably current. It should be, of course, if Windows Update has been working correctly, but if not, amble over to MS and get your installation up to date.

the Full Scan may take some time

There aren't a whole heap of options to choose from. Despite what the pic shows, I've only run the 'Quick Scan' on the work PC. I'm putting off running the full enchilada for overnight.

There's not a great deal to look at, but the software does it best to let you know it's busy...

MSRT scanning the disk...

Finally, once it's complete, you can click to view a full status report:

a clean bill of health

As you can see, this check is trying to find rather a lot of malware and stuff, and is probably worth running (since you've already got it installed), just for the comfort factor.

ETA: I have now learned that the MSRT is run in quick mode on the reboot after it's installed as part of the Windows Update process. However, the Full Scan is not automatic at all, and can only be user initiated (probably because doing so will take an aaaaaaaaaaaggggggggggeeee</Entish>).

Date: 2009-05-18 02:42 pm (UTC)
cynthia_black: (Default)
From: [personal profile] cynthia_black
Thank you for that, m'dear - I often wondered what the malicious software removal tool was supposed to do!

Date: 2009-05-18 04:19 pm (UTC)
linaelyn: (Default)
From: [personal profile] linaelyn
Though we're Mac-only here at Casa Telcontar-Longshanks, I'm bookmarking this for passing along. I know there are plenty of folks reading my journal(s) who could benefit from this information!

It's only a matter of time before the various Apple platforms face similar viral and wormish assaults on a regular basis. I'm frankly astounded that the iPhone is not under constant barrage of malware, given its broad appeal.

Date: 2009-05-18 08:18 pm (UTC)
ms_katonic: (Malfosoft)
From: [personal profile] ms_katonic
Useful stuff, may give it a go... although I was under the impression that it ran automatically on the first reboot after installation.

ETA: Well, first hurdle is that Vista has no Run option on its menu. :P

But typing mrt into the Search box does bring it up.
Edited Date: 2009-05-18 08:21 pm (UTC)

Date: 2011-09-20 07:22 pm (UTC)
glittertine: (Default)
From: [personal profile] glittertine
<3 I remembered you'd written this years ago and just needed the info. Thanks for tagging properly and making it easy to find things! :)

Profile

slowfox: Slowfox' default icon (Default)
slowfox

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 25th, 2025 07:45 pm
Powered by Dreamwidth Studios