Author Topic: MRT.exe (Malicious Software Removal Tool)  (Read 9137 times)

0 Members and 1 Guest are viewing this topic.

Offline wallofasgard

  • Jr. Member
  • **
  • Posts: 27
MRT.exe (Malicious Software Removal Tool)
« on: December 03, 2014, 11:38:05 AM »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31074
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #1 on: December 03, 2014, 11:43:59 AM »
File size: 4.26 KB
Do you really think a application that small can remove malware?

Offline wallofasgard

  • Jr. Member
  • **
  • Posts: 27
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #2 on: December 03, 2014, 11:59:54 AM »
So i deleted it.I thought it was a downloader or the like.

thank for clarifying. :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37670
  • F-Secure user
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #3 on: December 03, 2014, 12:01:19 PM »
Test suspicious files at www.virustotal.com / www.metascan-online.com

Offline wallofasgard

  • Jr. Member
  • **
  • Posts: 27
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #4 on: December 03, 2014, 12:21:00 PM »
Thanks. I trust AVAST enough...if i need a file,i'll just have to exclude it.And if i dont need it i just have to delete it after doing some research about the origin of a specific file. :)

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #5 on: December 03, 2014, 12:36:57 PM »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37670
  • F-Secure user
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #6 on: December 03, 2014, 12:52:32 PM »
Quote
Copyright

© Microsoft Corporation. All rights reserved.


Publisher Microsoft Corporation

Product Microsoft Windows Malicious Software Removal Tool

Original name mrt.exe

Internal name mrt.exe

File version 5.13.10300.0

Description Microsoft Windows Malicious Software Removal Tool

First submission 2014-08-03 08:03:49 UTC ( 4 months ago )


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #7 on: December 03, 2014, 01:37:49 PM »
What has me concerned Pondus, Is how small that is.
A google search quickly turns out that the actual download SHOULD be 30 MB.

http://www.microsoft.com/en-us/download/malicious-software-removal-tool-details.aspx
One, can fake a signature...

Edit: When I return into a less, hostile envirroment where I won't get yelled at for this. I will test out this MRT file inside a V irtual Machine :-)
« Last Edit: December 03, 2014, 01:40:20 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31074
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #8 on: December 03, 2014, 03:54:51 PM »
Another indication is the location.
Why downloading it from mediafire while you can from MS?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37670
  • F-Secure user
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #9 on: December 03, 2014, 04:19:35 PM »
Another indication is the location.
Why downloading it from mediafire while you can from MS?
maybe it was  @wallofasgard  that uploaded it to mediafire for us to check it?
« Last Edit: December 03, 2014, 04:39:50 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37670
  • F-Secure user
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #10 on: December 03, 2014, 04:20:35 PM »
What has me concerned Pondus, Is how small that is.
A google search quickly turns out that the actual download SHOULD be 30 MB.

http://www.microsoft.com/en-us/download/malicious-software-removal-tool-details.aspx
One, can fake a signature...

Edit: When I return into a less, hostile envirroment where I won't get yelled at for this. I will test out this MRT file inside a V irtual Machine :-)

file is 4 months old .... and avast have now removed detection
https://www.virustotal.com/nb/file/bba92ab706c22914da3222720c35f9e8bc165c03991b0375ee6890906debafb4/analysis/1417619824/


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #11 on: December 03, 2014, 05:31:06 PM »
Another indication is the location.
Why downloading it from mediafire while you can from MS?
maybe it was  @wallofasgard  that uploaded it to mediafire for us to check it?

Presumably...

What has me concerned Pondus, Is how small that is.
A google search quickly turns out that the actual download SHOULD be 30 MB.

http://www.microsoft.com/en-us/download/malicious-software-removal-tool-details.aspx
One, can fake a signature...

Edit: When I return into a less, hostile envirroment where I won't get yelled at for this. I will test out this MRT file inside a V irtual Machine :-)

file is 4 months old .... and avast have now removed detection
https://www.virustotal.com/nb/file/bba92ab706c22914da3222720c35f9e8bc165c03991b0375ee6890906debafb4/analysis/1417619824/
ermmm... that's annoying

Edit: Why would Avast! remove the detection of (Presumably, malware) that's making an Obvious attempt to hide itself using a M$ signature?
« Last Edit: December 03, 2014, 05:59:28 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37670
  • F-Secure user
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #12 on: December 03, 2014, 10:49:30 PM »
Quote
  Edit: Why would Avast! remove the detection of (Presumably, malware) that's making an Obvious attempt to hide itself using a M$ signature?
@Michael    Message to you from Avira lab




Quote
  Dear Sir or Madam,

Thank you for your email to Avira's virus lab.
Tracking number: INC01780449.

A listing of files alongside their results can be found below:

File ID   Filename   Size (Byte)   Result
28343717   mrt.exe   7.5 KB   CLEAN

Please find a detailed report concerning each individual sample below:

Filename   Result
mrt.exe   CLEAN

The file 'mrt.exe' has been determined to be 'CLEAN'. Our analysts did not discover any malicious content.   


Norman/BlueCoat
Quote
This file does not have any malicious content.
Thanks for submission.



« Last Edit: December 04, 2014, 08:00:49 AM by Pondus »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: MRT.exe (Malicious Software Removal Tool)
« Reply #13 on: December 04, 2014, 01:23:53 PM »
Wtf?

Seriously? That's ever so slightly irritating!!! It's a FAKE! GR! Unfortunately, I'm grounded from computers (No, they don't know I'm on Avast! right now).

I shall Test on Saturday!!
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.