mrt.exe

Microsoft Windows Malicious Software Removal Tool

Microsoft Corporation

MRT is an anti-malware utility that checks a PC for infection by specific, prevalent malicious software and helps to remove the infection if it is found. The version of the tool delivered by Microsoft Update and Windows Update runs in the background and then reports if a malware infection is found. Microsoft will release an updated version of this tool on the second Tuesday of each month.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Windows Malicious Software Removal Tool

Version:
4.7.6100.0

MD5:
f752025bbe7f4fa5fb5652468e7b8506

SHA-1:
d9cd65e9b8cd2a92e638328dc63f8875cad7c969

SHA-256:
b6d334cb5ecb44bb221a77965bdf8816ca8d0e17e56480c5c1a1ea1860975a76

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
3/5/2026 11:54:30 AM UTC  (today)

File size:
52.6 MB (55,154,568 bytes)

Product version:
4.7.6100.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
mrt.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\mrt.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
2/15/2011 5:11:44 AM

Valid to:
5/15/2012 5:11:44 AM

Subject:
CN=Microsoft Windows, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Verification PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
61030556000000000010

File PE Metadata
Compilation timestamp:
3/29/2012 5:46:29 PM

OS version:
6.2

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
1572864:vNLfDn8Ghu5q/w/9/z5xx5x85xp5xN/+/L5x95xe5xF5xwg7/JPTn:l8Gh8q/w/9/z5xx5x85xp5xN/+/L5x9w

Entry address:
0x2B2CF

Entry point:
E8, 4D, 0A, 00, 00, E9, 0B, FE, FF, FF, CC, CC, CC, CC, CC, FF, 25, EC, 14, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, E8, 14, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, E0, 14, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, DC, 14, 40, 00, CC, CC, CC, CC, CC, CC, FF, 25, D8, 14, 40, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 5D, E9, 05, 00, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, D0, 02, 00, 00, A1, 00, 40, 44, 00, 33, C5, 89, 45, FC, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF...
 
[+]

Entropy:
6.6893

Code size:
263 KB (269,312 bytes)