Running deep scans with the Windows Malicious Software Removal Tool
The Windows Malicious Software Removal Tool, often shortened to MRT, ships with every supported release of Windows and runs quietly in the background once a month. Most users in Sydney, Melbourne, or Perth only see it flash a brief "scan completed" notification before disappearing again. That background pass is fast but shallow, designed to catch a short list of prevalent families. When a machine behaves oddly — browsers redirecting to scam pages, sluggish startup, or unexpected pop-ups from a bundled freebie — a deeper manual scan becomes worth the effort.
This guide walks through forcing a full MRT pass, reading the report it leaves behind, and pairing the tool with other layers of protection. It also covers where the utility stops being useful, which matters because relying on it alone can leave Australian households and small businesses exposed to ransomware and credential stealers circulating in the local market.
What the Malicious Software Removal Tool really checks
MRT is not a full antivirus engine. It is a Microsoft-built targeted cleaner that looks for a fixed set of threat families — Conficker variants, Blaster, Sasser, Zlob, Mydoom, and roughly sixty others on its monthly update list. The database is refreshed through Windows Update around the second Tuesday of each month, the same cadence as Patch Tuesday advisories distributed by the Australian Cyber Security Centre.
Because the database is narrow, MRT cannot replace a real-time antivirus; it complements one. The strength of a manual deep scan lies in catching dormant infections that an always-on guard may have ignored, particularly rootkit-style components and registry-resident malware. That is also why technicians in Brisbane computer-repair shops frequently run MRT after a standard AV scan as a sanity check before returning a serviced device to its owner.
Where MRT sits beside other Windows security tools
Defender and paid suites offer continuous monitoring and behavioural heuristics, while MRT adds a focused, low-overhead sweep that catches established families without competing for system resources. Used together they create redundancy — a quality that matters when an infection slips past a single engine.
| Capability |
Windows MRT |
Windows Defender |
Typical third-party AV |
| Scan depth |
Curated family list, optional full drive |
Real-time plus on-demand |
Real-time plus on-demand |
| Signature updates |
Monthly via Windows Update |
Hourly cloud signatures |
Several times per day |
| Behaviour monitoring |
None |
Built in |
Built in |
| Rootkit detection |
Limited |
Strong |
Strong |
| Cost with Windows licence |
Free |
Free |
Paid subscription |
For most home users, pairing MRT with Defender is enough to catch the threats that monthly updates flag. Third-party tools earn their subscription cost when behaviour-based detection, browser-level filtering, or ransomware rollback matters more than the simple signature sweep MRT provides.
Forcing a full scan through Task Scheduler
The cleanest way to launch a deep pass is through the built-in scheduler rather than the visible MRT wizard. Open Task Scheduler from the Start menu, expand the tree to Microsoft > Windows > RemovalTools, and double-click the entry labelled MRT_HB. Tick "Run with highest privileges," enable the task, then trigger it manually from the right-hand pane. The job will execute the tool with the /F switch, which forces a full examination of every drive instead of the quick background sweep.
The full pass can take anywhere from twenty minutes on a small SSD to several hours on a multi-terabyte workstation. Let the laptop stay plugged in — a flat battery mid-scan in a regional town like Cairns, where the nearest repair shop might be hours away, can leave the boot sector in an awkward state if power drops. A deep scan can be repeated as often as needed; there is no licence limit and no extra telemetry sent to Microsoft beyond what the operating system already shares.
Running the tool directly from the command line
For users who prefer a more transparent view, the executable can be launched from %SystemRoot%\system32\MRT.exe with flags such as /F (full scan), /Q (quiet, no prompts), and /N (detect only, no removal). Opening an elevated Command Prompt and typing mrt /f /q runs the deep scan without the blue wizard, which is useful for remote-management scripts and for technicians servicing a fleet of devices in Adelaide offices.
Running MRT in elevated mode also lets it scan archived ZIP files, system restore points, and the Recovery partition that ordinary Defender scans sometimes skip. The scan log, stored at %WINDIR%\debug\mrt.log, lists every file inspected, every signature matched, and the action taken. That file is overwritten each time the tool runs, so copy it elsewhere if the result needs to be shared with a support agent or kept for insurance purposes following a business email compromise.
Reading the scan results and acting on them
When MRT finishes, it produces a short summary dialog stating whether infections were found, removed, or require a manual step. Clean results are reported as "No malicious software was detected," and the tool exits. If something is detected, the report names the threat family and the file path, which is far more useful than the vague "threat found" alerts some third-party suites produce.
Users hit by phishing campaigns — a recurring problem in Australia around tax time, when ATO and myGov impersonation emails spike — often discover a residual trojan in the MRT log that their primary antivirus missed. For cases involving suspicious mail attachments such as a fake stydco email virus payload, the log helps confirm the component has been wiped before the system is returned to the user.
Habits, limitations and follow-up after a deep scan
A few habits make a deep MRT scan noticeably more effective and keep a Windows machine healthy between passes.
- Run
wuauclt /detectnow or restart the computer before launching MRT so the latest signature set is loaded.
- Disconnect external USB drives and cloud sync clients during the scan to stop active infections re-entering the system.
- Boot into Safe Mode with Networking if the operating system shows signs of a persistent driver-level compromise.
- Keep System Restore enabled; MRT can roll back certain registry changes only if a restore point exists.
- Export the MRT log to a USB stick before clearing it, particularly on work devices that may later need to be reported under the Notifiable Data Breaches scheme.
- Re-run the deep scan two weeks after any major cleanup to confirm no dormant payload has re-emerged.
- Pair the routine with a password reset for any account accessed on the infected device, since credential theft often accompanies the malware MRT removes.
The tool has clear limits. It does not inspect email archives, browser extensions, or files inside encrypted containers, and it cannot recover data that ransomware has scrambled. Australians affected by the Medusa or Akira strains — both actively targeting local councils and mid-size firms — need a purpose-built decryptor, not MRT. For Mac users, MRT simply does not exist on that platform; those dealing with Safari pop-ups or shady profile installers should consult a dedicated Mac cleanup resource instead. Knowing where the tool ends saves time and stops a frustrating chase down a dead end.