Microsoft Releases Malicious Software Removal Tool
DaHat writes "Hot on the heels of their release last week of Microsoft AntiSpyware, Microsoft today released their very own Malicious Software Removal Tool with the claim that it will detect and remove infections from specific pieces of malware, including those in the families of Berbew, Doomjuice, Gaobot, Msblast, Mydoom, Nachi, Sassier, and Zindos from your Windows 2000, XP or 2003 machine. Microsoft also promises to release an updated version of the tool on the second Tuesday of each month."
I have rebooted. My initial impression is that there is no immediately obvious way to run the removal program. KB890830 points out the web version of the Malicious Software Removal Tool and says that "When you download the tool from Windows Update or from Automatic Updates, the tool always runs in quiet mode." The KB also has a url to download the tool. Whee.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
If you don't want to use IE/ActiveX, you can download the tool directly from http://www.microsoft.com/downloads/details.aspx?F
This tool reports to MS when it cleans. The reporting is anonymous, it says in the EULA.
T \DontReportInfectionInformation as a DWORD, and set the value to 1.
Those of you who detest automatic vendor notifications can disable this function. I just followed a tortuous string of buried references from MS to find out how, so to save you all the hassle, here's the thing:
Using regedit, create registry key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MR