Windows Malicious Software Removal Tool (MSRT) KB890830 - June 2026 (v5.142)
The Windows MSRT removes specific prevalent malware from supported Windows versions. Released monthly via Windows Update; June 2026 release is v5.142.

Summary
The Windows Malicious Software Removal Tool (MSRT), distributed as KB890830, is a post-infection malware removal tool that runs on Windows 7 through Windows 11 and several Windows Server releases. Microsoft releases it on a monthly cadence through Windows Update. The June 2026 release is v5.142. It is a security-category update available via Microsoft Support.
Improvements and fixes
- Adds detection and removal coverage for SilverCarbine, first included in the June 2026 (v5.142) release.
- Adds coverage for NexilBreak.B and NexilBreak.BA, both new to the June 2026 (v5.142) release.
- Adds coverage for PygmyHog.A and PygmyHog.B, introduced in the June 2026 (v5.142) release.
- Adds coverage for EchoWiper and GrimWiper.B, both new in the June 2026 (v5.142) release.
- Adds coverage for StoneFlare, RogueClimb, MintStone, SneakyGrunt, FossilBeacon, and FrostTamper, all introduced in the June 2026 (v5.142) release.
- Retains coverage for EggStremeLoader and AridWrangler, which were added in the May 2026 (v5.141) release.
- Retains coverage for MildTailor, also introduced in the May 2026 (v5.141) release.
Known issues
Microsoft lists no known issues for this update at the time of writing.
How to get this update
The simplest way to receive the MSRT is through Automatic Updates or Windows Update, where it is delivered automatically each month. It is also available through Microsoft Update and can be deployed in enterprise environments via Windows Server Update Services (WSUS), Microsoft Systems Management Server (SMS), Microsoft Software Update Services (MSUS), and Microsoft Baseline Security Analyzer (MBSA).
For manual download, both 32-bit (x86) and 64-bit (x64) packages are available from the Microsoft Download Center. The release date for the current version is June 09th, 2026. Note that starting November 2019, the MSRT is SHA-2 signed exclusively, so devices must support SHA-2 to run the tool.
To run the tool, the computer must be running a supported version of Windows, and the user must be logged on with an account that is a member of the Administrators group. If the tool is more than 215 days (7 months) out of date, it will prompt the user to download the latest version.
Frequently asked questions
Is the MSRT a replacement for antivirus software?
No. The MSRT is strictly a post-infection removal tool and does not replace an antivirus product. It only removes specific prevalent malware families and focuses on threats that are actively running on the computer. Microsoft strongly recommends running an up-to-date antivirus product alongside the MSRT for comprehensive protection.
What happens when the MSRT detects malware on a managed machine?
The tool runs in quiet mode by default. If it finds malware, a notification balloon appears in the system tray the next time an administrator logs on. Administrators can then initiate a full scan, which performs a quick scan followed by a full scan of all fixed and removable drives. Mapped network drives are not scanned during this process.
Does the MSRT send data back to Microsoft?
Yes, but only basic telemetry. If the tool detects malware or encounters an error, it sends minimal information to Microsoft for virus-prevalence tracking. According to Microsoft, no personally identifiable information about the user or the computer is included in this report.
What command-line switches does the MSRT support for enterprise deployments?
The MSRT supports several switches: /Q or /quiet suppresses the user interface; /N runs in detect-only mode without removing anything; /F forces an extended scan; /F:Y forces an extended scan and automatically cleans infections; and /? displays the full list of available switches. These options are useful for scripted or silent enterprise deployments via WSUS or SMS.



