


I just want to bring to your attention two points: 1- Microsoft’s MRT phones home not when run and closed but within an analysis (as far as I can tell).

I never really needed it, so I won’t miss it. An administrator can choose to disable the infection-reporting component of the tool by adding the following registry key value to computers. Option 1: Registry Key The Knowledgebase support article, Deployment of the Microsoft Windows Malicious Software Removal Tool in an enterprise environment, lists a Registry key to block the sending of reports of the MRT to Microsoft. We don't know what is sent to Microsoft as part of Heartbeat other than the information that Microsoft revealed in its privacy statement. Microsoft notes in its that the Malicious Software Removal Tool will sent a report to Microsoft with 'specific data about malware detected, errors, and other data about your device' but fails to go into details. You can verify that in the log as you will find 'Heartbeat Will be Sent in x Days' entries there. Heartbeat Telemetry data is not sent out each day according to the log, but only every five or six days. You may also hit F3 to open the search to jump to the first Heartbeat entry in the log.
