Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'Malwarebytes' Anti-Malware' = '%ProgramFiles(x86)%\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent'
- %TEMP%\7zipsfx.000\mbam-setup-1.51.1.1800.exe
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-sisc2.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-d6lp6.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-9e028.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-m62r4.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-l0jro.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-u2mct.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-6srh6.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-q07d3.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jt2lh.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-oqvvf.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-lqtft.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-fs3v1.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-oha5n.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jvu03.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-8i6kk.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-mc7bq.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-tdp91.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\unins000.msg
- %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-airua.tmp
- C:\users\public\desktop\malwarebytes' anti-malware.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\malwarebytes' anti-malware\uninstall malwarebytes' anti-malware.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\malwarebytes' anti-malware\malwarebytes' anti-malware help.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\malwarebytes' anti-malware\malwarebytes' anti-malware.lnk
- %WINDIR%\syswow64\drivers\is-g2d9h.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-enpj4.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-tnelm.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-csore.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-00uae.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-47lhg.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-re24c.tmp
- %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-ddhe6.tmp
- %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-8n8l6.tmp
- %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-9seel.tmp
- %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-dtbm0.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-qmn26.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-n1ogq.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-uhesi.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-qih32.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-ra75a.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-d0psa.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamext.dll
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-gcemv.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-9jbno.tmp
- <DRIVERS>\mbam.sys
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-1fsj5.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-67mat.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-8p8j9.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-or9e1.tmp
- %TEMP%\is-mgb91.tmp\mbam.dll
- %TEMP%\is-mgb91.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-mgb91.tmp\_isetup\_setup64.tmp
- %TEMP%\is-mgb91.tmp\_isetup\_regdll.tmp
- %TEMP%\is-ltp8n.tmp\mbam-setup-1.51.1.1800.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-61spi.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\is-bl77n.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-07npk.tmp
- %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\is-fdh98.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-tkorp.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-voqe9.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-212ck.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jq3t4.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-1s553.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-retj4.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-ndar0.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-fh21d.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-1a5bb.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-b5i7c.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-q6vse.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-9dvcm.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-8mqfq.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-lvtb9.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jfk47.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-kcsi2.tmp
- %ProgramFiles(x86)%\malwarebytes' anti-malware\unins000.dat
- %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam-ssdt-32.sys
- %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam-filter-32.sys
- %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam-filter-64.sys
- %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamext-32.dll
- %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamext-64.dll
- %TEMP%\is-mgb91.tmp\mbam.dll
- %TEMP%\is-mgb91.tmp\_isetup\_regdll.tmp
- %TEMP%\is-mgb91.tmp\_isetup\_setup64.tmp
- %TEMP%\is-mgb91.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-ltp8n.tmp\mbam-setup-1.51.1.1800.tmp
- %TEMP%\7zipsfx.000\mbam-setup-1.51.1.1800.exe
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-or9e1.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\unins000.exe
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jvu03.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\korean.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-oha5n.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\latvian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-fs3v1.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\lithuanian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-lqtft.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\macedonian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-oqvvf.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\norwegian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jt2lh.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\polish.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-q07d3.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\portuguesebr.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-6srh6.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\portuguesept.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-u2mct.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\romanian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-l0jro.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\russian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-m62r4.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\serbian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-9e028.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\slovak.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-d6lp6.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\slovenian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-sisc2.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\spanish.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-mc7bq.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\swedish.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-n1ogq.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\turkish.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-tdp91.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\vietnamese.lng
- from %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-airua.tmp to %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\config.conf
- from %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-dtbm0.tmp to %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\build.conf
- from %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-9seel.tmp to %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\custom.conf
- from %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-8n8l6.tmp to %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\news.conf
- from %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\is-ddhe6.tmp to %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\configuration\local.conf
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-re24c.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam.dll
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-47lhg.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamcore.dll
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-00uae.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamnet.dll
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-csore.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\ssubtmr6.dll
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-tnelm.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\vbalsgrid6.ocx
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-8i6kk.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\italian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-enpj4.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamservice.exe
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-qmn26.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\hungarian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-kcsi2.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\greek.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-8p8j9.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam-ssdt-32.sys
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-67mat.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam-filter-32.sys
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-1fsj5.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam-filter-64.sys
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-9jbno.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamext-32.dll
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-gcemv.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamext-64.dll
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-d0psa.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam.exe
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-ra75a.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbamgui.exe
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-61spi.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\mbam.chm
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-qih32.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\license.txt
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\is-bl77n.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\changes.rtf
- from %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\is-fdh98.tmp to %ALLUSERSPROFILE%\malwarebytes\malwarebytes' anti-malware\rules.ref
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jfk47.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\arabic.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-lvtb9.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\belarusian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-8mqfq.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\bosnian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-9dvcm.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\bulgarian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-q6vse.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\catalan.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-b5i7c.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\chinesesi.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-1a5bb.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\chinesetr.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-fh21d.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\croatian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-ndar0.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\czech.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-retj4.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\danish.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-1s553.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\dutch.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-jq3t4.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\english.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-212ck.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\estonian.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-voqe9.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\finnish.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-tkorp.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\french.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-07npk.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\german.lng
- from %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\is-uhesi.tmp to %ProgramFiles(x86)%\malwarebytes' anti-malware\languages\hebrew.lng
- from %WINDIR%\syswow64\drivers\is-g2d9h.tmp to %WINDIR%\syswow64\drivers\mbamswissarmy.sys
- '%TEMP%\7zipsfx.000\mbam-setup-1.51.1.1800.exe' /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
- '%TEMP%\is-ltp8n.tmp\mbam-setup-1.51.1.1800.tmp' /SL5="$B0188,9074506,54272,%TEMP%\7ZipSfx.000\mbam-setup-1.51.1.1800.exe" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
- '%ProgramFiles(x86)%\malwarebytes' anti-malware\mbamgui.exe' /uninstall
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Malwarebytes' Anti-Malware\mbamext.dll"' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Malwarebytes' Anti-Malware\mbamext.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\Malwarebytes' Anti-Malware\mbamext.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Malwarebytes' Anti-Malware\ssubtmr6.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Malwarebytes' Anti-Malware\vbalsgrid6.ocx"