Look, if we’re going to skip the arguing, just ask me nicely and I’ll show you what I mean.
For instance, I grabbed the free version of Malwarebytes, installed it, and checked MSConfig to see if it was set to run at startup. After a quick reboot, sure enough, there it was.
DO THE SAME THING.
Once you’ve confirmed it actually kicks off after a restart, open up Notepad, paste everything below into it, and save the file as removesuper.reg
Windows Registry editor version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes\Malwarebytes]
"ApplicationPath"="C:\\Program Files\\Malwarebytes"
"InstallationTime"=hex:db,07,01,00,05,00,07,00,08, 00,2b,00,3b,00,6d,00
"TIResellerId"=dword:00000000
"TIRetrieved"="no"
"SetupWizardComplete"="yes"
"ApplicationGUID"="{25910D24-747F-4D1B-A876-3D96817A56AD}"
"Registration"=dword:00000000
"Activation"=hex:00,00,00,00,00,00,00,00,00,00,00, 00,00,00,00,00,00
"SubscriptionExpiration"=hex:00,00,00,00,00,00,00, 00,00,00,00,00,00,00,00,00
"LastUpdateVersion"="4, 48, 0, 1000"
"ComponentsVerified"="no"
"TIReferrer"=""
"TITag"=""
"TIExtra"=""
"TIComplete"=""
"ESellerate"="no"
"RenewalDialogShown"="no"
"ScanFirstChancePreventionEnabled"="no"
"ScanFirstChancePreventionScanOnStartup"="no"
"ScanFirstChancePreventionScanOnShutdown"="no"
"ScanFirstChancePreventionScanServices"="no"
"ScanFaultCount"=dword:00000000
"AccountsMigrated"="yes"
"AppDataPath"="C:\\Documents and Settings\\Owner\\Application Data\\Malwarebytes\\Malwarebytes"
[-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes\Malwarebytes\InUseFiles]
[-HKEY_CURRENT_USER\Software\Malwarebytes]
[-HKEY_CURRENT_USER\Software\Malwarebytes\Malwarebytes]
"MachineID"=""
"PreConfigurationComplete"="yes"
"UseXPStyleMenus"="yes"
"ShowSplashScreen"="yes"
"ScanRequired"="no"
"NotifyHomePageChanged"="yes"
"NotifySpywareBlocked"="yes"
"EnableRealTimeProtection"="no"
"CheckForUpdates"="no"
"CheckForUpdatesOnStartup"="no"
"CheckForUpdatesInterval"=dword:00000008
"LastUpdateCheckTime"=hex:db,07,01,00,05,00,07,00, 02,00,2c,00,0b,00,7a,03
"NotifyAdBlockSoundPath"="C:\\Program Files\\Malwarebytes\\detect.wav"
"NotifyPlaySound"="no"
"EventLoggingActive"="no"
"EventLoggingFlags"=dword:00000000
"UseSystemHook"="yes"
"OptionalDisplayItems"=hex:01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01
"ProtectHomePage"="no"
"ProtectHomePageAsked"="yes"
"ProtectedHomePage"="
http://www.google.com/"
"VersionProcessList"=dword:0000185e
"VersionProcessListRelated"=dword:00000fd2
"UNCUpdateServerPath"=""
"LimitedAccess"="no"
"SilentUpdates"="no"
"EnableHotKeys"="yes"
"GetCommandLineFromProcess"="yes"
"TerminationProtection"="yes"
"TerminationProtectionAllowedTrusted"="yes"
"IntegrateWithSecurityCenter"="yes"
"UpgradeToProfessionalCompleted"="no"
"Language"="English (US)"
"ScanScheduleEnabled"="no"
"ScanScheduleRebootIfRequired"="no"
"ScanScheduleShutdownAfterScan"="no"
"ScanScheduleAutomaticallyRemoveItems"="no"
"ScanScheduleHideUserInterface"="no"
"ScanScheduleScanType"=dword:00000000
"ScanPromptedFirstTime"="yes"
"ScanSkipLargeFiles"="yes"
"ScanCleanCookies"="yes"
"ScanShowRemovalWarning"="yes"
"ScanScheduleFrequency"=dword:00000007
"ScanScheduleTime"=hex:00,00,00,00,00,00,00,00,00, 00,00,00,00,00,00,00
"ScanScheduleLastTime"=hex:db,07,01,00,06,00,08,00 ,03,00,2e,00,1c,00,0f,00
"ScanScheduleLastScanTime"=hex:db,07,01,00,05,00,0 7,00,02,00,2c,00,19,00,b9,03
"ScanLastDefinitionUpdateTime"=hex:db,07,01,00,05, 00,07,00,02,00,2b,00,3a,00,\
03,02
"ScanLastDefinitionCheckTime"=hex:db,07,01,00,06,0 0,08,00,03,00,2e,00,1b,00,61,\
02
"ScanLastDefinitionRemindTime"=hex:00,00,00,00,00, 00,00,00,00,00,00,00,00,00,\
00,00
"ScanRemindCheckForDefinitionUpdates"="yes"
"ScanRemindCheckForDefinitionUpdatesDays"=dword:00 000005
"ScanType"=dword:00000001
"ScanMinFileSize"=dword:00400000
"ScanOnlyKnownFileTypes"="yes"
"ScanSkipInternetCache"="yes"
"ScanLimitRecursionDepth"="no"
"ScanIgnoreNonExecutableFiles"="yes"
"ScanIgnoreSystemRestore"="no"
"ScanShowIconInSystemTray"="yes"
"ScanKeepLogs"="yes"
"ScanKeepCleanLogs"="yes"
"ScanLogRealTimeBlockedItems"="yes"
"ScanSelectedDrives"=dword:00000018
"ScanCustomMemory"="yes"
"ScanCustomRegistry"="yes"
"ScanCustomStartup"="yes"
"ScanCustomFolders"="yes"
"ScanCustomCookies"="yes"
"ScanAutoScanType"=dword:00000003
"ScanAutoScanCheckForUpdates"="yes"
"ScanScheduleCheckForUpdates"="yes"
"ScanCloseBrowsers"="no"
"ScanResolveLinks"="yes"
"ScanTerminateMemoryThreats"="no"
"ScanDonationAsked"="no"
"ScanUseKernelFileDirect"="yes"
"ScanUseKernelRegistryDirect"="yes"
"ScanUseDirectDiskAccess"="yes"
"ScanADS"="yes"
"ScanDisplayContextMenu"="yes"
[-HKEY_CURRENT_USER\Software\Malwarebytes\Malwarebytes\CLSIDRestoreList]
[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASCon.1]
@="SASContextMenu Class"
[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASCon.1\CLSID]
@="{CA8ACAFA-5FBB-467B-B348-90DD488DE003}"
[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASConte]
@="SASContextMenu Class"
[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASConte\CLSID]
@="{CA8ACAFA-5FBB-467B-B348-90DD488DE003}"
[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASConte\CurVer]
@="MalwarebytesContextMenuExt.SASCon.1"
Once you've saved it, run the thing and reboot your PC.
When you get back, Malwarebytes will start reinstalling itself. It stays inactive while that process is running.
If we had added the registry keys for the startup, it wouldn't have even launched.
That would’ve been way too much work, so I kept it simple.
There's one little catch left: how to make it run automatically without asking "do you want to do this?" every time you double-click the file. If you put in the effort, you can figure that part out.
If I sketched out every single detail, people would just abuse it.
What you see here doesn't completely wipe Malwarebytes—that's a massive undertaking and wouldn't work everywhere—but it gives the malware enough breathing room to kick in.
Since you're reading this in Notepad, you probably noticed all those options like "scan..." set to "yes".
If you actually wanted to stop Malwarebytes from scanning certain things, you'd have to rebuild everything differently just to swap "yes" for "no".
You also see the "SetupWizardComplete" option; it shows you just how many possibilities are tucked away in there.