Download and install Malwarebytes Agentless Remediation

Document created by bdemidov Employee on Dec 10, 2018Last modified by bdemidov Employee on Feb 22, 2019
Version 28Show Document
  • View in full screen mode

Malwarebytes Agentless Remediation is a threat detection and remediation tool built on top of our Malwarebytes Breach Remediation and Forensic Timeliner products. It scans endpoints for advanced threats including malware, PUPs, and adware and thoroughly removes them.


Malwarebytes Agentless Remediation Tool Handbook 




Requirements for MAR Console

  • Purchased license or trial of Malwarebytes Breach Remediation
  • .NET Framework 4.6.1 or later
  • Windows Management Framework (WMF) 5.0 (or later)
  • Domain computer only
  • Windows 10 x64 or Windows Server 2016 x64
  • Domain account with local admin rights on target computers should be provided for encrypted storage on the Jump Server


Requirements for target endpoints

  • Windows 10 (32/64-bit)
  • Windows 8.1 (32/64-bit)
  • Windows 8 (32/64-bit)
  • Windows 7 (32/64-bit) (Service Pack 1 or later)
  • Windows Server 2012/2012 R2 (64-bit only)
  • Windows Small Business Server 2011 (64-bit only)o Windows Server 2008 R2 (64 bit)

Note: Windows servers using the Server Core Installation process are specifically excluded



  1. Download the latest version of Malwarebytes Agentless Remediation app.

  2. Unzip archive and run setup.exe (running the installation with administrative privileges is recommended)

  3. Proceed with installation instructions. You may be asked to continue installation due to failed libraries registration. Ignore these messages and click Continue. Installation and operation of the product are unaffected.

  4. Once the installation completes, open Windows Explorer and navigate to the C:\irstealth folder and run IRStealth.exe with Run as Administrator



  1. Open the app at Settings tab and enter Malwarebytes Breach Remediation license key.
    Image of Malwarebytes Agentless Remediation Settings menu.

  2. Click Activate Products and check if you can see the message Successfully activated products.

  3. Click Update Database and check if you can see the message Successfully updated Breach Remediation Database.

    Note: the UI may be unresponsive during registration and database update operations (up to 10 seconds).

  4. Choose the option for distribution and registration of scanning libraries.
    Image of Malwarebytes Agentless Remediation Settings menu.

  5. Set up credentials for distribution and running Malwarebytes Breach Remediation and Forensic Timeliner scanners on target endpoints.
    Image of Malwarebytes Agentless Remediation Settings menu.


Note: This app has been tested only in domain environments. Use for WORKGROUPS may not work.


Running Scan

  1. Perform all preparation steps from Configuration section of this article.

  2. Provide the list of target endpoints for scan at Endpoints tab. You can import the list of endpoints from Active Directory OU or from a flat file.

  3. Set up scan parameters in the Settings tab. For additional configuration (e.g. SIEM or proxy settings) click on SettingsGo to Advanced Settings.

  4. Choose Complete Scan or Remediation Only type of scan.
    • Complete Scan - both Malwarebytes Breach Remediation and Forensic Timeliner scans.
    • Remediation Only - Malwarebytes Breach Remediation scan only.

  5. You can monitor the scan status under Scan tab.


Scan Results

Once scan is completed you will be able to see the detections in your dashboard.


For more information and exportable format navigate to Detections tab.


You can export the detections by clicking on Export to CSV button. This operation will create a new report in CSV format in the C:\irstealth folder.



This is a user community shared utility. Please send questions, comments, and support request to the authors directly. 


For troubleshooting of the app please attach events in the Log tab.