absrdst Posted September 15, 2020 ID:1407778 Share Posted September 15, 2020 Greetings and Good Afternoon - I am conducting a forensic investigation and would like to know if there are logs that record user information at the time mbam is installed on a system? I would like to know what user installed the software and it does not appear to be captured within the standard mbam LOGS directory. Any information would be greatly appreciated. Thank you. Link to post Share on other sites More sharing options...
Porthos Posted September 15, 2020 ID:1407784 Share Posted September 15, 2020 12 minutes ago, absrdst said: I am conducting a forensic investigation and would like to know if there are logs that record user information at the time mbam is installed on a system? I will ask staff member @LiquidTension to provide that info of possible. Link to post Share on other sites More sharing options...
Maurice Naggar Posted September 15, 2020 ID:1407825 Share Posted September 15, 2020 Hello @absrdst One can get the Date & Time of the last Malwarebytes for Windows setup run by going to these 2 locations via Windows File Explorer. They wont have the 'user' mentioned in the logs themselves. However, the 1st one listed below is dependent on the logged-in-Windows user profile. %temp%\mbsetup.log and %systemroot%\temp\mbamiservice.log Link to post Share on other sites More sharing options...
absrdst Posted September 16, 2020 Author ID:1407839 Share Posted September 16, 2020 Hi @Maurice Naggar Thank you very much for the reply and the information. It is much appreciated. Have a great rest of your evening! Link to post Share on other sites More sharing options...
Maurice Naggar Posted September 16, 2020 ID:1407841 Share Posted September 16, 2020 Y. W. Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now