The malware installs a fake Malwarebytes program to “%ProgramFiles(x86)%\Malwarebytes” and hides a majority of the malicious payload inside one of the two dlls, Qt5Help. dll. The malware notifies victims that Malwarebytes was successfully installed, which is not true, as the program cannot be opened.