Overview
Malwarebytes made its name as the thing you ran after something had already gone wrong, when the resident antivirus had missed whatever was now sitting on the machine. That reputation is deserved and the scanner still earns it, but the premium tier is a different product: four resident shields that run continuously, watching web traffic, running processes, exploit patterns in browsers and document readers, and the behaviour signature of an encryption sweep in progress.
The free build reverts to on demand scanning after a short trial and leaves the machine unprotected between scans. This build has the premium state applied, so all four shields stay enabled indefinitely, scheduled scans run without prompting, and the protection panel does not spend its life advertising an upgrade.
The four resident shields
Web protection blocks a connection to a known bad host before the browser finishes loading, which stops a fair amount of trouble at the point of contact rather than on the disk afterwards. It is a filter at the network layer rather than a browser add-on, so it covers everything on the machine and not just the one browser you installed it in.
Malware protection is the resident file and process watcher. Exploit protection is the interesting one, since it does not look for a known sample at all, it looks for the technique: a document reader spawning a shell, a browser process writing an executable and running it, memory being marked executable in a pattern that only ever means one thing. That covers new material that no signature has seen.
Ransomware protection watches for a process walking a directory tree and rewriting files in a pattern consistent with an encryption sweep, halts it, and rolls back the files it has already touched from a local cache. It works on behaviour rather than identity, which is the only approach that has ever held up against a fresh family.
Scanning and cleanup
The threat scan checks the places that matter, memory, startup entries, the registry run keys, the scheduled task store and the common staging folders, and finishes in a few minutes on a normal machine. The custom scan covers whatever paths you point it at and can be told to include archives and rootkit checks, which slows it down considerably but finds things the fast pass steps over.
Removal is the part this program has always been better at than most. Quarantine is reversible, the cleanup pass fixes browser settings and proxy entries that were changed, and the reboot removal path handles files that are locked while the system is running. Detections are listed with the actual path and the reason rather than a category name and nothing else, so you can make an informed decision about a false positive.
Running it next to another antivirus
Malwarebytes is designed to coexist with a second real time product, which is unusual. If Defender or another suite is already resident, this can run alongside it and the two will not fight for the same file handle in the way two traditional engines do. On a machine where the other product is doing the heavy signature work, turning off the malware shield here and leaving exploit and ransomware protection on is a sensible arrangement.
If you would rather it be the only resident product, disable the other one properly rather than leaving it half running. Two suites both trying to intercept the same operation is the single most common cause of the sluggishness people blame on the software rather than on the pairing.
What you get
- Web protection filtering at the network layer for every application
- Resident malware shield watching files and processes
- Exploit protection based on technique rather than known samples
- Ransomware protection with rollback from a local file cache
- Fast threat scan covering memory, startup and staging locations
- Custom scans with archive inspection and rootkit checks
- Reversible quarantine with full detection paths listed
- Reboot removal path for locked files
- Scheduled scanning with no prompts or upgrade advertising
- Designed to coexist with a second resident product
Inside the archive
- Malwarebytes Premium installer, 64-bit
- Premium protection state applied, all four shields enabled
- Offline definition set current to this build
- Notes on running alongside another resident antivirus
- Language files for the interface list shown above
System requirements
| Operating system | Windows 10 version 21H2 or later, Windows 11, 64-bit |
|---|---|
| Processor | 800 MHz or faster with SSE2 |
| Memory | 2 GB, 4 GB recommended |
| Storage | 500 MB free |
| Network | Connection needed for definition updates, offline set included |
| Display | 1024 by 768 or better |
Installing it
- Unpack the archive to a local folder.
- Turn off any other resident scanner for the length of the install, since the licensing module will otherwise be quarantined.
- Run the installer as administrator and let it finish without a restart.
- Open the program and confirm all four shields show as on in the protection panel.
- Run a threat scan once so the baseline is established before you leave it running.
Mirrors
| Route | Region | Note | State |
|---|---|---|---|
| Direct, primary | Europe | No wait, resumable | Online |
| Direct, secondary | Asia Pacific | No wait, resumable | Online |
| Torrent magnet | Global | Mirrors are usually quicker at this size | Online |
Release history
- Ransomware rollback cache moved off the system drive by default
- Fixed web protection blocking local network addresses on some configurations
- Reduced memory use of the resident service on long uptimes
- Exploit protection extended to cover more document reader processes
- Scan speed improved on machines with very large user folders
- Quarantine restore fixed for paths with accented characters
- Scheduled scan no longer wakes the machine from sleep unless told to
Questions about this release
Does it stay premium or revert to scan only?
It stays. The premium state is applied in this build, so the shields do not switch themselves off after a period.
Can I run it with Defender on?
Yes, that pairing is fine and is the usual arrangement. If you want to reduce overlap, turn off the malware shield here and leave exploit and ransomware protection running.
Will definitions still update?
Yes, definition updates run normally against the public feed. An offline set is included so a fresh install is not defenceless before its first update.
Why did my antivirus flag the installer?
The licensing module is modified, which every scanner treats as tampering. Suspend protection during the install and exclude the program folder afterwards.
Does the ransomware rollback need a lot of disk?
It keeps a rolling cache of recently changed files, which is a few gigabytes at most and is capped. The cache location can be moved in settings.
Comments
Running it next to Defender with the file shield off. No slowdown at all, exploit blocking has fired twice.
Cleaned a machine that had a browser hijack the other scanner kept missing. Reboot removal did the last piece.
Comments are read before they appear. If a build stops working, say so here and it gets rebuilt rather than quietly left up.
Shields all stayed on after a week and two restarts. Previous builds I tried would quietly drop back to free.