Malware · guide

Is MBAM safe, and which question are you asking?

By Alberto Gulotta · Updated · 16 min read

Is MBAM safe splits into two questions with different answers. If you are deciding whether to install it, the fact that matters is that Windows switches Defender off when a non-Microsoft antivirus registers. If you found the name in Task Manager, the name itself proves nothing.

What Windows does to Defender when a non-Microsoft antivirus is installed Microsoft’s compatibility documentation states that on Windows 10 and Windows 11 not onboarded to Defender for Endpoint, Microsoft Defender Antivirus is in active mode when it is the primary solution, and goes into disabled mode automatically when a non-Microsoft antivirus solution is present. On Windows 11 with Smart App Control enabled it may go into passive mode instead. NOT ADDITIVE: ONE REPLACES THE OTHER Before: Defender is primary Microsoft’s table calls this “active mode” After: a non-Microsoft product Defender goes to “disabled mode (happens automatically)” So “a second opinion” is not what installing one gives you On Windows 10 and 11 without Defender for Endpoint, adding a second product does not add a layer: it takes the first one out. Microsoft notes one exception, Windows 11 with Smart App Control. AI Tools Primer · figure
The behaviour is in Microsoft’s own compatibility table, and it decides the question more than any review does. Figure drawn by AI Tools Primer.

“Is mbam safe” is two questions wearing one name

MBAM is short for Malwarebytes Anti-Malware, and the search runs together two situations that have nothing to do with each other.

The first is a decision. You are thinking of installing it, or you have it and want to know whether it is a legitimate product or the kind that manufactures alarm in order to sell a subscription. That question is answered by what the company documents about itself and by what the software does to the rest of your machine.

The second is an alarm. You opened Task Manager, saw a process with mbam in its name, and want to know whether it belongs there — often on a machine where nobody remembers installing anything of the sort. That question is not about the product at all. It is about whether a particular file on your disk is what its name claims, and the answer to it is unrelated to whether the real product is any good.

They are separated here because the honest answers point in different directions, and a page that merges them ends up reassuring the person who should be checking and worrying the person who should not.

The consequence that decides it: what happens to the protection you already have

Malwarebytes is widely described as a second opinion — something to run alongside your existing antivirus rather than instead of it. On Windows, whether that is what happens is decided by Windows, not by the description, and Microsoft publishes the rule.

In Microsoft’s compatibility documentation, for devices not onboarded to Defender for Endpoint — which is nearly every home machine — the table is short. With Microsoft Defender Antivirus as the primary solution on Windows 10 or 11, its state is active mode. With “a non-Microsoft antivirus/antimalware solution” as the primary solution, its state is “disabled mode (happens automatically)”.

So on an ordinary Windows machine, installing a second product that registers itself as your antivirus does not add a layer. It replaces one. Microsoft records one exception: “in Windows 11, if SmartAppControl is enabled, you may observe that Microsoft Defender Antivirus goes into passive mode instead of remaining in disabled mode”.

That reframes the question usefully. It is not whether this is safe to add, but whether it is better than what it will switch off — and that is a question about your own machine rather than about the product’s reputation. The NCSC’s guidance points the same way from the other side: “we don’t recommend using more than one AV product on any device, the security benefit of doing so is minimal and the products may conflict with each other, potentially causing device stability issues.”

What the company says it takes, in its own words

Security software sees everything by design, so “is it safe” includes what it does with what it sees. Malwarebytes publishes a privacy policy, and the useful approach is the one used elsewhere on this site for a maker describing its own product: quote it, and let the wording carry the weight.

Under functional data it states that “we may need to collect system processes and behaviors in order to perform system rollback and recovery operations” — which is what a program of this kind has to do to work at all. Under client data it lists the machine itself: operating system, system language, processor architecture, file system.

One item in that list is worth reading twice: “information from the Windows Security/Action Center, including security settings and programs installed or in use”. That is a description of the other security software on your computer and how it is configured. There is a straightforward operational reason for it — a security product needs to know what else is running — and it is also a wider reach than the phrase “client environment” suggests on its own.

On selling data the policy is specific rather than absolute, and the specificity is the honest part: “we do not sell your personal data to third parties in exchange for monetary consideration”, immediately followed by “certain activities on our website, such as the use of cookies and similar tracking technologies, may be considered ‘selling’ or ‘sharing’ under applicable U.S. state privacy laws”. Read together: not sold for money, and some website tracking may meet a legal definition of selling anyway. A policy that says both is more informative than one that says only the first.

What Malwarebytes states it collects from the machine it is installed on, quoted from its own privacy policy, read on 9 September 2026. This is the maker describing itself.
CategoryWhat it says it takesThe reason it gives
Functional data “system processes and behaviors” To “perform system rollback and recovery operations”
Client data: the machine Operating system, system language, processor architecture, file system in use To describe “the client environment”
Client data: your other security “Information from the Windows Security/Action Center, including security settings and programs installed or in use” Same category, and the line worth reading twice
Usage “Information about how you use our software or services”, called log data Product and service improvement

The other question: a process with that name, on a machine you did not install it on

If you arrived here from Task Manager, the thing to know first is that the name proves nothing in either direction, and this is documented rather than merely prudent.

CISA and MS-ISAC, in the joint StopRansomware Guide, describe the technique in the course of listing what to look for: “malicious actors often name Cobalt Strike Windows processes with the same names as legitimate Windows processes to obfuscate their presence and complicate investigations”. The example is a specific tool, but the method is general and cheap: a name is the one property anything can copy for free.

So searching the name is the one step that cannot settle it, which is unfortunate, because it is the step the name invites. What can settle it are properties a copy cannot borrow.

Where the file is. In Task Manager, right-click the process and open its file location. Software installed properly lives in its own folder under Program Files; something calling itself a security product from a temporary or user folder is answering the question by where it is standing.

Whether it is signed. Right-click the file, Properties, Digital Signatures. A valid signature names the company that published it and is checkable; an absent or invalid one on a file claiming a well-known name is the finding.

And what Windows itself thinks is protecting you. Microsoft documents the place to look: Windows Security, Virus & threat protection, and under “Who’s protecting me?” the Manage providers page lists the security software registered on the machine and its state. If a name in Task Manager is not in that list, that discrepancy is worth more than any search result about the name.

Why searching a process name settles nothing, in CISA’s words CISA and MS-ISAC state in the StopRansomware Guide that malicious actors often give their Windows processes the same names as legitimate Windows processes in order to obfuscate their presence and complicate investigations. A familiar name in Task Manager is therefore not evidence either way, and the check that does mean something is the file’s location and digital signature. THE ANSWER TO “IS THIS PROCESS SAFE?” What you did saw a name in Task Manager and searched for the name the name is what is easiest to copy What CISA says about names attackers “often name” their processes “with the same names as legitimate Windows processes” So the name is the one property a hostile program can copy for free. What it cannot copy is a valid signature from the company it is pretending to be, or the folder that installer actually used. AI Tools Primer · figure
The question is answerable; it is just not answerable by the name. Figure drawn by AI Tools Primer.

Three honest answers, depending on which question you had

None of them is a score, and this page does not give one.

If the question is whether to install it Then the real question is what it will switch off. On Windows 10 or 11 a non-Microsoft antivirus registering itself puts Defender into disabled mode automatically, so you are choosing between products rather than adding one, and the NCSC advises against running two in any case.
If the question is what the company does with what it sees Its privacy policy is public and specific enough to disagree with: it names what it collects, including information from Windows Security about your other security software, and it says it does not sell personal data for money while noting that some website tracking may count as selling under some U.S. state laws.
If the question is what a process on your machine is The name will not tell you, because names are copied. The file’s location, its digital signature, and whether Windows Security lists it as a registered provider will.

What this page will not do, and why the sources are what they are. It does not score the product, place it in a ranking or compare its detection rates, because doing that honestly would mean paid licences, controlled samples and months of testing rather than a paragraph. What it can do is quote the maker on itself, which is the same approach this site takes to any company describing its own product, and set that beside two parties with no stake in the answer — Microsoft documenting what Windows does, and CISA documenting how process names are used. One source that would have helped is missing: Malwarebytes’ own help page on registering with the Windows Security Center could not be read, so it is not cited here and no claim rests on it.

If you are here because something is already wrong. Deciding on a product is the slower question; how to tell if your computer has a virus sorts the signs that are worth acting on from the ones that are not, and removing malware from a computer is the sequence itself. If the reason you are asking is a warning that appeared in a browser window, that is a fake security alert, and no product decision follows from it.

Where to start

Three ways in.

“Should I install it?”
What it switches off — what it does to defender
“What does it collect?”
Its own policy, quoted — what it collects
“What is this process?”
Why the name cannot say — the process

The questions underneath this one

Whether to add a scanner is usually downstream of a question about the machine itself.

The same question on a phone

On phones the answer to “which scanner” is different, and on one of them it is none.

Questions people also ask

Is MBAM Malwarebytes?

Yes — MBAM is the long-standing abbreviation of Malwarebytes Anti-Malware, and process and file names containing mbam come from that. The abbreviation is why the same search is used both by people considering the product and by people who found the name on a machine.

Does Malwarebytes turn off my antivirus?

On Windows 10 and 11 that is Windows’ doing, not the app’s. Microsoft’s compatibility documentation states that when a non-Microsoft antivirus is the primary solution, Microsoft Defender Antivirus goes into “disabled mode (happens automatically)”.

Is it safe to run Malwarebytes and another antivirus together?

The NCSC advises against it in general: “we don’t recommend using more than one AV product on any device, the security benefit of doing so is minimal and the products may conflict with each other, potentially causing device stability issues”.

Is mbamservice.exe safe?

A process name cannot answer that. CISA notes that attackers “often name” their processes “with the same names as legitimate Windows processes”. Check the file’s location and its digital signature, and whether Windows Security lists it under Manage providers.

What data does Malwarebytes collect?

By its own policy: system processes and behaviours for rollback and recovery; the operating system, language, processor architecture and file system; information from the Windows Security or Action Center including security settings and programs installed or in use; and log data about how you use the software.

Does Malwarebytes sell your data?

Its policy states it does “not sell your personal data to third parties in exchange for monetary consideration”, and adds that certain website activities such as cookies and similar tracking “may be considered ‘selling’ or ‘sharing’ under applicable U.S. state privacy laws”.

Not covered here. It does not rate the product or rank it against others. An honest comparison needs paid licences and controlled testing, and this page has neither.

It does not cover the Mac or Android versions, where what the software can reach is decided by the operating system and the answer changes with it.

And it does not describe the paid tier or its prices, which move faster than a page can follow. What holds instead is simple: the collection and selling clauses are quoted from Malwarebytes’ own privacy policy including the qualification it attaches, what Windows does to Defender is quoted from Microsoft’s compatibility documentation, the point about process names is CISA’s and is quoted from the StopRansomware Guide, the page gives no score or ranking and says why, and the one source that could not be read is named as unread rather than cited.

Sources

  1. Malwarebytes — Privacy Policy: the functional data collected, including system processes and behaviours for rollback and recovery; the client data listing operating system, system language, processor architecture, file system, and information from the Windows Security or Action Center including security settings and programs installed or in use; log data on how the software is used; and the statement that personal data is not sold for monetary consideration together with the note that some website tracking may be considered selling or sharing under some U.S. state privacy laws — www.malwarebytes.com, read 9 September 2026.
  2. Microsoft Learn — Microsoft Defender Antivirus compatibility with other security products: the table for devices not onboarded to Defender for Endpoint, showing Microsoft Defender Antivirus in active mode when it is the primary solution on Windows 10 and 11 and in disabled mode, automatically, when a non-Microsoft antivirus solution is primary; and the noted exception for Windows 11 with Smart App Control enabled — learn.microsoft.com, read 9 September 2026.
  3. CISA and MS-ISAC — #StopRansomware Guide: that malicious actors often name their Windows processes with the same names as legitimate Windows processes in order to obfuscate their presence and complicate investigations, alongside the other indicators listed there, including anomalous use of built-in Windows tools and unexpected PowerShell execution — www.cisa.gov, read 9 September 2026.
  4. CISA and MS-ISAC — #StopRansomware Guide, the same guide as a web page: the sentence on process names quoted above is there word for word, and this is the address to use if the PDF will not open — www.cisa.gov, read 9 September 2026.
  5. National Cyber Security Centre — Antivirus and other security software, Device security guidance: that more than one antivirus product on a device is not recommended because the security benefit is minimal and the products may conflict with each other, potentially causing device stability issues; and that Windows, macOS and Android include built-in antivirus by default which will meet the needs of many organisations — the page says organisations, not needs in general — www.ncsc.gov.uk, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.